From 7461ae27aab74ec185493863d5eee5d2b311e9e0 Mon Sep 17 00:00:00 2001 From: Malaber Date: Tue, 28 Apr 2026 23:51:36 +0200 Subject: [PATCH] Restore image versioning and auth safety --- .gitlab-ci.yml | 3 -- Dockerfile | 10 ++-- app/controllers/application_controller.rb | 4 -- doc/rails_8_dependency_update.md | 58 +++++++++++++++++++++++ tasks.py | 4 +- 5 files changed, 65 insertions(+), 14 deletions(-) create mode 100644 doc/rails_8_dependency_update.md diff --git a/.gitlab-ci.yml b/.gitlab-ci.yml index 2042e34..7a52e46 100644 --- a/.gitlab-ci.yml +++ b/.gitlab-ci.yml @@ -56,7 +56,6 @@ rails e2e spec: - name: $CI_REGISTRY_IMAGE/production/commits:$CI_COMMIT_SHA alias: app variables: - GIT_COMMIT_SHA: $CI_COMMIT_SHA TURNIERE_DISABLE_EMAIL_DELIVERY: "1" command: - bundle @@ -128,7 +127,6 @@ rails follow sync e2e spec: SECRET_KEY_BASE: turniere-blackbox-secret-key-base-please-change-in-real-prod MAILGUN_API_KEY: blackbox-test-api-key MAILGUN_DOMAIN: blackbox.example.com - GIT_COMMIT_SHA: $CI_COMMIT_SHA TURNIERE_DISABLE_EMAIL_DELIVERY: "1" TOURNAMENT_SYNC_HTTP_TIMEOUT_SECONDS: "3" NO_PROXY: source-app,follower-app,source-postgres,follower-postgres,localhost,127.0.0.1 @@ -153,7 +151,6 @@ rails follow sync e2e spec: SECRET_KEY_BASE: turniere-blackbox-secret-key-base-please-change-in-real-prod MAILGUN_API_KEY: blackbox-test-api-key MAILGUN_DOMAIN: blackbox.example.com - GIT_COMMIT_SHA: $CI_COMMIT_SHA TURNIERE_DISABLE_EMAIL_DELIVERY: "1" TOURNAMENT_SYNC_HTTP_TIMEOUT_SECONDS: "3" NO_PROXY: source-app,follower-app,source-postgres,follower-postgres,localhost,127.0.0.1 diff --git a/Dockerfile b/Dockerfile index 7d09b59..e5eda29 100644 --- a/Dockerfile +++ b/Dockerfile @@ -2,7 +2,7 @@ ARG RUBY_VERSION=4.0.3 ARG BUNDLER_VERSION=4.0.6 -ARG GIT_COMMIT_SHA=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa +ARG base_commit=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa FROM ruby:${RUBY_VERSION}-slim AS runtime-base @@ -57,10 +57,10 @@ RUN bundle config set with 'development test' \ FROM runtime-base AS production -ARG GIT_COMMIT_SHA=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa +ARG base_commit=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa ENV RAILS_ENV=production \ - GIT_COMMIT_SHA=${GIT_COMMIT_SHA} + GIT_COMMIT_SHA=${base_commit} COPY --from=bundle-production /usr/local/bundle /usr/local/bundle COPY --from=bundle-production /app/vendor/bundle /app/vendor/bundle @@ -83,10 +83,10 @@ CMD ["sh", "-lc", "bundle exec rails db:migrate && bundle exec rails s -p 3000 - FROM runtime-base AS test -ARG GIT_COMMIT_SHA=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa +ARG base_commit=aaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa ENV RAILS_ENV=test \ - GIT_COMMIT_SHA=${GIT_COMMIT_SHA} + GIT_COMMIT_SHA=${base_commit} RUN apt-get update -qq \ && apt-get install -y --no-install-recommends \ diff --git a/app/controllers/application_controller.rb b/app/controllers/application_controller.rb index 6c56364..f13d19f 100644 --- a/app/controllers/application_controller.rb +++ b/app/controllers/application_controller.rb @@ -10,10 +10,6 @@ class ApplicationController < ActionController::API end rescue_from ActiveRecord::RecordNotFound, with: :render_not_found_error - def bypass_sign_in(_resource, scope: nil) - true - end - protected def configure_permitted_parameters diff --git a/doc/rails_8_dependency_update.md b/doc/rails_8_dependency_update.md new file mode 100644 index 0000000..e0c2ec3 --- /dev/null +++ b/doc/rails_8_dependency_update.md @@ -0,0 +1,58 @@ +# Rails 8 Dependency Update Notes + +## Scope + +This update moves the backend runtime to Ruby 4.0.3, Bundler 4.0.6, Rails 8.1, +Puma 8, and the released `devise_token_auth` gem. + +The project no longer uses the Thor77 `devise_token_auth` fork. The released +gem currently supports this stack through `devise_token_auth` 1.2.6 with +`devise` 4.9.4. + +## Docker Versioning + +Container versioning still uses the shared pipeline `base_commit` build arg. +The production and test images burn that value into `GIT_COMMIT_SHA` at build +time. + +Do not set `GIT_COMMIT_SHA` as a runtime service variable in CI or deployment. +Runtime overrides can make `/version` report a different SHA than the image was +built from. + +## Email Delivery In Blackbox Runs + +`TURNIERE_BLACKBOX_DISABLE_EMAIL_DELIVERY` is a local blackbox compose variable. +It maps to the app runtime variable `TURNIERE_DISABLE_EMAIL_DELIVERY`. + +Blackbox production E2E uses real production mode but fake Mailgun credentials. +Registration sends a confirmation email, so blackbox runs disable delivery to +avoid calling Mailgun while still keeping the production confirmation flow. + +Normal production deployments should not set `TURNIERE_DISABLE_EMAIL_DELIVERY` +unless email delivery is intentionally disabled. + +## Schema Diff + +Rails 8.1 dumps columns in a different order than Rails 7. That creates a large +`db/schema.rb` diff, but it is ordering churn, not dropped columns. + +Relative to current `master`, no existing schema columns are removed by the +dependency update. The timer reason work on `master` adds: + +- `tournaments.timer_reason` +- `tournaments.timer_reason_text` + +## API And Frontend Compatibility + +Known frontend-facing API changes are additive: + +- tournament payloads include `timer_reason` +- tournament payloads include `timer_reason_text` +- timer endpoints accept and return those same fields + +Existing frontend code can ignore these fields and keep using `timestamp` and +`timer_mode`. Frontend changes are only needed if the UI should show or edit +timer reasons. + +No deployment configuration change is required beyond building/running the new +image with the existing shared pipeline build metadata. diff --git a/tasks.py b/tasks.py index 36f6bb9..299b6a3 100644 --- a/tasks.py +++ b/tasks.py @@ -256,7 +256,7 @@ def _docker_build_command(tag, target, platforms=None, push=False): "--target", target, "--build-arg", - f"GIT_COMMIT_SHA={_git_commit_sha()}", + f"base_commit={_git_commit_sha()}", "-t", tag, "-f", @@ -274,7 +274,7 @@ def _docker_build_command(tag, target, platforms=None, push=False): "--target", target, "--build-arg", - f"GIT_COMMIT_SHA={_git_commit_sha()}", + f"base_commit={_git_commit_sha()}", "-t", tag, "-f",