Repository navigation
release: v1.6.69 - #294
Open
roncodes wants to merge 12 commits into
Open
release: v1.6.69#294roncodes wants to merge 12 commits into
roncodes wants to merge 12 commits into
Conversation
- Drop the 'public' visibility from Utils::urlToStorefrontFile: a bucket with BucketOwnerEnforced rejects any PUT carrying an ACL, so put() returned false. - Add File::signStoredUrl()/s3KeyFromUrl(): turn absolute URLs stored as strings (legacy unsigned bucket URLs, expired signed URLs) back into a key and re-sign. - Re-sign template builder image src at render time. - Cache signed URLs for 60 of their 120 minutes so every URL handed out has at least an hour left; cut Extension icon_url cache from 24h to 30m.
Replace the db:backup command, which piped mysqldump through gzip without pipefail, swallowed upload errors and returned success on a failed dump. That is how production uploaded 20-byte empty dumps on 2026-09-24/25 (no mysqldump in the image) and then nothing at all while reporting DONE. - DatabaseBackupService streams the dump client's stdout into gzip in PHP (no shell pipeline), passes the password via MYSQL_PWD, and fails a run on a non-zero exit, a missing '-- Dump completed' marker, a dump under min_size_bytes, or an uploaded object whose size differs from the file. - Uploads go to any filesystem disk (bucket override for s3, key prefix); retention by age and/or count runs only after a fully successful run and always keeps each database's newest backup. - Every attempt is recorded in database_backups (status, size, duration, error, trigger); failures can email configured addresses. - Settings live in system.database-backups (env defaults in config/database-backups.php) and drive the schedule; disabled by default. - Admin endpoints under int/v1/database-backups: settings get/save/reset, recent runs, and a queued 'run now'. - db:backup exits non-zero on any failure; --force runs while disabled.
Add VerificationCode::issue(), check() and attemptsLeft() for flows where a leaked table must not give away live codes: - issue() stores an HMAC of the code, keyed by the app key, and hands the plain code back once on the instance (plainCode), defaulting to a 10-minute expiry and an 'active' status. - check() compares with hash_equals, counts wrong attempts in meta and locks the code on the last allowed one. Expired and locked codes report as such. - The creating hook keeps a code that was already set, so issue() is not overwritten; codes made the old way still get a random one and still check. Existing generators and their callers are unchanged. First user: the FleetOps public tracking page's one-time codes.
getCountryCodeByCurrency() and getCountryCodeByName() rebuilt the full countries dataset (a 4.7 MB JSON file plus flag hydration) on every call. Storefront serializes a country per store, so listing stores paid that cost once per record and network store lists could take minutes. The name/ISO2/currency rows are now built once, kept in the application cache and memoized per process. Cache failures fall back to building the lookup, and flushCountryLookup() resets it.
Store media, product images and proofs of delivery are looked up by subject_uuid, which had no index, so each lookup scanned the whole files table.
fix(files): support a fully private S3 media bucket
feat(backups): settings-driven database backups that fail loudly
feat(verification): hashed one-time codes with attempt counting
perf: cache the country lookup and index files.subject_uuid
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Release v1.6.69
Release branch for core-api v1.6.69. Merging into
maintriggersrelease.yml, which validates thatcomposer.jsonand the first line ofRELEASE.mdname1.6.69, then pushes thev1.6.69tag.This branch collects:
fleetbase/core-api ^1.6.69.files.subject_uuidindex. Adds a migration.Before merging
database_backups(feat(backups): settings-driven database backups that fail loudly #288) and thefiles.subject_uuidindex (perf: cache the country lookup and index files.subject_uuid #291).SOCKETCLUSTER_AUTH_ENABLED(defaultfalse),SOCKETCLUSTER_AUTH_KEY,SOCKETCLUSTER_PUBLISH_URL,SOCKETCLUSTER_TOKEN_TTL. Socket auth stays off untilSOCKETCLUSTER_AUTH_ENABLED=true, even with a key set, so existing socket clients keep working.