Compare commits
7
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
2eb7af0d41 | ||
|
|
7cecfeabc6 | ||
|
|
ed6178d12e | ||
|
|
8f9656ac0e | ||
|
|
72fc42217f | ||
|
|
d9c1e9e521 | ||
|
|
e2697c0a78 |
@@ -0,0 +1,182 @@
|
|||||||
|
# J621 CD — manual release workflow (Actions tab -> "Run workflow").
|
||||||
|
#
|
||||||
|
# One dispatch does everything; each half can be skipped with the `images`
|
||||||
|
# and `desktop` inputs:
|
||||||
|
# * builds and pushes the backend + frontend images (multi-arch, :latest
|
||||||
|
# and :<short-sha>, GIT_HASH baked in for the version pill),
|
||||||
|
# * builds the desktop packages and attaches them (plus the update
|
||||||
|
# metadata) to the Gitea release tagged `desktop-v<package.json version>`.
|
||||||
|
#
|
||||||
|
# The live update feed (deploy/data/desktop, served by the frontend nginx at
|
||||||
|
# /desktop/) is not touched here: it is runtime state on the deploy host and
|
||||||
|
# is still published with `deploy/push_desktop.sh --no-build` from a machine
|
||||||
|
# that can reach it.
|
||||||
|
#
|
||||||
|
# Registry login uses a repo PAT with the minimal write:package scope (the
|
||||||
|
# Gitea registry rejects the automatic job token, go-gitea/gitea#23642);
|
||||||
|
# release creation uses the automatic job token. Jobs run on the user-scoped
|
||||||
|
# nitro-ci runner (ubuntu-latest).
|
||||||
|
|
||||||
|
name: CD
|
||||||
|
|
||||||
|
on:
|
||||||
|
workflow_dispatch:
|
||||||
|
inputs:
|
||||||
|
images:
|
||||||
|
description: Build and push the Docker images
|
||||||
|
required: false
|
||||||
|
default: "true"
|
||||||
|
desktop:
|
||||||
|
description: Build the desktop release
|
||||||
|
required: false
|
||||||
|
default: "true"
|
||||||
|
platforms:
|
||||||
|
description: Image platforms (comma separated)
|
||||||
|
required: false
|
||||||
|
default: linux/amd64,linux/arm64
|
||||||
|
windows:
|
||||||
|
description: Also cross-build the Windows installer (needs wine, slow)
|
||||||
|
required: false
|
||||||
|
default: "false"
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: cd
|
||||||
|
cancel-in-progress: false
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
images:
|
||||||
|
name: Build & push images
|
||||||
|
if: ${{ inputs.images != 'false' }}
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
# The Gitea container registry does not accept the automatic job token
|
||||||
|
# (go-gitea/gitea#23642 is still open), so the push uses a repo PAT with
|
||||||
|
# the minimal write:package scope. Releases use the job token instead.
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
env:
|
||||||
|
REGISTRY_USER: ${{ secrets.REGISTRY_USER }}
|
||||||
|
REGISTRY_TOKEN: ${{ secrets.REGISTRY_TOKEN }}
|
||||||
|
PLATFORMS: ${{ inputs.platforms || 'linux/amd64,linux/arm64' }}
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
with:
|
||||||
|
fetch-depth: 0
|
||||||
|
|
||||||
|
- name: Check the registry credentials
|
||||||
|
run: |
|
||||||
|
if [ -z "$REGISTRY_USER" ] || [ -z "$REGISTRY_TOKEN" ]; then
|
||||||
|
echo "Set the REGISTRY_USER and REGISTRY_TOKEN repo secrets" >&2
|
||||||
|
echo "(a PAT with the write:package scope)." >&2
|
||||||
|
exit 1
|
||||||
|
fi
|
||||||
|
|
||||||
|
- name: Register binfmt (multi-arch builds)
|
||||||
|
run: docker run --privileged --rm tonistiigi/binfmt --install all
|
||||||
|
|
||||||
|
- name: Build & push both images
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
SHA="$(git rev-parse --short HEAD)"
|
||||||
|
echo "Publishing $SHA for $PLATFORMS"
|
||||||
|
PLATFORMS="$PLATFORMS" ./deploy/push_frontend.sh "$SHA"
|
||||||
|
PLATFORMS="$PLATFORMS" ./deploy/push_backend.sh "$SHA"
|
||||||
|
|
||||||
|
desktop:
|
||||||
|
name: Desktop release
|
||||||
|
if: ${{ inputs.desktop != 'false' }}
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
# Creating the release and uploading its assets uses the automatic job
|
||||||
|
# token, so it needs write access to the repository's releases.
|
||||||
|
permissions:
|
||||||
|
contents: write
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- uses: actions/setup-node@v4
|
||||||
|
with:
|
||||||
|
node-version: "22"
|
||||||
|
|
||||||
|
- name: Install packaging tools
|
||||||
|
run: |
|
||||||
|
sudo apt-get update
|
||||||
|
sudo apt-get install -y --no-install-recommends fakeroot libarchive-tools
|
||||||
|
if [ "${{ inputs.windows }}" = "true" ]; then
|
||||||
|
# electron-builder runs the 32-bit NSIS installer under wine to
|
||||||
|
# build the uninstaller: that needs a virtual display (Xvfb) and
|
||||||
|
# 32-bit wine libraries.
|
||||||
|
sudo dpkg --add-architecture i386
|
||||||
|
sudo apt-get update
|
||||||
|
sudo apt-get install -y --no-install-recommends xvfb wine wine32:i386
|
||||||
|
fi
|
||||||
|
|
||||||
|
- name: Install frontend + desktop dependencies
|
||||||
|
run: |
|
||||||
|
npm --prefix frontend ci --no-audit --no-fund
|
||||||
|
npm --prefix desktop ci --no-audit --no-fund
|
||||||
|
|
||||||
|
- name: Build desktop packages
|
||||||
|
env:
|
||||||
|
# Keep wine from trying to fetch Gecko/Mono on first run.
|
||||||
|
WINEDLLOVERRIDES: mscoree,mshtml=
|
||||||
|
run: |
|
||||||
|
if [ "${{ inputs.windows }}" = "true" ]; then
|
||||||
|
xvfb-run -a ./deploy/build_desktop.sh --all
|
||||||
|
else
|
||||||
|
./deploy/build_desktop.sh --linux
|
||||||
|
fi
|
||||||
|
|
||||||
|
- name: Add the Gitea release
|
||||||
|
env:
|
||||||
|
GITEA_TOKEN: ${{ secrets.GITEA_TOKEN || secrets.GITHUB_TOKEN }}
|
||||||
|
run: |
|
||||||
|
set -euo pipefail
|
||||||
|
VERSION="$(node -p "require('./desktop/package.json').version")"
|
||||||
|
TAG="desktop-v$VERSION"
|
||||||
|
API="${{ github.server_url }}/api/v1/repos/${{ github.repository }}"
|
||||||
|
AUTH="Authorization: token $GITEA_TOKEN"
|
||||||
|
|
||||||
|
NOTES="$(printf 'J621 desktop %s\n\n' "$VERSION"
|
||||||
|
cd desktop/release
|
||||||
|
sha256sum ./*.deb ./*.pkg.tar.zst ./*.exe 2>/dev/null || true)"
|
||||||
|
|
||||||
|
RELEASE_ID="$(curl -sf -H "$AUTH" "$API/releases/tags/$TAG" \
|
||||||
|
| python3 -c 'import json,sys; print(json.load(sys.stdin).get("id",""))' \
|
||||||
|
2>/dev/null || true)"
|
||||||
|
if [ -z "$RELEASE_ID" ]; then
|
||||||
|
echo "Creating release $TAG"
|
||||||
|
PAYLOAD="$(python3 - "$TAG" "${{ github.sha }}" "$NOTES" <<'PY'
|
||||||
|
import json, sys
|
||||||
|
print(json.dumps({
|
||||||
|
"tag_name": sys.argv[1],
|
||||||
|
"name": sys.argv[1],
|
||||||
|
"body": sys.argv[3],
|
||||||
|
"target_commitish": sys.argv[2],
|
||||||
|
}))
|
||||||
|
PY
|
||||||
|
)"
|
||||||
|
RELEASE_ID="$(curl -sf -X POST -H "$AUTH" \
|
||||||
|
-H "Content-Type: application/json" -d "$PAYLOAD" "$API/releases" \
|
||||||
|
| python3 -c 'import json,sys; print(json.load(sys.stdin)["id"])')"
|
||||||
|
else
|
||||||
|
echo "Release $TAG already exists (id $RELEASE_ID); attaching missing files."
|
||||||
|
fi
|
||||||
|
|
||||||
|
EXISTING="$(curl -sf -H "$AUTH" "$API/releases/$RELEASE_ID/assets" \
|
||||||
|
| python3 -c 'import json,sys; print("\n".join(a["name"] for a in json.load(sys.stdin)))' \
|
||||||
|
|| true)"
|
||||||
|
for FILE in desktop/release/*"$VERSION"*.deb \
|
||||||
|
desktop/release/*"$VERSION"*.pkg.tar.zst \
|
||||||
|
desktop/release/latest-linux.yml \
|
||||||
|
desktop/release/latest.yml \
|
||||||
|
desktop/release/*"$VERSION"*.exe \
|
||||||
|
desktop/release/*"$VERSION"*.exe.blockmap; do
|
||||||
|
[ -e "$FILE" ] || continue
|
||||||
|
NAME="$(basename "$FILE")"
|
||||||
|
case "$EXISTING" in
|
||||||
|
*"$NAME"*) echo " already attached: $NAME"; continue ;;
|
||||||
|
esac
|
||||||
|
echo " attaching $NAME"
|
||||||
|
curl -sf -X POST -H "$AUTH" -H "Content-Type: application/octet-stream" \
|
||||||
|
--data-binary @"$FILE" "$API/releases/$RELEASE_ID/assets?name=$NAME" >/dev/null
|
||||||
|
done
|
||||||
|
echo "Release: ${{ github.server_url }}/${{ github.repository }}/releases/tag/$TAG"
|
||||||
@@ -0,0 +1,101 @@
|
|||||||
|
# J621 CI — runs on every push (and pull request): Django checks + the full
|
||||||
|
# backend test suite against MariaDB/Redis, and the frontend type-check,
|
||||||
|
# lint and production build.
|
||||||
|
#
|
||||||
|
# Runner: the "nitro-ci" act_runner with the custom `ubuntu-latest` label.
|
||||||
|
|
||||||
|
name: CI
|
||||||
|
|
||||||
|
# Tests and builds only need to read the repository; the automatic job token
|
||||||
|
# stays read-only.
|
||||||
|
permissions:
|
||||||
|
contents: read
|
||||||
|
|
||||||
|
on:
|
||||||
|
push:
|
||||||
|
branches: ["**"]
|
||||||
|
tags-ignore: ["**"]
|
||||||
|
pull_request:
|
||||||
|
workflow_dispatch:
|
||||||
|
|
||||||
|
concurrency:
|
||||||
|
group: ci-${{ github.ref }}
|
||||||
|
cancel-in-progress: true
|
||||||
|
|
||||||
|
jobs:
|
||||||
|
backend:
|
||||||
|
name: Backend tests
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
services:
|
||||||
|
mariadb:
|
||||||
|
image: mariadb:11.4
|
||||||
|
env:
|
||||||
|
MARIADB_ROOT_PASSWORD: root
|
||||||
|
MARIADB_DATABASE: j621
|
||||||
|
MARIADB_USER: j621
|
||||||
|
MARIADB_PASSWORD: j621
|
||||||
|
options: >-
|
||||||
|
--health-cmd="healthcheck.sh --connect --innodb_initialized"
|
||||||
|
--health-interval=5s
|
||||||
|
--health-timeout=5s
|
||||||
|
--health-retries=12
|
||||||
|
redis:
|
||||||
|
image: redis:7-alpine
|
||||||
|
options: >-
|
||||||
|
--health-cmd="redis-cli ping"
|
||||||
|
--health-interval=5s
|
||||||
|
--health-timeout=5s
|
||||||
|
--health-retries=12
|
||||||
|
env:
|
||||||
|
# Connect as root so Django can create the test database itself;
|
||||||
|
# everything else mirrors the development defaults.
|
||||||
|
DB_HOST: mariadb
|
||||||
|
DB_PORT: "3306"
|
||||||
|
DB_NAME: j621
|
||||||
|
DB_USER: root
|
||||||
|
DB_PASSWORD: root
|
||||||
|
REDIS_URL: redis://redis:6379/1
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- uses: actions/setup-python@v5
|
||||||
|
with:
|
||||||
|
python-version: "3.14"
|
||||||
|
|
||||||
|
- name: Install backend dependencies
|
||||||
|
run: pip install -r backend/requirements.txt
|
||||||
|
|
||||||
|
- name: Django system checks
|
||||||
|
working-directory: backend
|
||||||
|
run: python manage.py check
|
||||||
|
|
||||||
|
- name: Backend tests
|
||||||
|
working-directory: backend
|
||||||
|
run: >-
|
||||||
|
python manage.py test
|
||||||
|
apps.core.tests
|
||||||
|
apps.library.tests
|
||||||
|
apps.follows.tests
|
||||||
|
apps.accounts.tests
|
||||||
|
|
||||||
|
frontend:
|
||||||
|
name: Frontend build & lint
|
||||||
|
runs-on: ubuntu-latest
|
||||||
|
steps:
|
||||||
|
- uses: actions/checkout@v4
|
||||||
|
|
||||||
|
- uses: actions/setup-node@v4
|
||||||
|
with:
|
||||||
|
node-version: "22"
|
||||||
|
|
||||||
|
- name: Install frontend dependencies
|
||||||
|
working-directory: frontend
|
||||||
|
run: npm ci
|
||||||
|
|
||||||
|
- name: Lint
|
||||||
|
working-directory: frontend
|
||||||
|
run: npm run lint
|
||||||
|
|
||||||
|
- name: Type-check & build
|
||||||
|
working-directory: frontend
|
||||||
|
run: npm run build
|
||||||
@@ -49,6 +49,16 @@ Project constraints (do not regress):
|
|||||||
- Periodic commands (follow syncs, similarity cleanup, guest blacklist
|
- Periodic commands (follow syncs, similarity cleanup, guest blacklist
|
||||||
refresh) run in the composes' `scheduler` service — the backend image with
|
refresh) run in the composes' `scheduler` service — the backend image with
|
||||||
the j621-scheduler entrypoint, intervals via J621_*_EVERY. No host cron.
|
the j621-scheduler entrypoint, intervals via J621_*_EVERY. No host cron.
|
||||||
|
- CI/CD lives in .gitea/workflows: ci.yml runs on every push/PR (Django checks
|
||||||
|
+ the full backend suite against MariaDB/Redis service containers, frontend
|
||||||
|
lint/type-check/build); cd.yml is manual and builds/pushes both images
|
||||||
|
multi-arch plus the desktop packages (attached to the Gitea release
|
||||||
|
`desktop-v<version>`). Jobs run on the user-scoped runners: `ubuntu-latest`
|
||||||
|
on nitro-ci, `desktop` on msi-mortar-ci. Do not add actions/cache
|
||||||
|
(`cache: pip`/`npm`) to these workflows: Gitea's cache service hangs the job
|
||||||
|
on restore/save. The live desktop update feed (deploy/data/desktop) is still
|
||||||
|
published with `deploy/push_desktop.sh --no-build` from a machine with SSH
|
||||||
|
to the deploy host — CI has no key for that.
|
||||||
- Security/permission tests live in backend/apps/core/tests and need a
|
- Security/permission tests live in backend/apps/core/tests and need a
|
||||||
one-time grant: GRANT ALL ON `test_j621`.* TO 'j621'@'%';
|
one-time grant: GRANT ALL ON `test_j621`.* TO 'j621'@'%';
|
||||||
|
|
||||||
@@ -85,7 +95,12 @@ Security hardening (do not weaken):
|
|||||||
SECRET_KEY (apps/accounts/crypto.py); rotating SECRET_KEY invalidates them
|
SECRET_KEY (apps/accounts/crypto.py); rotating SECRET_KEY invalidates them
|
||||||
(and all signed media URLs), so users must re-enter the key.
|
(and all signed media URLs), so users must re-enter the key.
|
||||||
- API throttles live in REST_FRAMEWORK (env-overridable): anon 120/min,
|
- API throttles live in REST_FRAMEWORK (env-overridable): anon 120/min,
|
||||||
user 600/min, login 5/min, register 20/hour, e621_proxy 60/hour.
|
user 600/min, login 5/min, register 20/hour, e621_proxy 60/hour. Signed
|
||||||
|
media URLs (raw/thumbnail/staged-file/similarity-file actions) are exempt
|
||||||
|
on purpose: <img>/<video> tags fetch them without an Authorization header,
|
||||||
|
so a gallery would otherwise drain the anonymous bucket and get 429 JSON
|
||||||
|
instead of images. THROTTLE_ENABLED=false removes the anon+user limits for
|
||||||
|
private/tailnet deployments (the login/register/proxy guards stay).
|
||||||
- Only admins (superusers) may grant/revoke the staff role or delete
|
- Only admins (superusers) may grant/revoke the staff role or delete
|
||||||
staff/admin accounts; staff manage regular/uploader accounts only.
|
staff/admin accounts; staff manage regular/uploader accounts only.
|
||||||
- Storage, duplicates, delete, temp-clear, uploads and downloads require
|
- Storage, duplicates, delete, temp-clear, uploads and downloads require
|
||||||
|
|||||||
@@ -429,6 +429,36 @@ class ThrottleTests(SecurityTestCase):
|
|||||||
{self.guest.get("/api/status/").status_code for _ in range(12)}, {200}
|
{self.guest.get("/api/status/").status_code for _ in range(12)}, {200}
|
||||||
)
|
)
|
||||||
|
|
||||||
|
def test_signed_media_urls_are_not_throttled(self):
|
||||||
|
"""<img>/<video> tags fetch these without an Authorization header.
|
||||||
|
|
||||||
|
Regression: they were charged to the anonymous bucket, so galleries
|
||||||
|
and the fish-greeting download started returning 429 JSON instead of
|
||||||
|
the image bytes.
|
||||||
|
"""
|
||||||
|
item = self.make_item("throttle-media", owner=self.users["sec-uploader"])
|
||||||
|
codes = {
|
||||||
|
self.guest.get(f"/api/files/J-{item.id}/raw/").status_code
|
||||||
|
for _ in range(150)
|
||||||
|
}
|
||||||
|
self.assertEqual(codes, {200})
|
||||||
|
|
||||||
|
def test_staged_upload_files_are_not_throttled(self):
|
||||||
|
temp = TempUpload.objects.create(
|
||||||
|
user=self.users["sec-uploader"],
|
||||||
|
file=SimpleUploadedFile("throttle-temp.bin", b"staged"),
|
||||||
|
original_filename="throttle-temp.bin",
|
||||||
|
md5=hashlib.md5(b"throttle-temp").hexdigest(),
|
||||||
|
size=6,
|
||||||
|
)
|
||||||
|
signature = signing.dumps(
|
||||||
|
{"temp": str(temp.id), "user": self.users["sec-uploader"].id},
|
||||||
|
salt=services.UPLOAD_FILE_SALT,
|
||||||
|
)
|
||||||
|
url = f"/api/uploads/{temp.id}/file/?sig={signature}"
|
||||||
|
codes = {self.guest.get(url).status_code for _ in range(150)}
|
||||||
|
self.assertEqual(codes, {200})
|
||||||
|
|
||||||
|
|
||||||
class RemoteUrlTests(SecurityTestCase):
|
class RemoteUrlTests(SecurityTestCase):
|
||||||
def test_allowlist(self):
|
def test_allowlist(self):
|
||||||
|
|||||||
@@ -136,7 +136,12 @@ class SimilarityCheckViewSet(
|
|||||||
self.get_serializer(check).data, status=status.HTTP_201_CREATED
|
self.get_serializer(check).data, status=status.HTTP_201_CREATED
|
||||||
)
|
)
|
||||||
|
|
||||||
@action(detail=True, methods=["get", "head"], permission_classes=[AllowAny])
|
@action(
|
||||||
|
detail=True,
|
||||||
|
methods=["get", "head"],
|
||||||
|
permission_classes=[AllowAny],
|
||||||
|
throttle_classes=[],
|
||||||
|
)
|
||||||
def file(self, request, pk=None):
|
def file(self, request, pk=None):
|
||||||
"""Serve the temp file; accepts a signed URL like staged uploads."""
|
"""Serve the temp file; accepts a signed URL like staged uploads."""
|
||||||
check = None
|
check = None
|
||||||
|
|||||||
@@ -381,7 +381,12 @@ class TempUploadViewSet(
|
|||||||
errors.append({"temp_id": value, "error": str(exc)})
|
errors.append({"temp_id": value, "error": str(exc)})
|
||||||
return Response({"discarded": discarded, "errors": errors})
|
return Response({"discarded": discarded, "errors": errors})
|
||||||
|
|
||||||
@action(detail=True, methods=["get", "head"], permission_classes=[AllowAny])
|
@action(
|
||||||
|
detail=True,
|
||||||
|
methods=["get", "head"],
|
||||||
|
permission_classes=[AllowAny],
|
||||||
|
throttle_classes=[],
|
||||||
|
)
|
||||||
def file(self, request, pk=None):
|
def file(self, request, pk=None):
|
||||||
"""Serve the staged file; accepts a signed URL for media tags."""
|
"""Serve the staged file; accepts a signed URL for media tags."""
|
||||||
user = request.user if request.user.is_authenticated else None
|
user = request.user if request.user.is_authenticated else None
|
||||||
|
|||||||
@@ -148,7 +148,7 @@ class MediaItemViewSet(
|
|||||||
return item
|
return item
|
||||||
return self.get_object()
|
return self.get_object()
|
||||||
|
|
||||||
@action(detail=True, methods=["get"])
|
@action(detail=True, methods=["get"], throttle_classes=[])
|
||||||
def raw(self, request, pk=None):
|
def raw(self, request, pk=None):
|
||||||
item = self._media_object(request, "raw")
|
item = self._media_object(request, "raw")
|
||||||
location = item.locations.first()
|
location = item.locations.first()
|
||||||
@@ -161,7 +161,7 @@ class MediaItemViewSet(
|
|||||||
request, location.path, download=request.query_params.get("download") == "1"
|
request, location.path, download=request.query_params.get("download") == "1"
|
||||||
)
|
)
|
||||||
|
|
||||||
@action(detail=True, methods=["get"])
|
@action(detail=True, methods=["get"], throttle_classes=[])
|
||||||
def thumbnail(self, request, pk=None):
|
def thumbnail(self, request, pk=None):
|
||||||
item = self._media_object(request, "thumbnail")
|
item = self._media_object(request, "thumbnail")
|
||||||
location = item.locations.first()
|
location = item.locations.first()
|
||||||
|
|||||||
@@ -255,6 +255,16 @@ CACHES = {
|
|||||||
|
|
||||||
# Django REST Framework
|
# Django REST Framework
|
||||||
|
|
||||||
|
# Private / tailnet-only deployments can drop the general anon+user limits
|
||||||
|
# entirely (THROTTLE_ENABLED=false). The scoped guards below (login, register,
|
||||||
|
# e621 proxy) and the media endpoints' own protections stay active either way.
|
||||||
|
THROTTLE_ENABLED = os.getenv("THROTTLE_ENABLED", "true").strip().lower() not in {
|
||||||
|
"0",
|
||||||
|
"false",
|
||||||
|
"no",
|
||||||
|
"off",
|
||||||
|
}
|
||||||
|
|
||||||
REST_FRAMEWORK = {
|
REST_FRAMEWORK = {
|
||||||
"DEFAULT_AUTHENTICATION_CLASSES": [
|
"DEFAULT_AUTHENTICATION_CLASSES": [
|
||||||
"rest_framework.authentication.TokenAuthentication",
|
"rest_framework.authentication.TokenAuthentication",
|
||||||
@@ -269,11 +279,18 @@ REST_FRAMEWORK = {
|
|||||||
],
|
],
|
||||||
"DEFAULT_PAGINATION_CLASS": "config.pagination.StandardPagination",
|
"DEFAULT_PAGINATION_CLASS": "config.pagination.StandardPagination",
|
||||||
"PAGE_SIZE": 48,
|
"PAGE_SIZE": 48,
|
||||||
# Per-IP/per-user rate limits (counted in the shared Redis cache).
|
# Per-IP/per-user rate limits (counted in the shared Redis cache). Signed
|
||||||
"DEFAULT_THROTTLE_CLASSES": [
|
# media URLs are deliberately excluded at the view level: <img>/<video>
|
||||||
|
# tags fetch them without an Authorization header, so a library page would
|
||||||
|
# otherwise burn the anonymous bucket and start returning JSON 429s.
|
||||||
|
"DEFAULT_THROTTLE_CLASSES": (
|
||||||
|
[
|
||||||
"rest_framework.throttling.AnonRateThrottle",
|
"rest_framework.throttling.AnonRateThrottle",
|
||||||
"rest_framework.throttling.UserRateThrottle",
|
"rest_framework.throttling.UserRateThrottle",
|
||||||
],
|
]
|
||||||
|
if THROTTLE_ENABLED
|
||||||
|
else []
|
||||||
|
),
|
||||||
"DEFAULT_THROTTLE_RATES": {
|
"DEFAULT_THROTTLE_RATES": {
|
||||||
# Generous enough for the shell polling (status every 5s, stats every 2s).
|
# Generous enough for the shell polling (status every 5s, stats every 2s).
|
||||||
"anon": os.getenv("THROTTLE_ANON", "120/min"),
|
"anon": os.getenv("THROTTLE_ANON", "120/min"),
|
||||||
|
|||||||
@@ -64,6 +64,10 @@ DB_ROOT_PASSWORD=j621root
|
|||||||
# THROTTLE_LOGIN=5/min
|
# THROTTLE_LOGIN=5/min
|
||||||
# THROTTLE_REGISTER=20/hour
|
# THROTTLE_REGISTER=20/hour
|
||||||
# THROTTLE_E621_PROXY=60/hour
|
# THROTTLE_E621_PROXY=60/hour
|
||||||
|
# Tailnet-only / private deployments can drop the general limits entirely.
|
||||||
|
# Signed media URLs (<img>/<video>) and the login/register/proxy guards are
|
||||||
|
# exempt from this switch either way.
|
||||||
|
# THROTTLE_ENABLED=false
|
||||||
|
|
||||||
# e621 media hosts the backend may fetch from (downloads, proxies)
|
# e621 media hosts the backend may fetch from (downloads, proxies)
|
||||||
# E621_MEDIA_HOSTS=static1.e621.net,static2.e621.net,static3.e621.net
|
# E621_MEDIA_HOSTS=static1.e621.net,static2.e621.net,static3.e621.net
|
||||||
|
|||||||
@@ -164,6 +164,16 @@ does not. The desktop app's "Check for updates…" menu item reads
|
|||||||
`latest-linux.yml` / `latest.yml` from there (see `desktop/README.md`).
|
`latest-linux.yml` / `latest.yml` from there (see `desktop/README.md`).
|
||||||
Backend-only composes have no frontend, so no feed.
|
Backend-only composes have no frontend, so no feed.
|
||||||
|
|
||||||
|
The manual **CD** workflow (Actions tab) builds the desktop packages on the
|
||||||
|
runner and attaches them plus the update metadata to the Gitea release
|
||||||
|
`desktop-v<version>`; it does not touch the live feed, because that is
|
||||||
|
runtime state on the deploy host and CI has no SSH key for it. After a CD run,
|
||||||
|
publish the feed from a machine that can reach the deploy checkout:
|
||||||
|
|
||||||
|
```bash
|
||||||
|
./push_desktop.sh --no-build --local # or without --local to also copy it
|
||||||
|
```
|
||||||
|
|
||||||
## Scheduled jobs
|
## Scheduled jobs
|
||||||
|
|
||||||
Compose files with a backend also run a **`scheduler`** service — the same
|
Compose files with a backend also run a **`scheduler`** service — the same
|
||||||
|
|||||||
@@ -10,10 +10,16 @@ REGISTRY="gitea.rainbow-herring.ts.net/jakebreath/j621-backend"
|
|||||||
REGISTRY_HOST="$(printf '%s' "$REGISTRY" | cut -d/ -f1)"
|
REGISTRY_HOST="$(printf '%s' "$REGISTRY" | cut -d/ -f1)"
|
||||||
SHA="${1:-$(git rev-parse --short HEAD)}"
|
SHA="${1:-$(git rev-parse --short HEAD)}"
|
||||||
BUILDER=multiarch
|
BUILDER=multiarch
|
||||||
PLATFORMS="linux/amd64,linux/arm64"
|
PLATFORMS="${PLATFORMS:-linux/amd64,linux/arm64}"
|
||||||
|
|
||||||
echo "==> Logging in to $REGISTRY_HOST ..."
|
echo "==> Logging in to $REGISTRY_HOST ..."
|
||||||
docker login "$REGISTRY_HOST"
|
if [ -n "${REGISTRY_USER:-}" ] && [ -n "${REGISTRY_TOKEN:-}" ]; then
|
||||||
|
# Non-interactive login for CI (workflow passes GITHUB_TOKEN).
|
||||||
|
printf '%s' "$REGISTRY_TOKEN" | docker login "$REGISTRY_HOST" \
|
||||||
|
-u "$REGISTRY_USER" --password-stdin
|
||||||
|
else
|
||||||
|
docker login "$REGISTRY_HOST"
|
||||||
|
fi
|
||||||
|
|
||||||
if ! docker buildx inspect "$BUILDER" >/dev/null 2>&1; then
|
if ! docker buildx inspect "$BUILDER" >/dev/null 2>&1; then
|
||||||
echo "==> Creating buildx builder '$BUILDER' ..."
|
echo "==> Creating buildx builder '$BUILDER' ..."
|
||||||
|
|||||||
@@ -10,10 +10,16 @@ REGISTRY="gitea.rainbow-herring.ts.net/jakebreath/j621-frontend"
|
|||||||
REGISTRY_HOST="$(printf '%s' "$REGISTRY" | cut -d/ -f1)"
|
REGISTRY_HOST="$(printf '%s' "$REGISTRY" | cut -d/ -f1)"
|
||||||
SHA="${1:-$(git rev-parse --short HEAD)}"
|
SHA="${1:-$(git rev-parse --short HEAD)}"
|
||||||
BUILDER=multiarch
|
BUILDER=multiarch
|
||||||
PLATFORMS="linux/amd64,linux/arm64"
|
PLATFORMS="${PLATFORMS:-linux/amd64,linux/arm64}"
|
||||||
|
|
||||||
echo "==> Logging in to $REGISTRY_HOST ..."
|
echo "==> Logging in to $REGISTRY_HOST ..."
|
||||||
docker login "$REGISTRY_HOST"
|
if [ -n "${REGISTRY_USER:-}" ] && [ -n "${REGISTRY_TOKEN:-}" ]; then
|
||||||
|
# Non-interactive login for CI (workflow passes GITHUB_TOKEN).
|
||||||
|
printf '%s' "$REGISTRY_TOKEN" | docker login "$REGISTRY_HOST" \
|
||||||
|
-u "$REGISTRY_USER" --password-stdin
|
||||||
|
else
|
||||||
|
docker login "$REGISTRY_HOST"
|
||||||
|
fi
|
||||||
|
|
||||||
if ! docker buildx inspect "$BUILDER" >/dev/null 2>&1; then
|
if ! docker buildx inspect "$BUILDER" >/dev/null 2>&1; then
|
||||||
echo "==> Creating buildx builder '$BUILDER' ..."
|
echo "==> Creating buildx builder '$BUILDER' ..."
|
||||||
|
|||||||
@@ -89,18 +89,19 @@ export function effectiveCredentials(
|
|||||||
const GIT_HASH = typeof __GIT_HASH__ === "string" ? __GIT_HASH__ : "dev";
|
const GIT_HASH = typeof __GIT_HASH__ === "string" ? __GIT_HASH__ : "dev";
|
||||||
const CLIENT_VERSION = `J621/${GIT_HASH} (JakeBreath)`;
|
const CLIENT_VERSION = `J621/${GIT_HASH} (JakeBreath)`;
|
||||||
|
|
||||||
// e621 allows 2 requests/second hard, 1/second sustained — and the IQDB
|
// e621 allows 2 requests/second hard, 1/second sustained. Serialize every
|
||||||
// endpoint is stricter, so stay comfortably under it. Serialize every request
|
// request through a queue with a minimum gap; IQDB is throttled much harder
|
||||||
// through a queue with a minimum gap.
|
// by e621, so it gets a wider gap of its own.
|
||||||
let lastRequestAt = 0;
|
let lastRequestAt = 0;
|
||||||
let queue: Promise<unknown> = Promise.resolve();
|
let queue: Promise<unknown> = Promise.resolve();
|
||||||
|
|
||||||
/** A hung request would block the whole serialized queue forever. */
|
/** A hung request would block the whole serialized queue forever. */
|
||||||
const REQUEST_TIMEOUT_MS = 20_000;
|
const REQUEST_TIMEOUT_MS = 20_000;
|
||||||
const REQUEST_GAP_MS = 1500;
|
const REQUEST_GAP_MS = 1000;
|
||||||
|
const IQDB_GAP_MS = 2500;
|
||||||
|
|
||||||
/** A 429 (or a CORS-blocked failure) pauses every e621 call for a while. */
|
/** A 429 (or a CORS-blocked failure) pauses every e621 call briefly. */
|
||||||
const RATE_LIMIT_COOLDOWN_MS = 60_000;
|
const RATE_LIMIT_COOLDOWN_MS = 15_000;
|
||||||
const COOLDOWN_KEY = "j621.e621.cooldown";
|
const COOLDOWN_KEY = "j621.e621.cooldown";
|
||||||
let cooldownUntil = 0;
|
let cooldownUntil = 0;
|
||||||
|
|
||||||
@@ -143,10 +144,10 @@ function schedule<T>(task: () => Promise<T>): Promise<T> {
|
|||||||
return run;
|
return run;
|
||||||
}
|
}
|
||||||
|
|
||||||
async function throttle(): Promise<void> {
|
async function throttle(minGap = REQUEST_GAP_MS): Promise<void> {
|
||||||
const wait = Math.max(
|
const wait = Math.max(
|
||||||
0,
|
0,
|
||||||
lastRequestAt + REQUEST_GAP_MS - Date.now(),
|
lastRequestAt + minGap - Date.now(),
|
||||||
e621CooldownRemainingMs(),
|
e621CooldownRemainingMs(),
|
||||||
);
|
);
|
||||||
if (wait > 0) {
|
if (wait > 0) {
|
||||||
@@ -168,7 +169,9 @@ export function e621Request<T>(
|
|||||||
options: E621RequestOptions = {},
|
options: E621RequestOptions = {},
|
||||||
): Promise<T> {
|
): Promise<T> {
|
||||||
return schedule(async () => {
|
return schedule(async () => {
|
||||||
await throttle();
|
await throttle(
|
||||||
|
path.includes("iqdb_queries") ? IQDB_GAP_MS : REQUEST_GAP_MS,
|
||||||
|
);
|
||||||
|
|
||||||
const base = credentials.base_url.replace(/\/+$/, "");
|
const base = credentials.base_url.replace(/\/+$/, "");
|
||||||
const url = new URL(`${base}/${path.replace(/^\/+/, "")}`);
|
const url = new URL(`${base}/${path.replace(/^\/+/, "")}`);
|
||||||
|
|||||||
Reference in New Issue
Block a user