Skip to content

[pull] master from vastsa:master - #113

Merged
pull[bot] merged 41 commits into
haibinml:masterfrom
vastsa:master
Sep 14, 2026
Merged

pull[bot] merged 41 commits into
haibinml:masterfrom
vastsa:master

Conversation

@pull

@pull pull Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

…cleanup

- add pyproject.toml with pytest config and dev dependency group (PEP 735)
- add ruff (core correctness rules) + pre-commit hook
- fix stored XSS: html.escape site config before index template injection,
  with regression tests
- log previously swallowed cleanup exceptions in upload rollback paths
- consolidate three duplicate path generators into build_file_path
  (also aligns chunk/presign date dirs to get_now() instead of local time)
- drop redundant ip_limit sync in load_config (refresh_settings covers all limiters)
- remove dead code (calculate_file_hash, commented-out block), two orphan
  guide docs, and stale .gitignore entries
- add dependabot for pip, docker, and github-actions
- bump starlette 1.3.1 -> 1.6.0 (no breaking API changes; verified with the
  full test suite plus an ASGI smoke test incl. Range downloads)
- skip theme asset tests when themes/ is not built locally
- tests/helpers.py: SettingsOverrideMixin + init_memory_db()/close_db()
- tests/conftest.py: httpx ASGI client fixtures (db, client, initialized_client)
- enable pytest asyncio_mode=auto
- replace 6 duplicated SettingsOverrideMixin copies and 4 duplicated
  Tortoise.init blocks across the legacy unittest suite
… rehash

- new hashes use scrypt (n=2^14, r=8, p=1); sha256 and plaintext formats
  keep verifying unchanged, so existing deployments are unaffected
- on successful login a legacy-stored admin password is rehashed to scrypt
  in the settings KeyValue row
- add password_needs_rehash() and extend scheme detection; stdlib only, no
  new dependency
…148 lines)

- apps/base/setup_wizard.py: form parsing rules, setup options, and the
  two admin-facing HTML pages
- apps/base/pages.py: setup/assets/index/robots/public-config routes and
  theme resolution (404 handler registered on the app in main.py)
- tests updated to import from the new modules
…) and add config schema guard

- opendal_scheme was read directly by the OpenDAL backend but never declared
  in DEFAULT_CONFIG: selecting that backend crashed with AttributeError
- chunk_expire_hours existed only as getattr fallbacks in two modules
- refresh_settings now warns about unknown user_config keys
- meta-test scans the codebase so any future settings.X reference without a
  DEFAULT_CONFIG declaration fails the suite
- 20 camelCase keys (uploadSize, expireStyle, openUpload, ...) renamed across
  DEFAULT_CONFIG, settings accessors, setup form fields, and ConfigService
- migrations_007 renames keys inside the existing settings KeyValue row,
  preserving all values for existing deployments
- schema guard meta-test keeps future keys declared
…share (D2)

- storage contract drops UploadFile in favor of BinaryIO (+content_type param),
  completing the framework decoupling of the storage layer
- LocalFileClass.read() leaked an open fd and its handle was passed where
  save_file expected UploadFile — /admin/local/share 500ed on every call;
  now reads bytes via with-block and shares correctly (regression tests added)
- OneDrive save_file additionally had save_path called as a function — fixed
- quota.get_storage_usage (runs on every upload) now aggregates via Sum
  instead of loading every row
- dashboard simple counters (total/size/expired/active/text/chunked/used,
  yesterday/today, top suffixes, recent 8) moved to SQL; the per-row health
  rules engine keeps its single pass (documented)
…ess lock (D5)

settings/activities/view-presets are whole-blob KeyValue rows; concurrent
admin operations could silently drop each other's writes (last-writer-wins).
Single-worker deployment assumption documented; lock is process-local.
…e (2.3)

share_text/share_file/complete_upload/presign proxy/presign confirm now
delegate quota reservation, storage writes, record creation, rollback and
chunk cleanup to service methods; handlers keep auth, request validation,
rate limiting and response wrapping. validate_file_size and
PRESIGN_SESSION_EXPIRES move to services as shared single sources.
Marrrrrrrrry and others added 11 commits September 11, 2026 03:10
Drop the message/msg envelope twin, all camel+snake dual-field response
pairs (file list/detail/policy/storage, dashboard counters, batch op
counts, status insights, presets, metadata), and camel request fields
(clearExpiredAt, downloadLimit, sortBy/sortOrder, maxChars). Stored
KeyValue JSON (metadata, presets, activities) keeps legacy-key read
fallbacks so existing deployments normalize transparently.
…sign page

API version 2.1.0 -> 2.5.6; response examples use the single message
field; dashboard/list examples and params match current snake_case
contract; drop stale save_path from presign init response; add English
presign-upload page and sidebar entry; uploadSize -> upload_size.
Sync zh/en guide docs with migration 007 key names (upload_size,
open_upload, enable_chunk, expire_style, error_count, etc.) so existing
deployments following the docs use the current schema.
build_public_config/build_public_meta served a mixed camel/snake
contract (allowedFileTypes, meta.features.*, api.legacyConfig,
limits.uploadWindowMinutes). Rename to snake_case; frontend reads
allowed_file_types only.
- ci.yml: ruff + pytest on push/PR, installing from the hashed lockfile
  with --require-hashes, plus a lockfile-vs-requirements consistency
  check (dependabot cannot regenerate the lockfile; drift was silent).
- test_api_contract.py: deep-scans public config, dashboard, admin file
  list and share metadata responses for camelCase keys - the regression
  net for the D7 public-config leak found during review.
工程化加固、安全与性能修复、API 契约统一 snake_case(含 CI 测试流水线)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
#514 began validating `background` as an http(s) URL against the *merged*
config, so a value stored by an older release (a relative path, or one
containing a space/parenthesis — all legal before) made every subsequent
settings save return 400, including saves that never touched `background`.
Existing deployments could not change any setting at all.

Validate only values that actually change: an untouched legacy value is
kept as-is (it is still html-escaped on render), while any edit must pass
validation. Regression tests cover both directions and fail without this
change.

Also treat OverflowError from hashlib.scrypt as a non-matching hash so a
hand-crafted n/r/p cannot disturb the login path on runtimes that raise it.
fix: 存量 background 值不再阻塞后台设置保存(#514 升级回归)
Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
@pull pull Bot locked and limited conversation to collaborators Sep 14, 2026
@pull pull Bot added the ⤵️ pull label Sep 14, 2026
@pull
pull Bot merged commit 3c135eb into haibinml:master Sep 14, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants