Compare commits
2
Commits
474403ffe2
...
d9c1e9e521
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
d9c1e9e521 | ||
|
|
e2697c0a78 |
@@ -0,0 +1,114 @@
|
||||
# J621 CI — runs on every push (and pull request): Django checks + the full
|
||||
# backend test suite against MariaDB/Redis, and the frontend type-check,
|
||||
# lint and production build.
|
||||
#
|
||||
# Runner: the "nitro-ci" act_runner with the custom `ubuntu-latest` label.
|
||||
|
||||
name: CI
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: ["**"]
|
||||
tags-ignore: ["**"]
|
||||
pull_request:
|
||||
workflow_dispatch:
|
||||
|
||||
concurrency:
|
||||
group: ci-${{ github.ref }}
|
||||
cancel-in-progress: true
|
||||
|
||||
jobs:
|
||||
backend:
|
||||
name: Backend tests
|
||||
runs-on: ubuntu-latest
|
||||
services:
|
||||
mariadb:
|
||||
image: mariadb:11.4
|
||||
env:
|
||||
MARIADB_ROOT_PASSWORD: root
|
||||
MARIADB_DATABASE: j621
|
||||
MARIADB_USER: j621
|
||||
MARIADB_PASSWORD: j621
|
||||
options: >-
|
||||
--health-cmd "healthcheck.sh --connect --innodb_initialized"
|
||||
--health-interval 5s
|
||||
--health-timeout 5s
|
||||
--health-retries 20
|
||||
redis:
|
||||
image: redis:7-alpine
|
||||
options: >-
|
||||
--health-cmd "redis-cli ping"
|
||||
--health-interval 5s
|
||||
--health-timeout 5s
|
||||
--health-retries 20
|
||||
env:
|
||||
DB_HOST: mariadb
|
||||
DB_PORT: "3306"
|
||||
DB_NAME: j621
|
||||
DB_USER: j621
|
||||
DB_PASSWORD: j621
|
||||
DB_ROOT_PASSWORD: root
|
||||
REDIS_URL: redis://redis:6379/1
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- uses: actions/setup-python@v5
|
||||
with:
|
||||
python-version: "3.14"
|
||||
cache: pip
|
||||
cache-dependency-path: backend/requirements.txt
|
||||
|
||||
- name: Install backend dependencies
|
||||
run: pip install -r backend/requirements.txt
|
||||
|
||||
- name: Install a MariaDB client
|
||||
run: |
|
||||
sudo apt-get update
|
||||
sudo apt-get install -y --no-install-recommends default-mysql-client
|
||||
|
||||
- name: Grant the test database rights
|
||||
run: |
|
||||
for i in $(seq 1 30); do
|
||||
mysql -h "$DB_HOST" -P "$DB_PORT" -u root -p"$DB_ROOT_PASSWORD" \
|
||||
-e "SELECT 1" >/dev/null 2>&1 && break
|
||||
sleep 2
|
||||
done
|
||||
mysql -h "$DB_HOST" -P "$DB_PORT" -u root -p"$DB_ROOT_PASSWORD" \
|
||||
-e "GRANT ALL ON \`test_j621\`.* TO 'j621'@'%'; FLUSH PRIVILEGES;"
|
||||
|
||||
- name: Django system checks
|
||||
working-directory: backend
|
||||
run: python manage.py check
|
||||
|
||||
- name: Backend tests
|
||||
working-directory: backend
|
||||
run: >-
|
||||
python manage.py test
|
||||
apps.core.tests
|
||||
apps.library.tests
|
||||
apps.follows.tests
|
||||
apps.accounts.tests
|
||||
|
||||
frontend:
|
||||
name: Frontend build & lint
|
||||
runs-on: ubuntu-latest
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- uses: actions/setup-node@v4
|
||||
with:
|
||||
node-version: "22"
|
||||
cache: npm
|
||||
cache-dependency-path: frontend/package-lock.json
|
||||
|
||||
- name: Install frontend dependencies
|
||||
working-directory: frontend
|
||||
run: npm ci
|
||||
|
||||
- name: Lint
|
||||
working-directory: frontend
|
||||
run: npm run lint
|
||||
|
||||
- name: Type-check & build
|
||||
working-directory: frontend
|
||||
run: npm run build
|
||||
@@ -0,0 +1,51 @@
|
||||
# J621 image publishing — manual workflow.
|
||||
#
|
||||
# Builds the backend (gunicorn + whitenoise, ffmpeg) and frontend (static
|
||||
# nginx) images for linux/amd64 + linux/arm64 and pushes them to the Gitea
|
||||
# registry as :latest and :<short-sha>, with the commit baked in as GIT_HASH.
|
||||
#
|
||||
# Run it from the Actions tab ("Run workflow"), or:
|
||||
# curl -X POST .../api/v1/repos/JakeBreath/J621/actions/workflows/publish.yml/dispatches \
|
||||
# -d '{"ref":"main"}'
|
||||
#
|
||||
# Registry login uses the automatic GITHUB_TOKEN (the repo needs package write
|
||||
# access for the actor); no extra secrets are required.
|
||||
|
||||
name: Publish images
|
||||
|
||||
on:
|
||||
workflow_dispatch:
|
||||
inputs:
|
||||
platforms:
|
||||
description: Build platforms (comma separated)
|
||||
required: false
|
||||
default: linux/amd64,linux/arm64
|
||||
|
||||
concurrency:
|
||||
group: publish
|
||||
cancel-in-progress: false
|
||||
|
||||
jobs:
|
||||
publish:
|
||||
name: Build & push images
|
||||
runs-on: ubuntu-latest
|
||||
env:
|
||||
REGISTRY_USER: ${{ github.actor }}
|
||||
REGISTRY_TOKEN: ${{ secrets.GITHUB_TOKEN }}
|
||||
PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }}
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
with:
|
||||
fetch-depth: 0
|
||||
|
||||
- name: Register binfmt (multi-arch builds)
|
||||
run: docker run --privileged --rm tonistiigi/binfmt --install all
|
||||
|
||||
- name: Build & push both images
|
||||
run: |
|
||||
set -euo pipefail
|
||||
SHA="$(git rev-parse --short HEAD)"
|
||||
echo "Publishing $SHA for $PLATFORMS"
|
||||
# Both scripts honour REGISTRY_USER/REGISTRY_TOKEN (see deploy/push_*.sh).
|
||||
PLATFORMS="$PLATFORMS" ./deploy/push_frontend.sh "$SHA"
|
||||
PLATFORMS="$PLATFORMS" ./deploy/push_backend.sh "$SHA"
|
||||
@@ -429,6 +429,36 @@ class ThrottleTests(SecurityTestCase):
|
||||
{self.guest.get("/api/status/").status_code for _ in range(12)}, {200}
|
||||
)
|
||||
|
||||
def test_signed_media_urls_are_not_throttled(self):
|
||||
"""<img>/<video> tags fetch these without an Authorization header.
|
||||
|
||||
Regression: they were charged to the anonymous bucket, so galleries
|
||||
and the fish-greeting download started returning 429 JSON instead of
|
||||
the image bytes.
|
||||
"""
|
||||
item = self.make_item("throttle-media", owner=self.users["sec-uploader"])
|
||||
codes = {
|
||||
self.guest.get(f"/api/files/J-{item.id}/raw/").status_code
|
||||
for _ in range(150)
|
||||
}
|
||||
self.assertEqual(codes, {200})
|
||||
|
||||
def test_staged_upload_files_are_not_throttled(self):
|
||||
temp = TempUpload.objects.create(
|
||||
user=self.users["sec-uploader"],
|
||||
file=SimpleUploadedFile("throttle-temp.bin", b"staged"),
|
||||
original_filename="throttle-temp.bin",
|
||||
md5=hashlib.md5(b"throttle-temp").hexdigest(),
|
||||
size=6,
|
||||
)
|
||||
signature = signing.dumps(
|
||||
{"temp": str(temp.id), "user": self.users["sec-uploader"].id},
|
||||
salt=services.UPLOAD_FILE_SALT,
|
||||
)
|
||||
url = f"/api/uploads/{temp.id}/file/?sig={signature}"
|
||||
codes = {self.guest.get(url).status_code for _ in range(150)}
|
||||
self.assertEqual(codes, {200})
|
||||
|
||||
|
||||
class RemoteUrlTests(SecurityTestCase):
|
||||
def test_allowlist(self):
|
||||
|
||||
@@ -136,7 +136,12 @@ class SimilarityCheckViewSet(
|
||||
self.get_serializer(check).data, status=status.HTTP_201_CREATED
|
||||
)
|
||||
|
||||
@action(detail=True, methods=["get", "head"], permission_classes=[AllowAny])
|
||||
@action(
|
||||
detail=True,
|
||||
methods=["get", "head"],
|
||||
permission_classes=[AllowAny],
|
||||
throttle_classes=[],
|
||||
)
|
||||
def file(self, request, pk=None):
|
||||
"""Serve the temp file; accepts a signed URL like staged uploads."""
|
||||
check = None
|
||||
|
||||
@@ -381,7 +381,12 @@ class TempUploadViewSet(
|
||||
errors.append({"temp_id": value, "error": str(exc)})
|
||||
return Response({"discarded": discarded, "errors": errors})
|
||||
|
||||
@action(detail=True, methods=["get", "head"], permission_classes=[AllowAny])
|
||||
@action(
|
||||
detail=True,
|
||||
methods=["get", "head"],
|
||||
permission_classes=[AllowAny],
|
||||
throttle_classes=[],
|
||||
)
|
||||
def file(self, request, pk=None):
|
||||
"""Serve the staged file; accepts a signed URL for media tags."""
|
||||
user = request.user if request.user.is_authenticated else None
|
||||
|
||||
@@ -148,7 +148,7 @@ class MediaItemViewSet(
|
||||
return item
|
||||
return self.get_object()
|
||||
|
||||
@action(detail=True, methods=["get"])
|
||||
@action(detail=True, methods=["get"], throttle_classes=[])
|
||||
def raw(self, request, pk=None):
|
||||
item = self._media_object(request, "raw")
|
||||
location = item.locations.first()
|
||||
@@ -161,7 +161,7 @@ class MediaItemViewSet(
|
||||
request, location.path, download=request.query_params.get("download") == "1"
|
||||
)
|
||||
|
||||
@action(detail=True, methods=["get"])
|
||||
@action(detail=True, methods=["get"], throttle_classes=[])
|
||||
def thumbnail(self, request, pk=None):
|
||||
item = self._media_object(request, "thumbnail")
|
||||
location = item.locations.first()
|
||||
|
||||
@@ -255,6 +255,16 @@ CACHES = {
|
||||
|
||||
# Django REST Framework
|
||||
|
||||
# Private / tailnet-only deployments can drop the general anon+user limits
|
||||
# entirely (THROTTLE_ENABLED=false). The scoped guards below (login, register,
|
||||
# e621 proxy) and the media endpoints' own protections stay active either way.
|
||||
THROTTLE_ENABLED = os.getenv("THROTTLE_ENABLED", "true").strip().lower() not in {
|
||||
"0",
|
||||
"false",
|
||||
"no",
|
||||
"off",
|
||||
}
|
||||
|
||||
REST_FRAMEWORK = {
|
||||
"DEFAULT_AUTHENTICATION_CLASSES": [
|
||||
"rest_framework.authentication.TokenAuthentication",
|
||||
@@ -269,11 +279,18 @@ REST_FRAMEWORK = {
|
||||
],
|
||||
"DEFAULT_PAGINATION_CLASS": "config.pagination.StandardPagination",
|
||||
"PAGE_SIZE": 48,
|
||||
# Per-IP/per-user rate limits (counted in the shared Redis cache).
|
||||
"DEFAULT_THROTTLE_CLASSES": [
|
||||
# Per-IP/per-user rate limits (counted in the shared Redis cache). Signed
|
||||
# media URLs are deliberately excluded at the view level: <img>/<video>
|
||||
# tags fetch them without an Authorization header, so a library page would
|
||||
# otherwise burn the anonymous bucket and start returning JSON 429s.
|
||||
"DEFAULT_THROTTLE_CLASSES": (
|
||||
[
|
||||
"rest_framework.throttling.AnonRateThrottle",
|
||||
"rest_framework.throttling.UserRateThrottle",
|
||||
],
|
||||
]
|
||||
if THROTTLE_ENABLED
|
||||
else []
|
||||
),
|
||||
"DEFAULT_THROTTLE_RATES": {
|
||||
# Generous enough for the shell polling (status every 5s, stats every 2s).
|
||||
"anon": os.getenv("THROTTLE_ANON", "120/min"),
|
||||
|
||||
@@ -64,6 +64,10 @@ DB_ROOT_PASSWORD=j621root
|
||||
# THROTTLE_LOGIN=5/min
|
||||
# THROTTLE_REGISTER=20/hour
|
||||
# THROTTLE_E621_PROXY=60/hour
|
||||
# Tailnet-only / private deployments can drop the general limits entirely.
|
||||
# Signed media URLs (<img>/<video>) and the login/register/proxy guards are
|
||||
# exempt from this switch either way.
|
||||
# THROTTLE_ENABLED=false
|
||||
|
||||
# e621 media hosts the backend may fetch from (downloads, proxies)
|
||||
# E621_MEDIA_HOSTS=static1.e621.net,static2.e621.net,static3.e621.net
|
||||
|
||||
@@ -10,10 +10,16 @@ REGISTRY="gitea.rainbow-herring.ts.net/jakebreath/j621-backend"
|
||||
REGISTRY_HOST="$(printf '%s' "$REGISTRY" | cut -d/ -f1)"
|
||||
SHA="${1:-$(git rev-parse --short HEAD)}"
|
||||
BUILDER=multiarch
|
||||
PLATFORMS="linux/amd64,linux/arm64"
|
||||
PLATFORMS="${PLATFORMS:-linux/amd64,linux/arm64}"
|
||||
|
||||
echo "==> Logging in to $REGISTRY_HOST ..."
|
||||
docker login "$REGISTRY_HOST"
|
||||
if [ -n "${REGISTRY_USER:-}" ] && [ -n "${REGISTRY_TOKEN:-}" ]; then
|
||||
# Non-interactive login for CI (workflow passes GITHUB_TOKEN).
|
||||
printf '%s' "$REGISTRY_TOKEN" | docker login "$REGISTRY_HOST" \
|
||||
-u "$REGISTRY_USER" --password-stdin
|
||||
else
|
||||
docker login "$REGISTRY_HOST"
|
||||
fi
|
||||
|
||||
if ! docker buildx inspect "$BUILDER" >/dev/null 2>&1; then
|
||||
echo "==> Creating buildx builder '$BUILDER' ..."
|
||||
|
||||
@@ -10,10 +10,16 @@ REGISTRY="gitea.rainbow-herring.ts.net/jakebreath/j621-frontend"
|
||||
REGISTRY_HOST="$(printf '%s' "$REGISTRY" | cut -d/ -f1)"
|
||||
SHA="${1:-$(git rev-parse --short HEAD)}"
|
||||
BUILDER=multiarch
|
||||
PLATFORMS="linux/amd64,linux/arm64"
|
||||
PLATFORMS="${PLATFORMS:-linux/amd64,linux/arm64}"
|
||||
|
||||
echo "==> Logging in to $REGISTRY_HOST ..."
|
||||
docker login "$REGISTRY_HOST"
|
||||
if [ -n "${REGISTRY_USER:-}" ] && [ -n "${REGISTRY_TOKEN:-}" ]; then
|
||||
# Non-interactive login for CI (workflow passes GITHUB_TOKEN).
|
||||
printf '%s' "$REGISTRY_TOKEN" | docker login "$REGISTRY_HOST" \
|
||||
-u "$REGISTRY_USER" --password-stdin
|
||||
else
|
||||
docker login "$REGISTRY_HOST"
|
||||
fi
|
||||
|
||||
if ! docker buildx inspect "$BUILDER" >/dev/null 2>&1; then
|
||||
echo "==> Creating buildx builder '$BUILDER' ..."
|
||||
|
||||
@@ -89,18 +89,19 @@ export function effectiveCredentials(
|
||||
const GIT_HASH = typeof __GIT_HASH__ === "string" ? __GIT_HASH__ : "dev";
|
||||
const CLIENT_VERSION = `J621/${GIT_HASH} (JakeBreath)`;
|
||||
|
||||
// e621 allows 2 requests/second hard, 1/second sustained — and the IQDB
|
||||
// endpoint is stricter, so stay comfortably under it. Serialize every request
|
||||
// through a queue with a minimum gap.
|
||||
// e621 allows 2 requests/second hard, 1/second sustained. Serialize every
|
||||
// request through a queue with a minimum gap; IQDB is throttled much harder
|
||||
// by e621, so it gets a wider gap of its own.
|
||||
let lastRequestAt = 0;
|
||||
let queue: Promise<unknown> = Promise.resolve();
|
||||
|
||||
/** A hung request would block the whole serialized queue forever. */
|
||||
const REQUEST_TIMEOUT_MS = 20_000;
|
||||
const REQUEST_GAP_MS = 1500;
|
||||
const REQUEST_GAP_MS = 1000;
|
||||
const IQDB_GAP_MS = 2500;
|
||||
|
||||
/** A 429 (or a CORS-blocked failure) pauses every e621 call for a while. */
|
||||
const RATE_LIMIT_COOLDOWN_MS = 60_000;
|
||||
/** A 429 (or a CORS-blocked failure) pauses every e621 call briefly. */
|
||||
const RATE_LIMIT_COOLDOWN_MS = 15_000;
|
||||
const COOLDOWN_KEY = "j621.e621.cooldown";
|
||||
let cooldownUntil = 0;
|
||||
|
||||
@@ -143,10 +144,10 @@ function schedule<T>(task: () => Promise<T>): Promise<T> {
|
||||
return run;
|
||||
}
|
||||
|
||||
async function throttle(): Promise<void> {
|
||||
async function throttle(minGap = REQUEST_GAP_MS): Promise<void> {
|
||||
const wait = Math.max(
|
||||
0,
|
||||
lastRequestAt + REQUEST_GAP_MS - Date.now(),
|
||||
lastRequestAt + minGap - Date.now(),
|
||||
e621CooldownRemainingMs(),
|
||||
);
|
||||
if (wait > 0) {
|
||||
@@ -168,7 +169,9 @@ export function e621Request<T>(
|
||||
options: E621RequestOptions = {},
|
||||
): Promise<T> {
|
||||
return schedule(async () => {
|
||||
await throttle();
|
||||
await throttle(
|
||||
path.includes("iqdb_queries") ? IQDB_GAP_MS : REQUEST_GAP_MS,
|
||||
);
|
||||
|
||||
const base = credentials.base_url.replace(/\/+$/, "");
|
||||
const url = new URL(`${base}/${path.replace(/^\/+/, "")}`);
|
||||
|
||||
Reference in New Issue
Block a user