Fix CI for the user-scoped runners
- ci.yml: connect to the test MariaDB as root so Django creates the test database itself (no client install/grant step), and drop actions/cache (cache: pip/npm): Gitea's cache service hangs the job on restore/save. - publish.yml: prefer the REGISTRY_USER/REGISTRY_TOKEN secrets (as on other repos) and fall back to the automatic Actions token. - AGENTS.md: note the CI layout, the runner labels and the cache caveat.
This commit is contained in:
@@ -49,6 +49,12 @@ Project constraints (do not regress):
|
||||
- Periodic commands (follow syncs, similarity cleanup, guest blacklist
|
||||
refresh) run in the composes' `scheduler` service — the backend image with
|
||||
the j621-scheduler entrypoint, intervals via J621_*_EVERY. No host cron.
|
||||
- CI lives in .gitea/workflows: ci.yml runs on every push/PR (Django checks +
|
||||
the full backend suite against MariaDB/Redis service containers, frontend
|
||||
lint/type-check/build); publish.yml is manual and builds/pushes both images
|
||||
multi-arch. Jobs run on the user-scoped msi-mortar-ci runner (labels
|
||||
`desktop` + `ubuntu-latest`). Do not add actions/cache (`cache: pip`/`npm`)
|
||||
to these workflows: Gitea's cache service hangs the job on restore/save.
|
||||
- Security/permission tests live in backend/apps/core/tests and need a
|
||||
one-time grant: GRANT ALL ON `test_j621`.* TO 'j621'@'%';
|
||||
|
||||
@@ -85,7 +91,12 @@ Security hardening (do not weaken):
|
||||
SECRET_KEY (apps/accounts/crypto.py); rotating SECRET_KEY invalidates them
|
||||
(and all signed media URLs), so users must re-enter the key.
|
||||
- API throttles live in REST_FRAMEWORK (env-overridable): anon 120/min,
|
||||
user 600/min, login 5/min, register 20/hour, e621_proxy 60/hour.
|
||||
user 600/min, login 5/min, register 20/hour, e621_proxy 60/hour. Signed
|
||||
media URLs (raw/thumbnail/staged-file/similarity-file actions) are exempt
|
||||
on purpose: <img>/<video> tags fetch them without an Authorization header,
|
||||
so a gallery would otherwise drain the anonymous bucket and get 429 JSON
|
||||
instead of images. THROTTLE_ENABLED=false removes the anon+user limits for
|
||||
private/tailnet deployments (the login/register/proxy guards stay).
|
||||
- Only admins (superusers) may grant/revoke the staff role or delete
|
||||
staff/admin accounts; staff manage regular/uploader accounts only.
|
||||
- Storage, duplicates, delete, temp-clear, uploads and downloads require
|
||||
|
||||
Reference in New Issue
Block a user