Compare commits

..
Author SHA1 Message Date
raucao 64d12c6658 Merge branch 'master' into live 2026-08-10 21:37:50 -06:00
raucao 7df61ddcd7 Merge branch 'master' into live 2026-08-10 17:24:47 -06:00
raucao 34cd98625c Merge branch 'master' into live 2026-08-10 17:12:06 -06:00
raucao fa64cf64a2 Merge branch 'master' into live 2026-08-10 14:24:57 -06:00
raucao 8336930077 Merge branch 'master' into live 2026-08-09 18:51:24 -06:00
raucao 1a69f59b32 Merge branch 'master' into live 2026-08-09 14:31:39 -06:00
raucao 975d1ca614 Merge branch 'master' into live
continuous-integration/drone/push Build is failing
2026-08-07 12:38:27 -06:00
raucao 28127bc1f5 Gah 2026-07-09 16:53:29 +02:00
raucao 93e4a65a00 Point tailwind command at module executable 2026-07-09 16:45:16 +02:00
raucao 8728684c21 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-06-12 16:10:06 +04:00
raucao dfb5b6b794 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-06-12 15:39:15 +04:00
raucao 8cf138b035 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-05-28 14:51:31 +04:00
raucao d48f1caa28 Merge branch 'master' into live
continuous-integration/drone/push Build is failing
2025-05-28 14:29:09 +04:00
raucao 6a2ad475be Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-05-28 13:26:51 +04:00
raucao 942ae25f09 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-05-23 14:10:16 +04:00
raucao b6968f1742 Merge branch 'feature/mastodon_api' into live
continuous-integration/drone/push Build is passing
2025-05-18 14:56:52 +04:00
raucao 4f4e086518 Merge branch 'feature/mastodon_api' into live
continuous-integration/drone/push Build is passing
2025-05-18 14:46:33 +04:00
raucao a04a1479f8 Merge branch 'feature/mastodon_api' into live
continuous-integration/drone/push Build is passing
2025-05-18 14:38:00 +04:00
raucao 613090d38a Merge branch 'feature/mastodon_api' into live
continuous-integration/drone/push Build is passing
2025-05-17 18:57:10 +04:00
raucao f1c540537a Merge branch 'feature/mastodon_api' into live
continuous-integration/drone/push Build is passing
2025-05-17 18:22:38 +04:00
raucao 1dcdc2b032 Allow syncing a single Mastodon profile
continuous-integration/drone/push Build is passing
2025-05-17 18:22:11 +04:00
raucao 4545c3ba19 Merge branch 'feature/mastodon_api' into live
continuous-integration/drone/push Build is passing
2025-05-17 18:12:57 +04:00
raucao bfa1514181 Update doc
continuous-integration/drone/push Build is passing
2025-05-17 18:11:17 +04:00
raucao f0846308da Only update other avatars in one place
continuous-integration/drone/push Build is passing
Prevent future mistakes
2025-05-17 18:02:13 +04:00
raucao b3b7fe6359 Don't queue job when service isn't enabled 2025-05-17 18:02:13 +04:00
raucao f0b541ee50 Add avatar to admin user page 2025-05-17 18:02:13 +04:00
raucao df9077e3c1 Sync Mastodon IDs/profiles to local accounts
Add a new service to import some data from Mastodon accounts:

* Find users by username, store Mastodon account ID in local db when
  found
* Import display name (don't overwrite existing)
* Import avatar (don't overwrite existing)
2025-05-17 18:02:07 +04:00
raucao 74666130c0 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-05-16 17:30:30 +04:00
raucao 7c43a4d919 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-05-16 16:01:31 +04:00
raucao 520552ec70 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-05-16 15:38:20 +04:00
raucao 307095bfd0 WTF
continuous-integration/drone/push Build is passing
2025-05-15 22:21:33 +04:00
raucao ae7291d4f1 Merge branch 'feature/ejabberd_pep' into live
continuous-integration/drone/push Build is failing
2025-05-15 22:07:26 +04:00
raucao 322ca98da9 Merge branch 'feature/ejabberd_pep' into live
continuous-integration/drone/push Build is passing
2025-05-15 20:05:30 +04:00
raucao 66f3950b83 Add job for setting avatar via XMPP 2025-05-15 20:04:55 +04:00
raucao 4e115eb514 Merge branch 'feature/ejabberd_pep' into live
continuous-integration/drone/push Build is failing
2025-05-15 19:50:30 +04:00
raucao fc9b471a10 Add job for setting avatar via XMPP 2025-05-15 19:50:05 +04:00
raucao b33e47e60f Merge branch 'feature/ejabberd_pep' into live
continuous-integration/drone/push Build is passing
2025-05-15 12:54:25 +04:00
raucao 9878e4a3e8 Merge branch 'feature/ejabberd_pep' into live
continuous-integration/drone/push Build is passing
2025-05-15 12:38:58 +04:00
raucao 9c35323bcd Return response for ejabberd API calls 2025-05-15 12:38:40 +04:00
raucao e2716d94c0 Merge branch 'feature/ejabberd_pep' into live
continuous-integration/drone/push Build is passing
2025-05-15 12:22:29 +04:00
raucao 9394f649a6 Merge branch 'feature/ejabberd_pep' into live
continuous-integration/drone/push Build is passing
2025-05-15 12:02:05 +04:00
raucao 41b9cb722b Merge branch 'feature/ejabberd_pep' into live
continuous-integration/drone/push Build is passing
2025-05-15 11:48:10 +04:00
raucao f1c13d7bd9 Add private_get to ejabberd service
continuous-integration/drone/push Build is passing
2025-05-15 11:47:23 +04:00
raucao c6cb9caa6d Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-05-14 18:58:38 +04:00
raucao 208977177a Merge branch 'feature/user_avatars' into live
continuous-integration/drone/push Build is passing
2025-05-14 15:40:47 +04:00
raucao 9a406b8381 Merge branch 'feature/user_avatars' into live
continuous-integration/drone/push Build is passing
2025-05-14 14:44:14 +04:00
raucao 4c972bfe7a Merge branch 'feature/user_avatars' into live
continuous-integration/drone/push Build is passing
2025-05-12 16:40:44 +04:00
raucao 0191d248f8 Merge branch 'feature/user_avatars' into live
continuous-integration/drone/push Build is passing
2025-05-12 15:11:39 +04:00
raucao 710afb6c78 Merge branch 'chore/215-configs' into live
continuous-integration/drone/push Build is passing
2025-05-06 20:14:42 +04:00
raucao 69e9662133 Merge branch 'chore/215-configs' into live
continuous-integration/drone/push Build is failing
2025-05-06 20:01:15 +04:00
raucao a73d0f29bd Merge branch 'chore/215-configs' into live
continuous-integration/drone/push Build is passing
2025-05-06 19:53:52 +04:00
raucao 7836805570 Merge branch 'chore/215-configs' into live
continuous-integration/drone/push Build is passing
2025-05-06 19:04:03 +04:00
raucao 1fc434cb3a Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-05-05 17:39:06 +04:00
raucao dad7d5195e Merge branch 'chore/db_configs' into live
continuous-integration/drone/push Build is passing
2025-05-05 15:28:16 +04:00
raucao 596cad34da Merge branch 'chore/upgrade_rails' into live 2025-04-29 17:25:25 +04:00
raucao aaee5cb4ed Merge branch 'chore/upgrade_rails' into live
continuous-integration/drone/push Build is passing
2025-04-28 17:56:57 +04:00
raucao ebaca5ba65 Merge branch 'chore/upgrade_rails' into live 2025-04-28 15:58:17 +04:00
raucao b6bcfa2ee3 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2025-04-18 14:54:01 +04:00
raucao 9082ee45d8 Merge branch 'master' into live 2025-01-02 08:32:15 -05:00
raucao 29264aad98 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-10-16 13:33:35 +02:00
raucao 259b51a95e Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-09-24 21:40:25 +02:00
raucao fb369530e3 Merge branch 'master' into live
continuous-integration/drone/push Build is failing
2024-09-14 17:18:09 +02:00
raucao 5dc10a4d33 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-09-14 16:46:27 +02:00
raucao 2297c68046 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-09-14 16:41:01 +02:00
raucao b82ab45c99 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-09-14 14:57:35 +02:00
raucao d12c63db26 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-09-10 16:07:24 +02:00
raucao e6a9ef84ce Merge branch 'master' into live
continuous-integration/drone/push Build is failing
2024-08-19 15:13:46 +02:00
raucao b7e91344a0 Merge branch 'master' into live
continuous-integration/drone/push Build is failing
2024-08-19 14:48:35 +02:00
raucao 0f07e32781 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-08-17 14:49:29 +02:00
raucao 1311b5ed6a Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-08-17 14:46:00 +02:00
raucao 12f82061e8 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-08-17 14:42:32 +02:00
raucao a07b4369ab Hide njump link for users without pubkey
continuous-integration/drone/push Build is passing
2024-06-23 17:33:34 +02:00
raucao 2605c06807 Merge branch 'feature/admin_pages' into live
continuous-integration/drone/push Build is passing
2024-06-23 17:30:22 +02:00
raucao 1db768fb15 Merge branch 'feature/admin_pages' into live
continuous-integration/drone/push Build is passing
2024-06-23 17:27:03 +02:00
raucao 8a7403df32 Merge branch 'feature/own_relay' into live
continuous-integration/drone/push Build is passing
2024-06-20 15:52:03 +02:00
raucao f0295fef7a Merge branch 'feature/own_relay' into live
continuous-integration/drone/push Build is passing
2024-06-20 15:28:55 +02:00
raucao 090affd304 Merge branch 'feature/own_relay' into live
continuous-integration/drone/push Build is passing
2024-06-20 14:51:20 +02:00
raucao bafddd436b Merge branch 'feature/own_relay' into live
continuous-integration/drone/push Build is passing
2024-06-20 13:59:59 +02:00
raucao 560f193c4b Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-06-20 13:56:11 +02:00
raucao 8aabbad5bb Merge branch 'feature/strfry_zap_receipts' into live 2024-06-20 13:56:00 +02:00
raucao ba8d21eb7a Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-06-09 13:29:57 +02:00
raucao 53df455d53 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-06-09 13:17:51 +02:00
raucao 9f1af3a9aa Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-06-07 14:13:53 +02:00
raucao 1d09008ce2 Merge branch 'master' into live
continuous-integration/drone/push Build is passing
2024-06-04 17:45:13 +02:00
raucao 57c5317c38 Merge branch 'feature/170-nostr_zaps' into live
continuous-integration/drone/push Build is passing
2024-05-21 18:29:13 +02:00
raucao 41bd920060 Merge branch 'feature/170-nostr_zaps' into live
continuous-integration/drone/push Build is passing
2024-05-21 18:09:09 +02:00
raucao 0815fa6040 Merge branch 'feature/170-nostr_zaps' into live
continuous-integration/drone/push Build is passing
2024-05-19 17:07:58 +02:00
raucao af0e99aa50 Merge branch 'feature/170-nostr_zaps' into live
continuous-integration/drone/push Build is passing
2024-05-19 16:55:10 +02:00
raucao f05eec5255 Merge branch 'feature/170-nostr_zaps' into live
continuous-integration/drone/push Build is passing
2024-05-19 16:48:28 +02:00
raucao 66ca2dc6b0 Merge branch 'feature/173-nostr_ldap' into live
continuous-integration/drone/push Build is passing
2024-05-19 13:44:24 +02:00
raucao 800183e9da Increase sidekiq concurrency in prod
continuous-integration/drone/push Build is passing
2024-05-19 13:44:01 +02:00
18 changed files with 69 additions and 196 deletions

No files matched your search

+4 -7
View File
@@ -7,16 +7,13 @@ ejabberd, Discourse, Mastodon, remoteStorage, Nostr, LNDHub, and BTCPay.
## Development environment ## Development environment
Development runs in Docker Compose — run all commands against the `web` container. Development runs in Docker Compose — run all commands against the `web` container.
Start services: `docker compose up` (web, ldap, redis, garage, liquor-cabinet, strfry). Start services: `docker compose up` (web, ldap, redis, minio, liquor-cabinet, strfry).
The `web` service runs `bin/dev` (foreman: Puma + Tailwind CSS watcher) and embeds The `web` service runs `bin/dev` (foreman: Puma + Tailwind CSS watcher) and embeds
Solid Queue workers (`SOLID_QUEUE_IN_PUMA=true`). Solid Queue workers (`SOLID_QUEUE_IN_PUMA=true`).
First-time LDAP and database setup is automated: the `ldap-init` service First-time LDAP setup (after creating the 389ds backend once):
creates the 389ds back-end, then the `web` entrypoint seeds LDAP and the `docker compose exec ldap dsconf localhost backend create --suffix="dc=kosmos,dc=org" --be_name="dev"`
databases on first start and runs `db:prepare` on every boot. Manual then `docker compose run web bin/rails ldap:setup`.
equivalents: `docker compose exec ldap dsconf localhost backend create
--suffix="dc=kosmos,dc=org" --be-name="dev"` and `docker compose run --rm web
bin/rails ldap:setup`.
## Common commands (prefix with `docker compose exec web`) ## Common commands (prefix with `docker compose exec web`)
+24 -44
View File
@@ -14,14 +14,13 @@ so:
1. Make sure [Docker Compose is installed][1] and Docker is running (included in 1. Make sure [Docker Compose is installed][1] and Docker is running (included in
Docker Desktop) Docker Desktop)
2. Run `docker compose up --build` and wait until all services have started 3. Run `docker compose up --build` and wait until all services have started
(389ds might take an extra minute to be ready). This will take a while when (389ds might take an extra minute to be ready). This will take a while when
running for the first time, so you might want to do something else in the running for the first time, so you might want to do something else in the
meantime. meantime.
4. `docker-compose exec ldap dsconf localhost backend create --suffix="dc=kosmos,dc=org" --be-name="dev"`
On the first start, the `ldap-init` service creates the 389ds back-end, and the 5. `docker compose run web rails ldap:setup`
`web` container then seeds the LDAP directory and the databases automatically. 6. `docker compose run web rails db:setup`
On every start, `web` also applies any pending database migrations.
After these steps, you should have a working Rails app with a handful of test After these steps, you should have a working Rails app with a handful of test
users running on [http://localhost:3000](http://localhost:3000). users running on [http://localhost:3000](http://localhost:3000).
@@ -72,12 +71,15 @@ containers you want to run to the `up` command, like so:
#### LDAP server #### LDAP server
On first start, the `ldap-init` service creates the dirsrv back-end After creating the Docker container for the first time (or after deleting it),
automatically, and the `web` container then seeds it with development entries. you need to run the following command once, in order to create the dirsrv
To do either step manually (for example, after changing the setup), run: back-end:
docker compose exec ldap dsconf localhost backend create --suffix="dc=kosmos,dc=org" --be-name="dev" docker-compose exec ldap dsconf localhost backend create --suffix="dc=kosmos,dc=org" --be-name="dev"
docker compose run --rm web bin/rails ldap:setup
Now you can seed the back-end with data using this Rails task:
bundle exec rails ldap:setup
The setup task will first delete any existing entries in the directory tree The setup task will first delete any existing entries in the directory tree
("dc=kosmos,dc=org"), and then create our development entries. ("dc=kosmos,dc=org"), and then create our development entries.
@@ -86,42 +88,20 @@ Note that all 389ds data is stored in the `389ds-data` volume. So if you want
to start over with a fresh installation, delete both that volume as well as the to start over with a fresh installation, delete both that volume as well as the
container. container.
To reset the development environment completely, remove all volumes plus the #### Minio / remoteStorage
generated database files and the first-run marker, then start over:
docker compose down -v If you want to run remoteStorage accounts locally, you will have to create the
rm -f db/*.sqlite3 tmp/.setup-complete respective bucket first. With the `minio` container running (run by default
docker compose up --build when using Docker Compose), follow these steps:
#### Garage / remoteStorage * `docker compose up web redis minio liquor-cabinet`
* Head to http://localhost:9001 and log in with user `minioadmin`, password
remoteStorage accounts use the `garage` S3-compatible object store. On first `minioadmin`
start, Garage automatically configures a single-node cluster and creates the * Create a new bucket called `remotestorage` (or whatever you
`remotestorage` bucket together with a `dev-key1` access key (secret change the `S3_BUCKET` config to)
`1234567890123456`), so no manual setup is required. * Create a new key with ID "dev-key" and secret "123456789" (or whatever you
change `S3_ACCESS_KEY` and `S3_SECRET_KEY` to). Leave the policy field empty,
If you want to run remoteStorage accounts locally, the `garage` container is as it will automatically allow access to the bucket you created.
started by default when using Docker Compose. To run just the remoteStorage
stack:
* `docker compose up web redis garage liquor-cabinet`
The S3 API is available at http://localhost:3900 (region `garage`). If you want
to start over with a fresh storage, delete the `garage-data` volume as well as
the container.
#### Accessing remoteStorage from another machine
remoteStorage clients force HTTPS for any host except `localhost`, and browsers
block plain-HTTP requests to a LAN IP as mixed content. To connect to the dev
remoteStorage from a browser on another machine (including production apps such
as Inspektor), forward the ports over SSH and connect as `localhost`:
ssh -N -L 3000:localhost:3000 -L 4567:localhost:4567 <user>@<dev-host>
Then use `<user>@localhost:3000` as the remoteStorage address in the client.
WeFinger discovery and storage requests are served through the forwarded ports,
so no TLS setup is needed.
### Adding npm modules to use with Stimulus controllers ### Adding npm modules to use with Stimulus controllers
@@ -1,7 +1,7 @@
class Services::RemotestorageController < Services::BaseController class Services::RemotestorageController < Services::BaseController
before_action :authenticate_user! before_action :authenticate_user!
before_action :require_service_available before_action :require_service_available
before_action :require_service_enabled before_action :require_feature_enabled
# Dashboard # Dashboard
def show def show
@@ -17,8 +17,8 @@ class Services::RemotestorageController < Services::BaseController
http_status :not_found unless Setting.remotestorage_enabled? http_status :not_found unless Setting.remotestorage_enabled?
end end
def require_service_enabled def require_feature_enabled
unless current_user.service_enabled?(:remotestorage) unless Flipper.enabled?(:remotestorage, current_user)
http_status :forbidden http_status :forbidden
end end
end end
@@ -1,7 +1,8 @@
class Services::RsAuthsController < Services::BaseController class Services::RsAuthsController < Services::BaseController
before_action :authenticate_user! before_action :authenticate_user!
before_action :require_service_enabled before_action :require_feature_enabled
before_action :require_service_available before_action :require_service_available
# before_action :require_service_enabled
before_action :find_rs_auth, only: [:destroy, :launch_app] before_action :find_rs_auth, only: [:destroy, :launch_app]
def index def index
@@ -22,12 +23,9 @@ class Services::RsAuthsController < Services::BaseController
end end
def launch_app def launch_app
user_address = user_address = Rails.env.development? ?
if Rails.env.development? "#{current_user.cn}@localhost:3000" :
"#{current_user.cn}@#{request.host_with_port}" current_user.address
else
current_user.address
end
launch_url = "#{@auth.launch_url}#remotestorage=#{user_address}" launch_url = "#{@auth.launch_url}#remotestorage=#{user_address}"
@@ -36,8 +34,8 @@ class Services::RsAuthsController < Services::BaseController
private private
def require_service_enabled def require_feature_enabled
unless current_user.service_enabled?(:remotestorage) unless Flipper.enabled?(:remotestorage, current_user)
http_status :forbidden http_status :forbidden
end end
end end
+2 -16
View File
@@ -88,14 +88,8 @@ class WebfingerController < WellKnownController
end end
def remotestorage_link def remotestorage_link
auth_url = auth_url = new_rs_oauth_url(@username, host: Setting.rs_accounts_domain)
if Rails.env.development? storage_url = "#{Setting.rs_storage_url}/#{@username}"
new_rs_oauth_url(@username)
else
new_rs_oauth_url(@username, host: Setting.rs_accounts_domain)
end
storage_url = "#{remotestorage_storage_base_url}/#{@username}"
{ {
rel: "http://tools.ietf.org/id/draft-dejong-remotestorage", rel: "http://tools.ietf.org/id/draft-dejong-remotestorage",
@@ -109,12 +103,4 @@ class WebfingerController < WellKnownController
} }
} }
end end
def remotestorage_storage_base_url
return Setting.rs_storage_url unless Rails.env.development?
uri = URI.parse(Setting.rs_storage_url)
uri.host = request.host
uri.to_s
end
end end
+1 -1
View File
@@ -305,7 +305,7 @@
<td>remoteStorage</td> <td>remoteStorage</td>
<td> <td>
<%= render FormElements::ToggleComponent.new( <%= render FormElements::ToggleComponent.new(
enabled: @services_enabled.include?("remotestorage"), enabled: Flipper.enabled?(:remotestorage, current_user) && @services_enabled.include?("remotestorage"),
input_enabled: false input_enabled: false
) %> ) %>
</td> </td>
+2 -1
View File
@@ -43,7 +43,8 @@
<% end %> <% end %>
</div> </div>
<% end %> <% end %>
<% if Setting.remotestorage_enabled? %> <% if Setting.remotestorage_enabled? &&
Flipper.enabled?(:remotestorage, current_user) %>
<div class="border border-gray-300 rounded-md hover:border-gray-400 <div class="border border-gray-300 rounded-md hover:border-gray-400
bg-[length:80%] bg-[center_top_-156px] bg-no-repeat bg-[length:80%] bg-[center_top_-156px] bg-no-repeat
bg-[url(/img/logos/icon_remotestorage.svg)]"> bg-[url(/img/logos/icon_remotestorage.svg)]">
+2 -1
View File
@@ -25,7 +25,8 @@
active: @settings_section.to_s == "lightning" active: @settings_section.to_s == "lightning"
) %> ) %>
<% end %> <% end %>
<% if Setting.remotestorage_enabled? %> <% if Setting.remotestorage_enabled? &&
Flipper.enabled?(:remotestorage, current_user) %>
<%= render SidenavLinkComponent.new( <%= render SidenavLinkComponent.new(
name: "Storage", path: setting_path(:remotestorage), icon: "remotestorage", name: "Storage", path: setting_path(:remotestorage), icon: "remotestorage",
active: @settings_section.to_s == "remotestorage" active: @settings_section.to_s == "remotestorage"
+2
View File
@@ -1,4 +1,6 @@
:concurrency: 2 :concurrency: 2
production:
:concurrency: 10
:queues: :queues:
- default - default
- mailers - mailers
+3 -6
View File
@@ -1,9 +1,8 @@
require 'sidekiq/testing'
ldap = LdapService.new ldap = LdapService.new
original_queue_adapter = ActiveJob::Base.queue_adapter Sidekiq::Testing.inline! do
ActiveJob::Base.queue_adapter = :inline
begin
ldap.delete_all_users! ldap.delete_all_users!
puts "Create user: admin" puts "Create user: admin"
@@ -26,6 +25,4 @@ begin
password: "user is user", confirmed: true password: "user is user", confirmed: true
}) })
end end
ensure
ActiveJob::Base.queue_adapter = original_queue_adapter
end end
+14 -40
View File
@@ -12,20 +12,6 @@ services:
DS_DM_PASSWORD: passthebutter DS_DM_PASSWORD: passthebutter
SUFFIX_NAME: "dc=kosmos,dc=org" SUFFIX_NAME: "dc=kosmos,dc=org"
ldap-init:
image: 4teamwork/389ds:latest
networks:
- internal_network
volumes:
- ./docker/ldap-init.sh:/ldap-init.sh:ro
environment:
LDAP_ADMIN_PASSWORD: passthebutter
LDAP_SUFFIX: "dc=kosmos,dc=org"
depends_on:
ldap:
condition: service_healthy
command: ["/bin/sh", "/ldap-init.sh"]
redis: redis:
restart: always restart: always
image: redis:7-alpine image: redis:7-alpine
@@ -40,7 +26,7 @@ services:
web: web:
build: . build: .
tty: true tty: true
command: ["bash", "docker/web-entrypoint.sh"] command: bash -c "rm -f /akkounts/tmp/pids/server.pid; bin/dev"
volumes: volumes:
- .:/akkounts - .:/akkounts
- /akkounts/node_modules - /akkounts/node_modules
@@ -71,28 +57,20 @@ services:
NOSTR_PRIVATE_KEY: 7c3ef7e448505f0615137af38569d01807d3b05b5005d5ecf8aaafcd40323cea NOSTR_PRIVATE_KEY: 7c3ef7e448505f0615137af38569d01807d3b05b5005d5ecf8aaafcd40323cea
NOSTR_RELAY_URL: ws://strfry:7777 NOSTR_RELAY_URL: ws://strfry:7777
depends_on: depends_on:
ldap: - ldap
condition: service_started - redis
ldap-init:
condition: service_completed_successfully
redis:
condition: service_started
garage: minio:
image: dxflrs/garage:v2.4.1 image: quay.io/minio/minio:latest
command: ["/garage", "server", "--single-node", "--default-bucket"] command: "server /data --console-address ':9001'"
networks: networks:
- external_network - external_network
- internal_network - internal_network
ports: ports:
- "3900:3900" - "9000:9000"
- "9001:9001"
volumes: volumes:
- ./docker/garage/garage.toml:/etc/garage.toml:ro - minio-data:/data
- garage-data:/var/lib/garage
environment:
GARAGE_DEFAULT_ACCESS_KEY: dev-key1
GARAGE_DEFAULT_SECRET_KEY: "1234567890123456"
GARAGE_DEFAULT_BUCKET: remotestorage
liquor-cabinet: liquor-cabinet:
image: gitea.kosmos.org/5apps/liquor-cabinet:2.0.0-rc.1 image: gitea.kosmos.org/5apps/liquor-cabinet:2.0.0-rc.1
@@ -101,21 +79,17 @@ services:
- internal_network - internal_network
ports: ports:
- "4567:4567" - "4567:4567"
volumes:
- ./docker/liquor-cabinet/rainbows.conf.rb:/etc/liquor-cabinet/rainbows.conf.rb:ro
command: ["bundle", "exec", "rainbows", "-c", "/etc/liquor-cabinet/rainbows.conf.rb", "--listen", "0.0.0.0:4567"]
environment: environment:
RACK_ENV: staging RACK_ENV: staging
REDIS_HOST: redis REDIS_HOST: redis
REDIS_PORT: 6379 REDIS_PORT: 6379
REDIS_DB: 1 REDIS_DB: 1
S3_ENDPOINT: http://garage:3900 S3_ENDPOINT: http://minio:9000
S3_REGION: garage S3_ACCESS_KEY: dev-key
S3_ACCESS_KEY: dev-key1 S3_SECRET_KEY: 123456789
S3_SECRET_KEY: "1234567890123456"
S3_BUCKET: remotestorage S3_BUCKET: remotestorage
depends_on: depends_on:
- garage - minio
- redis - redis
strfry: strfry:
@@ -153,7 +127,7 @@ networks:
volumes: volumes:
389ds-data: 389ds-data:
driver: local driver: local
garage-data: minio-data:
driver: local driver: local
redis-data: redis-data:
driver: local driver: local
-14
View File
@@ -1,14 +0,0 @@
metadata_dir = "/var/lib/garage/meta"
data_dir = "/var/lib/garage/data"
db_engine = "sqlite"
replication_factor = 1
rpc_bind_addr = "[::]:3901"
rpc_public_addr = "127.0.0.1:3901"
rpc_secret = "1799bccfd7411eddcf9ebd316bc1f5287ad12a68094e1c6ac6abde7e6feae1ec"
[s3_api]
s3_region = "garage"
api_bind_addr = "[::]:3900"
root_domain = ".s3.garage.localhost"
-14
View File
@@ -1,14 +0,0 @@
#!/bin/sh
set -e
SUFFIX="${LDAP_SUFFIX:-dc=kosmos,dc=org}"
URI="ldap://ldap:3389"
if dsconf -D "cn=Directory Manager" -w "$LDAP_ADMIN_PASSWORD" "$URI" \
backend suffix list --suffix 2>/dev/null | grep -Fqx "$SUFFIX"; then
echo "LDAP backend for $SUFFIX already exists, skipping."
else
echo "Creating LDAP backend for $SUFFIX..."
dsconf -D "cn=Directory Manager" -w "$LDAP_ADMIN_PASSWORD" "$URI" \
backend create --suffix "$SUFFIX" --be-name dev
fi
-5
View File
@@ -1,5 +0,0 @@
Rainbows! do
use :ThreadPool
worker_connections 16
client_max_body_size 100 * 1024 * 1024
end
-14
View File
@@ -1,14 +0,0 @@
#!/usr/bin/env bash
set -e
if [ ! -f tmp/.setup-complete ]; then
echo "First start: setting up LDAP entries and databases..."
bin/rails ldap:setup
bin/rails db:setup
touch tmp/.setup-complete
else
bin/rails db:prepare
fi
rm -f tmp/pids/server.pid
exec bin/dev
+1 -1
View File
@@ -11,7 +11,7 @@
"postcss-preset-env": "^7.8.3", "postcss-preset-env": "^7.8.3",
"tailwindcss": "^3.4.0" "tailwindcss": "^3.4.0"
}, },
"version": "0.11.1", "version": "0.11.0",
"scripts": { "scripts": {
"build:css:tailwind": "bun ./node_modules/tailwindcss/lib/cli.js --postcss -i ./app/assets/stylesheets/application.tailwind.css -o ./app/assets/builds/application.css", "build:css:tailwind": "bun ./node_modules/tailwindcss/lib/cli.js --postcss -i ./app/assets/stylesheets/application.tailwind.css -o ./app/assets/builds/application.css",
"build:css": "bun run build:css:tailwind" "build:css": "bun run build:css:tailwind"
@@ -6,9 +6,7 @@ RSpec.describe Services::RsAuthsController, type: :controller do
before do before do
allow_any_instance_of(AppCatalog::WebApp).to receive(:update_metadata).and_return(true) allow_any_instance_of(AppCatalog::WebApp).to receive(:update_metadata).and_return(true)
allow_any_instance_of(RemoteStorageAuthorization).to receive(:remove_token_expiry_job).and_return(nil) allow_any_instance_of(RemoteStorageAuthorization).to receive(:remove_token_expiry_job).and_return(nil)
allow_any_instance_of(LdapService).to receive(:fetch_users).and_return([ allow_any_instance_of(Flipper).to receive(:enabled?).and_return(true)
{ services_enabled: ["remotestorage"] }
])
end end
describe "GET /services/storage/rs_auths/:id/launch_app" do describe "GET /services/storage/rs_auths/:id/launch_app" do
@@ -37,20 +35,6 @@ RSpec.describe Services::RsAuthsController, type: :controller do
expect(response).to redirect_to(launch_url) expect(response).to redirect_to(launch_url)
end end
end end
context "when remoteStorage is not enabled for the user" do
before do
allow_any_instance_of(LdapService).to receive(:fetch_users).and_return([
{ services_enabled: [] }
])
get :launch_app, params: { id: 1 }
end
it "responds with forbidden" do
expect(response).to have_http_status(:forbidden)
end
end
end end
end end
end end
@@ -11,7 +11,6 @@ RSpec.describe RemoteStorageAuthorization, type: :model do
end end
describe "#create" do describe "#create" do
before(:each) { redis_rs_delete_keys("authorizations:*") }
after(:each) { clear_enqueued_jobs } after(:each) { clear_enqueued_jobs }
after(:all) { redis_rs_delete_keys("authorizations:*") } after(:all) { redis_rs_delete_keys("authorizations:*") }
@@ -28,9 +27,10 @@ RSpec.describe RemoteStorageAuthorization, type: :model do
end end
it "stores a token in redis" do it "stores a token in redis" do
auth user_auth_keys = redis_rs.keys("authorizations:#{user.cn}:*")
expect(user_auth_keys.length).to eq(1)
authorizations = redis_rs.smembers("authorizations:#{user.cn}:#{auth.token}") authorizations = redis_rs.smembers(user_auth_keys.first)
expect(authorizations.sort).to eq(%w(documents photos contacts:rw videos:r tasks/work:r).sort) expect(authorizations.sort).to eq(%w(documents photos contacts:rw videos:r tasks/work:r).sort)
end end