forked from Orcpub/orcpub
-
Notifications
You must be signed in to change notification settings - Fork 0
[MIRROR of Orcpub/orcpub#695] Locale safety, Windows ports, env blank-handling, registration #35
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Open
codeGlaze
wants to merge
35
commits into
mirror/upstream-develop
Choose a base branch
from
hotfix/locale-safety
base: mirror/upstream-develop
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Changes from all commits
Commits
Show all changes
35 commits
Select commit
Hold shift + click to select a range
9a0e482
ci: prove the Windows behaviour on a Windows runner
codeGlaze 5829e85
ci: source check_port_available from start.sh, where it actually lives
codeGlaze 6636369
scripts: handle both kinds of Windows pid, and stop crying wolf
codeGlaze 71c4d26
ci: assert the quiet case on a port no other step has touched
codeGlaze 5d2bbd1
Fix locale-dependent failures in ETag and CSP config
codeGlaze c27cbd3
scripts: make the Windows paths work instead of silently lying
codeGlaze 798b126
ci: run the Windows job on the branch that now carries the work
codeGlaze 4e972cf
Correct the CSP docs, and say which policy the server starts under
codeGlaze cf8a6d7
Surface the effective config when the launcher starts
codeGlaze bcf8526
Put config where it is read, and repair --check, which died silently
codeGlaze 402ea5e
Add tests that pin both defects, and prove they fail without the fix
codeGlaze b86d3d1
Pin the locale on name-to-kw and the two name filters
codeGlaze 55adc9e
Address the review on #695: six findings, each reproduced first
codeGlaze 89f8d17
Stop the env template from dictating the Datomic URL to both runtimes
codeGlaze dcd0483
Address the second review on #695: eight findings, each reproduced first
codeGlaze b6df809
Make the dev service map honour PORT, so the scripts and the server a…
codeGlaze c9fd5a5
Finish the CSP docs fix: three user-facing docs still described Repor…
codeGlaze 7703e36
Mirror the server exactly in dev_mode_blocks_figwheel, including empt…
codeGlaze c0a6fa7
Drop the commented-out datomic-pro coordinate and the comment that ou…
codeGlaze 813fdbb
Mirror the server's three-way CSP cond, and stop the warning claiming…
codeGlaze db2f7ee
Add orcpub.env, convert every env read to it, and make the old patter…
codeGlaze f412602
Keep postal's inputs as empty strings: orcpub.env regressed the Docke…
codeGlaze e4a6964
Roll back the account when the verification email fails
codeGlaze 67cb98e
Correct the severity claim: the stuck account is recoverable via resend
codeGlaze 50e4c4c
Finish the severity correction: two copies were still wrong
codeGlaze 5d7b4b2
Verify on creation when no SMTP is configured, making the .env promis…
codeGlaze fcaf894
Fail closed when email config goes missing: auto-verify now needs an …
codeGlaze 896d186
Say at startup what registration will actually do
codeGlaze 8b33c26
Set EMAIL_FROM_ADDRESS explicitly in the template
codeGlaze 4909ea1
Document ALLOW_UNVERIFIED_REGISTRATION, and make the KB references re…
codeGlaze 9ca0560
Write the new settings for humans, and point the code at the doc that…
codeGlaze 969cf64
Read the JWT secret through config/signature so Docker secrets work
codeGlaze 7b16f2e
Guard the two secret-backed settings against being read from the env …
codeGlaze b29d89e
Fix the three registration paths Greptile flagged, and pin lein in th…
codeGlaze 94a71ea
Only restore the previous verification key if it is still ours
codeGlaze File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
| Original file line number | Diff line number | Diff line change |
|---|---|---|
| @@ -0,0 +1,61 @@ | ||
| # Runs the JVM suite under non-English locales. | ||
| # | ||
| # Everything the locale-safety work fixed was invisible to an English-locale CI: | ||
| # an unlocalised date formatter that blanked every webjar asset, CSP_POLICY | ||
| # folding to "strıct", name-to-kw producing :ıllusory-script, and two name | ||
| # searches returning nothing for an uppercase query. None of them fail under | ||
| # en_US, so en_US alone can never catch the next one. | ||
| # | ||
| # tr_TR is the high-value entry: Turkish and Azerbaijani are the only locales | ||
| # whose ASCII case folding differs, so they catch that whole class. es_ES | ||
| # catches date parsing, which tr_TR also catches -- one non-English entry would | ||
| # do, but es_ES is where the original bug report came from, so it stays as a | ||
| # named regression guard. | ||
|
|
||
| name: Locale | ||
|
|
||
| on: | ||
| push: | ||
| branches: [hotfix/locale-safety, develop, main] | ||
| pull_request: | ||
| branches: [develop, main] | ||
| workflow_dispatch: | ||
|
|
||
| permissions: | ||
| contents: read | ||
|
|
||
| jobs: | ||
| jvm-suite: | ||
| name: JVM suite under ${{ matrix.locale }} | ||
| runs-on: ubuntu-latest | ||
| timeout-minutes: 20 | ||
| strategy: | ||
| fail-fast: false | ||
| matrix: | ||
| include: | ||
| - locale: tr_TR | ||
| java_opts: -Duser.language=tr -Duser.country=TR | ||
| - locale: es_ES | ||
| java_opts: -Duser.language=es -Duser.country=ES | ||
| steps: | ||
| - uses: actions/checkout@v4 | ||
|
|
||
| - uses: actions/setup-java@v4 | ||
| with: | ||
| distribution: temurin | ||
| java-version: '21' | ||
|
|
||
| # Pinned to the version continuous-integration.yml uses. `stable` is a | ||
| # moving ref, so an upstream release could change or break this check. | ||
| - name: Install Leiningen | ||
| run: | | ||
| curl -fsSL -o "$HOME/lein" \ | ||
| https://raw.githubusercontent.com/technomancy/leiningen/2.11.2/bin/lein | ||
| chmod +x "$HOME/lein" | ||
| echo "$HOME" >> "$GITHUB_PATH" | ||
| "$HOME/lein" version | ||
|
codeGlaze marked this conversation as resolved.
|
||
|
|
||
| - name: lein test | ||
| env: | ||
| JAVA_TOOL_OPTIONS: ${{ matrix.java_opts }} | ||
| run: lein test | ||
Oops, something went wrong.
Oops, something went wrong.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Uh oh!
There was an error while loading. Please reload this page.