Skip to content

Properly guard against incomplete Rails module definitions - #2462

Merged
joelhawksley merged 4 commits into
ViewComponent:mainfrom
mikz:derails
Dec 3, 2025
Merged

joelhawksley merged 4 commits into
ViewComponent:mainfrom
mikz:derails

Conversation

@mikz

@mikz mikz commented Oct 17, 2025

Copy link
Copy Markdown
Contributor

Some parts of the code guard against undefined Rails module, but some parts do that in unsafe manner.

Good example: defined?(Rails.env) && Rails.env
Bad example: defined?(Rails) && Rails.env

There are gems (eg. rails-html-sanitizer https://github.com/rails/rails-html-sanitizer/blob/2a8fe8971b02b1b14abb6634e04af4e32b0057cd/lib/rails-html-sanitizer.rb#L10-L12), that define module Rails to extend it, but then it is incomplete and causes failures.

This change unifies accessing Rails module with proper defines? guarding against incomplete definition of the Rails module.

This pattern is already used on other places in the codebase:

What are you trying to accomplish?

Use view_component gem without Rails.

What approach did you choose and why?

Guard clause defined? checking the nested access into the Rails module. Since it is already used within the codebase on other places.

Anything you want to highlight for special attention from reviewers?

I don't know what would be a good way to test this. A part of test suite that runs without Rails? Is that something you'd like to guarantee as a project?

Some parts of the code guard against undefined Rails module,
but some parts do that in unsafe manner.

Good example: `defined?(Rails.env) && Rails.env`
Bad example: `defined?(Rails) && Rails.env`

There are gems, that define `module Rails` to extend it, but then it is
incomplete and causes failures.

This change unifies accessing Rails module with proper `defines?`
guarding against incomplete definition of the Rails module.
@Spone

Spone commented Oct 27, 2025

Copy link
Copy Markdown
Collaborator

Thanks @mikz for your contribution!

I think it's a good idea to fix the guards as you suggest, but ViewComponent still depends on ActiveSupport and ActionView.

Is that something you'd like to guarantee as a project?

I'm not sure we want to guarantee this, because most of us are using ViewComponent with Rails, but if you'd like to work on a test suite that pass without Rails, we can certainly include it to the CI.

Comment thread docs/CHANGELOG.md Outdated
@joelhawksley
joelhawksley merged commit a3b9af5 into ViewComponent:main Dec 3, 2025
13 of 14 checks passed
@joelhawksley

Copy link
Copy Markdown
Member

@mikz thank you for your contribution! I would welcome a CI suite to cover this change as our compatibility with Bridgetown is documented: https://viewcomponent.org/compatibility.html#bridgetown-static-site-generator

@mikz
mikz deleted the derails branch December 8, 2025 08:26
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants