Compare commits

..
Author SHA1 Message Date
raucao 64d12c6658 Merge branch 'master' into live 2026-08-10 21:37:50 -06:00
raucao 7df61ddcd7 Merge branch 'master' into live 2026-08-10 17:24:47 -06:00
raucao 34cd98625c Merge branch 'master' into live 2026-08-10 17:12:06 -06:00
raucao fa64cf64a2 Merge branch 'master' into live 2026-08-10 14:24:57 -06:00
raucao 8336930077 Merge branch 'master' into live 2026-08-09 18:51:24 -06:00
raucao 1a69f59b32 Merge branch 'master' into live 2026-08-09 14:31:39 -06:00
raucao 975d1ca614 Merge branch 'master' into live
continuous-integration/drone/push Build is failing
2026-08-07 12:38:27 -06:00
raucao 28127bc1f5 Gah 2026-07-09 16:53:29 +02:00
raucao 93e4a65a00 Point tailwind command at module executable 2026-07-09 16:45:16 +02:00
raucao 8728684c21 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-06-12 16:10:06 +04:00
raucao dfb5b6b794 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-06-12 15:39:15 +04:00
raucao 8cf138b035 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-05-28 14:51:31 +04:00
raucao d48f1caa28 Merge branch 'master' into live
continuous-integration/drone/push Build is failing
2025-05-28 14:29:09 +04:00
raucao 6a2ad475be Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-05-28 13:26:51 +04:00
raucao 942ae25f09 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-05-23 14:10:16 +04:00
raucao b6968f1742 Merge branch 'feature/mastodon_api' into live
continuous-integration/drone/push Build is passing
2025-05-18 14:56:52 +04:00
raucao 4f4e086518 Merge branch 'feature/mastodon_api' into live
continuous-integration/drone/push Build is passing
2025-05-18 14:46:33 +04:00
raucao a04a1479f8 Merge branch 'feature/mastodon_api' into live
continuous-integration/drone/push Build is passing
2025-05-18 14:38:00 +04:00
raucao 613090d38a Merge branch 'feature/mastodon_api' into live
continuous-integration/drone/push Build is passing
2025-05-17 18:57:10 +04:00
raucao f1c540537a Merge branch 'feature/mastodon_api' into live
continuous-integration/drone/push Build is passing
2025-05-17 18:22:38 +04:00
raucao 1dcdc2b032 Allow syncing a single Mastodon profile
continuous-integration/drone/push Build is passing
2025-05-17 18:22:11 +04:00
raucao 4545c3ba19 Merge branch 'feature/mastodon_api' into live
continuous-integration/drone/push Build is passing
2025-05-17 18:12:57 +04:00
raucao bfa1514181 Update doc
continuous-integration/drone/push Build is passing
2025-05-17 18:11:17 +04:00
raucao f0846308da Only update other avatars in one place
continuous-integration/drone/push Build is passing
Prevent future mistakes
2025-05-17 18:02:13 +04:00
raucao b3b7fe6359 Don't queue job when service isn't enabled 2025-05-17 18:02:13 +04:00
raucao f0b541ee50 Add avatar to admin user page 2025-05-17 18:02:13 +04:00
raucao df9077e3c1 Sync Mastodon IDs/profiles to local accounts
Add a new service to import some data from Mastodon accounts:

* Find users by username, store Mastodon account ID in local db when
  found
* Import display name (don't overwrite existing)
* Import avatar (don't overwrite existing)
2025-05-17 18:02:07 +04:00
raucao 74666130c0 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-05-16 17:30:30 +04:00
raucao 7c43a4d919 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-05-16 16:01:31 +04:00
raucao 520552ec70 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-05-16 15:38:20 +04:00
raucao 307095bfd0 WTF
continuous-integration/drone/push Build is passing
2025-05-15 22:21:33 +04:00
raucao ae7291d4f1 Merge branch 'feature/ejabberd_pep' into live
continuous-integration/drone/push Build is failing
2025-05-15 22:07:26 +04:00
raucao 322ca98da9 Merge branch 'feature/ejabberd_pep' into live
continuous-integration/drone/push Build is passing
2025-05-15 20:05:30 +04:00
raucao 66f3950b83 Add job for setting avatar via XMPP 2025-05-15 20:04:55 +04:00
raucao 4e115eb514 Merge branch 'feature/ejabberd_pep' into live
continuous-integration/drone/push Build is failing
2025-05-15 19:50:30 +04:00
raucao fc9b471a10 Add job for setting avatar via XMPP 2025-05-15 19:50:05 +04:00
raucao b33e47e60f Merge branch 'feature/ejabberd_pep' into live
continuous-integration/drone/push Build is passing
2025-05-15 12:54:25 +04:00
raucao 9878e4a3e8 Merge branch 'feature/ejabberd_pep' into live
continuous-integration/drone/push Build is passing
2025-05-15 12:38:58 +04:00
raucao 9c35323bcd Return response for ejabberd API calls 2025-05-15 12:38:40 +04:00
raucao e2716d94c0 Merge branch 'feature/ejabberd_pep' into live
continuous-integration/drone/push Build is passing
2025-05-15 12:22:29 +04:00
raucao 9394f649a6 Merge branch 'feature/ejabberd_pep' into live
continuous-integration/drone/push Build is passing
2025-05-15 12:02:05 +04:00
raucao 41b9cb722b Merge branch 'feature/ejabberd_pep' into live
continuous-integration/drone/push Build is passing
2025-05-15 11:48:10 +04:00
raucao f1c13d7bd9 Add private_get to ejabberd service
continuous-integration/drone/push Build is passing
2025-05-15 11:47:23 +04:00
raucao c6cb9caa6d Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-05-14 18:58:38 +04:00
raucao 208977177a Merge branch 'feature/user_avatars' into live
continuous-integration/drone/push Build is passing
2025-05-14 15:40:47 +04:00
raucao 9a406b8381 Merge branch 'feature/user_avatars' into live
continuous-integration/drone/push Build is passing
2025-05-14 14:44:14 +04:00
raucao 4c972bfe7a Merge branch 'feature/user_avatars' into live
continuous-integration/drone/push Build is passing
2025-05-12 16:40:44 +04:00
raucao 0191d248f8 Merge branch 'feature/user_avatars' into live
continuous-integration/drone/push Build is passing
2025-05-12 15:11:39 +04:00
raucao 710afb6c78 Merge branch 'chore/215-configs' into live
continuous-integration/drone/push Build is passing
2025-05-06 20:14:42 +04:00
raucao 69e9662133 Merge branch 'chore/215-configs' into live
continuous-integration/drone/push Build is failing
2025-05-06 20:01:15 +04:00
raucao a73d0f29bd Merge branch 'chore/215-configs' into live
continuous-integration/drone/push Build is passing
2025-05-06 19:53:52 +04:00
raucao 7836805570 Merge branch 'chore/215-configs' into live
continuous-integration/drone/push Build is passing
2025-05-06 19:04:03 +04:00
raucao 1fc434cb3a Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-05-05 17:39:06 +04:00
raucao dad7d5195e Merge branch 'chore/db_configs' into live
continuous-integration/drone/push Build is passing
2025-05-05 15:28:16 +04:00
raucao 596cad34da Merge branch 'chore/upgrade_rails' into live 2025-04-29 17:25:25 +04:00
raucao aaee5cb4ed Merge branch 'chore/upgrade_rails' into live
continuous-integration/drone/push Build is passing
2025-04-28 17:56:57 +04:00
raucao ebaca5ba65 Merge branch 'chore/upgrade_rails' into live 2025-04-28 15:58:17 +04:00
raucao b6bcfa2ee3 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-04-18 14:54:01 +04:00
raucao 9082ee45d8 Merge branch 'master' into live 2025-01-02 08:32:15 -05:00
raucao 29264aad98 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-10-16 13:33:35 +02:00
raucao 259b51a95e Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-09-24 21:40:25 +02:00
raucao fb369530e3 Merge branch 'master' into live
continuous-integration/drone/push Build is failing
2024-09-14 17:18:09 +02:00
raucao 5dc10a4d33 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-09-14 16:46:27 +02:00
raucao 2297c68046 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-09-14 16:41:01 +02:00
raucao b82ab45c99 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-09-14 14:57:35 +02:00
raucao d12c63db26 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-09-10 16:07:24 +02:00
raucao e6a9ef84ce Merge branch 'master' into live
continuous-integration/drone/push Build is failing
2024-08-19 15:13:46 +02:00
raucao b7e91344a0 Merge branch 'master' into live
continuous-integration/drone/push Build is failing
2024-08-19 14:48:35 +02:00
raucao 0f07e32781 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-08-17 14:49:29 +02:00
raucao 1311b5ed6a Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-08-17 14:46:00 +02:00
raucao 12f82061e8 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-08-17 14:42:32 +02:00
raucao a07b4369ab Hide njump link for users without pubkey
continuous-integration/drone/push Build is passing
2024-06-23 17:33:34 +02:00
raucao 2605c06807 Merge branch 'feature/admin_pages' into live
continuous-integration/drone/push Build is passing
2024-06-23 17:30:22 +02:00
raucao 1db768fb15 Merge branch 'feature/admin_pages' into live
continuous-integration/drone/push Build is passing
2024-06-23 17:27:03 +02:00
raucao 8a7403df32 Merge branch 'feature/own_relay' into live
continuous-integration/drone/push Build is passing
2024-06-20 15:52:03 +02:00
raucao f0295fef7a Merge branch 'feature/own_relay' into live
continuous-integration/drone/push Build is passing
2024-06-20 15:28:55 +02:00
raucao 090affd304 Merge branch 'feature/own_relay' into live
continuous-integration/drone/push Build is passing
2024-06-20 14:51:20 +02:00
raucao bafddd436b Merge branch 'feature/own_relay' into live
continuous-integration/drone/push Build is passing
2024-06-20 13:59:59 +02:00
raucao 560f193c4b Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-06-20 13:56:11 +02:00
raucao 8aabbad5bb Merge branch 'feature/strfry_zap_receipts' into live 2024-06-20 13:56:00 +02:00
raucao ba8d21eb7a Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-06-09 13:29:57 +02:00
raucao 53df455d53 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-06-09 13:17:51 +02:00
raucao 9f1af3a9aa Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-06-07 14:13:53 +02:00
raucao 1d09008ce2 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-06-04 17:45:13 +02:00
raucao 57c5317c38 Merge branch 'feature/170-nostr_zaps' into live
continuous-integration/drone/push Build is passing
2024-05-21 18:29:13 +02:00
raucao 41bd920060 Merge branch 'feature/170-nostr_zaps' into live
continuous-integration/drone/push Build is passing
2024-05-21 18:09:09 +02:00
raucao 0815fa6040 Merge branch 'feature/170-nostr_zaps' into live
continuous-integration/drone/push Build is passing
2024-05-19 17:07:58 +02:00
raucao af0e99aa50 Merge branch 'feature/170-nostr_zaps' into live
continuous-integration/drone/push Build is passing
2024-05-19 16:55:10 +02:00
raucao f05eec5255 Merge branch 'feature/170-nostr_zaps' into live
continuous-integration/drone/push Build is passing
2024-05-19 16:48:28 +02:00
raucao 66ca2dc6b0 Merge branch 'feature/173-nostr_ldap' into live
continuous-integration/drone/push Build is passing
2024-05-19 13:44:24 +02:00
raucao 800183e9da Increase sidekiq concurrency in prod
continuous-integration/drone/push Build is passing
2024-05-19 13:44:01 +02:00
18 changed files with 69 additions and 196 deletions

No files matched your search

+4 -7
View File
@@ -7,16 +7,13 @@ ejabberd, Discourse, Mastodon, remoteStorage, Nostr, LNDHub, and BTCPay.
## Development environment
Development runs in Docker Compose — run all commands against the `web` container.
Start services: `docker compose up` (web, ldap, redis, garage, liquor-cabinet, strfry).
Start services: `docker compose up` (web, ldap, redis, minio, liquor-cabinet, strfry).
The `web` service runs `bin/dev` (foreman: Puma + Tailwind CSS watcher) and embeds
Solid Queue workers (`SOLID_QUEUE_IN_PUMA=true`).
First-time LDAP and database setup is automated: the `ldap-init` service
creates the 389ds back-end, then the `web` entrypoint seeds LDAP and the
databases on first start and runs `db:prepare` on every boot. Manual
equivalents: `docker compose exec ldap dsconf localhost backend create
--suffix="dc=kosmos,dc=org" --be-name="dev"` and `docker compose run --rm web
bin/rails ldap:setup`.
First-time LDAP setup (after creating the 389ds backend once):
`docker compose exec ldap dsconf localhost backend create --suffix="dc=kosmos,dc=org" --be_name="dev"`
then `docker compose run web bin/rails ldap:setup`.
## Common commands (prefix with `docker compose exec web`)
+24 -44
View File
@@ -14,14 +14,13 @@ so:
1. Make sure [Docker Compose is installed][1] and Docker is running (included in
Docker Desktop)
2. Run `docker compose up --build` and wait until all services have started
3. Run `docker compose up --build` and wait until all services have started
(389ds might take an extra minute to be ready). This will take a while when
running for the first time, so you might want to do something else in the
meantime.
On the first start, the `ldap-init` service creates the 389ds back-end, and the
`web` container then seeds the LDAP directory and the databases automatically.
On every start, `web` also applies any pending database migrations.
4. `docker-compose exec ldap dsconf localhost backend create --suffix="dc=kosmos,dc=org" --be-name="dev"`
5. `docker compose run web rails ldap:setup`
6. `docker compose run web rails db:setup`
After these steps, you should have a working Rails app with a handful of test
users running on [http://localhost:3000](http://localhost:3000).
@@ -72,12 +71,15 @@ containers you want to run to the `up` command, like so:
#### LDAP server
On first start, the `ldap-init` service creates the dirsrv back-end
automatically, and the `web` container then seeds it with development entries.
To do either step manually (for example, after changing the setup), run:
After creating the Docker container for the first time (or after deleting it),
you need to run the following command once, in order to create the dirsrv
back-end:
docker compose exec ldap dsconf localhost backend create --suffix="dc=kosmos,dc=org" --be-name="dev"
docker compose run --rm web bin/rails ldap:setup
docker-compose exec ldap dsconf localhost backend create --suffix="dc=kosmos,dc=org" --be-name="dev"
Now you can seed the back-end with data using this Rails task:
bundle exec rails ldap:setup
The setup task will first delete any existing entries in the directory tree
("dc=kosmos,dc=org"), and then create our development entries.
@@ -86,42 +88,20 @@ Note that all 389ds data is stored in the `389ds-data` volume. So if you want
to start over with a fresh installation, delete both that volume as well as the
container.
To reset the development environment completely, remove all volumes plus the
generated database files and the first-run marker, then start over:
#### Minio / remoteStorage
docker compose down -v
rm -f db/*.sqlite3 tmp/.setup-complete
docker compose up --build
If you want to run remoteStorage accounts locally, you will have to create the
respective bucket first. With the `minio` container running (run by default
when using Docker Compose), follow these steps:
#### Garage / remoteStorage
remoteStorage accounts use the `garage` S3-compatible object store. On first
start, Garage automatically configures a single-node cluster and creates the
`remotestorage` bucket together with a `dev-key1` access key (secret
`1234567890123456`), so no manual setup is required.
If you want to run remoteStorage accounts locally, the `garage` container is
started by default when using Docker Compose. To run just the remoteStorage
stack:
* `docker compose up web redis garage liquor-cabinet`
The S3 API is available at http://localhost:3900 (region `garage`). If you want
to start over with a fresh storage, delete the `garage-data` volume as well as
the container.
#### Accessing remoteStorage from another machine
remoteStorage clients force HTTPS for any host except `localhost`, and browsers
block plain-HTTP requests to a LAN IP as mixed content. To connect to the dev
remoteStorage from a browser on another machine (including production apps such
as Inspektor), forward the ports over SSH and connect as `localhost`:
ssh -N -L 3000:localhost:3000 -L 4567:localhost:4567 <user>@<dev-host>
Then use `<user>@localhost:3000` as the remoteStorage address in the client.
WeFinger discovery and storage requests are served through the forwarded ports,
so no TLS setup is needed.
* `docker compose up web redis minio liquor-cabinet`
* Head to http://localhost:9001 and log in with user `minioadmin`, password
`minioadmin`
* Create a new bucket called `remotestorage` (or whatever you
change the `S3_BUCKET` config to)
* Create a new key with ID "dev-key" and secret "123456789" (or whatever you
change `S3_ACCESS_KEY` and `S3_SECRET_KEY` to). Leave the policy field empty,
as it will automatically allow access to the bucket you created.
### Adding npm modules to use with Stimulus controllers
@@ -1,7 +1,7 @@
class Services::RemotestorageController < Services::BaseController
before_action :authenticate_user!
before_action :require_service_available
before_action :require_service_enabled
before_action :require_feature_enabled
# Dashboard
def show
@@ -17,8 +17,8 @@ class Services::RemotestorageController < Services::BaseController
http_status :not_found unless Setting.remotestorage_enabled?
end
def require_service_enabled
unless current_user.service_enabled?(:remotestorage)
def require_feature_enabled
unless Flipper.enabled?(:remotestorage, current_user)
http_status :forbidden
end
end
@@ -1,7 +1,8 @@
class Services::RsAuthsController < Services::BaseController
before_action :authenticate_user!
before_action :require_service_enabled
before_action :require_feature_enabled
before_action :require_service_available
# before_action :require_service_enabled
before_action :find_rs_auth, only: [:destroy, :launch_app]
def index
@@ -22,12 +23,9 @@ class Services::RsAuthsController < Services::BaseController
end
def launch_app
user_address =
if Rails.env.development?
"#{current_user.cn}@#{request.host_with_port}"
else
current_user.address
end
user_address = Rails.env.development? ?
"#{current_user.cn}@localhost:3000" :
current_user.address
launch_url = "#{@auth.launch_url}#remotestorage=#{user_address}"
@@ -36,8 +34,8 @@ class Services::RsAuthsController < Services::BaseController
private
def require_service_enabled
unless current_user.service_enabled?(:remotestorage)
def require_feature_enabled
unless Flipper.enabled?(:remotestorage, current_user)
http_status :forbidden
end
end
+2 -16
View File
@@ -88,14 +88,8 @@ class WebfingerController < WellKnownController
end
def remotestorage_link
auth_url =
if Rails.env.development?
new_rs_oauth_url(@username)
else
new_rs_oauth_url(@username, host: Setting.rs_accounts_domain)
end
storage_url = "#{remotestorage_storage_base_url}/#{@username}"
auth_url = new_rs_oauth_url(@username, host: Setting.rs_accounts_domain)
storage_url = "#{Setting.rs_storage_url}/#{@username}"
{
rel: "http://tools.ietf.org/id/draft-dejong-remotestorage",
@@ -109,12 +103,4 @@ class WebfingerController < WellKnownController
}
}
end
def remotestorage_storage_base_url
return Setting.rs_storage_url unless Rails.env.development?
uri = URI.parse(Setting.rs_storage_url)
uri.host = request.host
uri.to_s
end
end
+1 -1
View File
@@ -305,7 +305,7 @@
<td>remoteStorage</td>
<td>
<%= render FormElements::ToggleComponent.new(
enabled: @services_enabled.include?("remotestorage"),
enabled: Flipper.enabled?(:remotestorage, current_user) && @services_enabled.include?("remotestorage"),
input_enabled: false
) %>
</td>
+2 -1
View File
@@ -43,7 +43,8 @@
<% end %>
</div>
<% end %>
<% if Setting.remotestorage_enabled? %>
<% if Setting.remotestorage_enabled? &&
Flipper.enabled?(:remotestorage, current_user) %>
<div class="border border-gray-300 rounded-md hover:border-gray-400
bg-[length:80%] bg-[center_top_-156px] bg-no-repeat
bg-[url(/img/logos/icon_remotestorage.svg)]">
+2 -1
View File
@@ -25,7 +25,8 @@
active: @settings_section.to_s == "lightning"
) %>
<% end %>
<% if Setting.remotestorage_enabled? %>
<% if Setting.remotestorage_enabled? &&
Flipper.enabled?(:remotestorage, current_user) %>
<%= render SidenavLinkComponent.new(
name: "Storage", path: setting_path(:remotestorage), icon: "remotestorage",
active: @settings_section.to_s == "remotestorage"
+2
View File
@@ -1,4 +1,6 @@
:concurrency: 2
production:
:concurrency: 10
:queues:
- default
- mailers
+3 -6
View File
@@ -1,9 +1,8 @@
require 'sidekiq/testing'
ldap = LdapService.new
original_queue_adapter = ActiveJob::Base.queue_adapter
ActiveJob::Base.queue_adapter = :inline
begin
Sidekiq::Testing.inline! do
ldap.delete_all_users!
puts "Create user: admin"
@@ -26,6 +25,4 @@ begin
password: "user is user", confirmed: true
})
end
ensure
ActiveJob::Base.queue_adapter = original_queue_adapter
end
+14 -40
View File
@@ -12,20 +12,6 @@ services:
DS_DM_PASSWORD: passthebutter
SUFFIX_NAME: "dc=kosmos,dc=org"
ldap-init:
image: 4teamwork/389ds:latest
networks:
- internal_network
volumes:
- ./docker/ldap-init.sh:/ldap-init.sh:ro
environment:
LDAP_ADMIN_PASSWORD: passthebutter
LDAP_SUFFIX: "dc=kosmos,dc=org"
depends_on:
ldap:
condition: service_healthy
command: ["/bin/sh", "/ldap-init.sh"]
redis:
restart: always
image: redis:7-alpine
@@ -40,7 +26,7 @@ services:
web:
build: .
tty: true
command: ["bash", "docker/web-entrypoint.sh"]
command: bash -c "rm -f /akkounts/tmp/pids/server.pid; bin/dev"
volumes:
- .:/akkounts
- /akkounts/node_modules
@@ -71,28 +57,20 @@ services:
NOSTR_PRIVATE_KEY: 7c3ef7e448505f0615137af38569d01807d3b05b5005d5ecf8aaafcd40323cea
NOSTR_RELAY_URL: ws://strfry:7777
depends_on:
ldap:
condition: service_started
ldap-init:
condition: service_completed_successfully
redis:
condition: service_started
- ldap
- redis
garage:
image: dxflrs/garage:v2.4.1
command: ["/garage", "server", "--single-node", "--default-bucket"]
minio:
image: quay.io/minio/minio:latest
command: "server /data --console-address ':9001'"
networks:
- external_network
- internal_network
ports:
- "3900:3900"
- "9000:9000"
- "9001:9001"
volumes:
- ./docker/garage/garage.toml:/etc/garage.toml:ro
- garage-data:/var/lib/garage
environment:
GARAGE_DEFAULT_ACCESS_KEY: dev-key1
GARAGE_DEFAULT_SECRET_KEY: "1234567890123456"
GARAGE_DEFAULT_BUCKET: remotestorage
- minio-data:/data
liquor-cabinet:
image: gitea.kosmos.org/5apps/liquor-cabinet:2.0.0-rc.1
@@ -101,21 +79,17 @@ services:
- internal_network
ports:
- "4567:4567"
volumes:
- ./docker/liquor-cabinet/rainbows.conf.rb:/etc/liquor-cabinet/rainbows.conf.rb:ro
command: ["bundle", "exec", "rainbows", "-c", "/etc/liquor-cabinet/rainbows.conf.rb", "--listen", "0.0.0.0:4567"]
environment:
RACK_ENV: staging
REDIS_HOST: redis
REDIS_PORT: 6379
REDIS_DB: 1
S3_ENDPOINT: http://garage:3900
S3_REGION: garage
S3_ACCESS_KEY: dev-key1
S3_SECRET_KEY: "1234567890123456"
S3_ENDPOINT: http://minio:9000
S3_ACCESS_KEY: dev-key
S3_SECRET_KEY: 123456789
S3_BUCKET: remotestorage
depends_on:
- garage
- minio
- redis
strfry:
@@ -153,7 +127,7 @@ networks:
volumes:
389ds-data:
driver: local
garage-data:
minio-data:
driver: local
redis-data:
driver: local
-14
View File
@@ -1,14 +0,0 @@
metadata_dir = "/var/lib/garage/meta"
data_dir = "/var/lib/garage/data"
db_engine = "sqlite"
replication_factor = 1
rpc_bind_addr = "[::]:3901"
rpc_public_addr = "127.0.0.1:3901"
rpc_secret = "1799bccfd7411eddcf9ebd316bc1f5287ad12a68094e1c6ac6abde7e6feae1ec"
[s3_api]
s3_region = "garage"
api_bind_addr = "[::]:3900"
root_domain = ".s3.garage.localhost"
-14
View File
@@ -1,14 +0,0 @@
#!/bin/sh
set -e
SUFFIX="${LDAP_SUFFIX:-dc=kosmos,dc=org}"
URI="ldap://ldap:3389"
if dsconf -D "cn=Directory Manager" -w "$LDAP_ADMIN_PASSWORD" "$URI" \
backend suffix list --suffix 2>/dev/null | grep -Fqx "$SUFFIX"; then
echo "LDAP backend for $SUFFIX already exists, skipping."
else
echo "Creating LDAP backend for $SUFFIX..."
dsconf -D "cn=Directory Manager" -w "$LDAP_ADMIN_PASSWORD" "$URI" \
backend create --suffix "$SUFFIX" --be-name dev
fi
-5
View File
@@ -1,5 +0,0 @@
Rainbows! do
use :ThreadPool
worker_connections 16
client_max_body_size 100 * 1024 * 1024
end
-14
View File
@@ -1,14 +0,0 @@
#!/usr/bin/env bash
set -e
if [ ! -f tmp/.setup-complete ]; then
echo "First start: setting up LDAP entries and databases..."
bin/rails ldap:setup
bin/rails db:setup
touch tmp/.setup-complete
else
bin/rails db:prepare
fi
rm -f tmp/pids/server.pid
exec bin/dev
+1 -1
View File
@@ -11,7 +11,7 @@
"postcss-preset-env": "^7.8.3",
"tailwindcss": "^3.4.0"
},
"version": "0.11.1",
"version": "0.11.0",
"scripts": {
"build:css:tailwind": "bun ./node_modules/tailwindcss/lib/cli.js --postcss -i ./app/assets/stylesheets/application.tailwind.css -o ./app/assets/builds/application.css",
"build:css": "bun run build:css:tailwind"
@@ -6,9 +6,7 @@ RSpec.describe Services::RsAuthsController, type: :controller do
before do
allow_any_instance_of(AppCatalog::WebApp).to receive(:update_metadata).and_return(true)
allow_any_instance_of(RemoteStorageAuthorization).to receive(:remove_token_expiry_job).and_return(nil)
allow_any_instance_of(LdapService).to receive(:fetch_users).and_return([
{ services_enabled: ["remotestorage"] }
])
allow_any_instance_of(Flipper).to receive(:enabled?).and_return(true)
end
describe "GET /services/storage/rs_auths/:id/launch_app" do
@@ -37,20 +35,6 @@ RSpec.describe Services::RsAuthsController, type: :controller do
expect(response).to redirect_to(launch_url)
end
end
context "when remoteStorage is not enabled for the user" do
before do
allow_any_instance_of(LdapService).to receive(:fetch_users).and_return([
{ services_enabled: [] }
])
get :launch_app, params: { id: 1 }
end
it "responds with forbidden" do
expect(response).to have_http_status(:forbidden)
end
end
end
end
end
@@ -11,7 +11,6 @@ RSpec.describe RemoteStorageAuthorization, type: :model do
end
describe "#create" do
before(:each) { redis_rs_delete_keys("authorizations:*") }
after(:each) { clear_enqueued_jobs }
after(:all) { redis_rs_delete_keys("authorizations:*") }
@@ -28,9 +27,10 @@ RSpec.describe RemoteStorageAuthorization, type: :model do
end
it "stores a token in redis" do
auth
user_auth_keys = redis_rs.keys("authorizations:#{user.cn}:*")
expect(user_auth_keys.length).to eq(1)
authorizations = redis_rs.smembers("authorizations:#{user.cn}:#{auth.token}")
authorizations = redis_rs.smembers(user_auth_keys.first)
expect(authorizations.sort).to eq(%w(documents photos contacts:rw videos:r tasks/work:r).sort)
end