Commit graph

3,088 commits

Author SHA1 Message Date
0f50b0d094 Merge pull request 'feat/postit-release-page' (#15) from feat/postit-release-page into main
Reviewed-on: #15
2026-08-15 18:13:05 +01:00
fe71b822b5 postit: validate CHANGELOG section on tag, classify stable/preview/unstable 1.0.5
Rend le job publish-release dépendant d'un nouveau job validate-release
qui :
- parse le tag (format MAJOR.MINOR.PATCH[-SUFFIX])
- classifie le canal : pair=stable, impair=preview, suffixe=instable
- fail-fast sur instable sauf opt-in explicite via workflow_dispatch
- vérifie que CHANGELOG.md contient une section ## [<tag>] - <canal>
- expose le body de la section via $GITHUB_ENV pour le job de publication

Le tag trigger passe de 'v*' à '*' (pas de préfixe sur les tags), et
le corps de release GitHub est désormais curé via CHANGELOG.md plutôt
que généré automatiquement.

Cette convention de parité est partagée avec le dépôt postit-debian
pour la production des paquets .deb (alignement à traiter dans une PR
séparée).
2026-08-15 15:51:42 +01:00
be502593c3 postit: add CHANGELOG.md with Keep a Changelog format
Initialise le changelog du projet au format Keep a Changelog 1.1.0,
en français, avec une section [Unreleased] vide prête à être curée
au moment de la première release.

Le préambule documente la convention de parité du patch :
- pair → stable
- impair → preview
- suffixe → instable

Cette convention est partagée avec le dépôt postit-debian pour la
production des paquets .deb (alignement à traiter dans une PR séparée).
2026-08-15 15:44:47 +01:00
fa886be84f Add comments API support and tests 2026-08-10 22:27:52 +01:00
66fcdc68d4 Fix blog comment endpoint path and add regression test 2026-08-10 21:48:03 +01:00
4e1ceb729c GetUserId_reads_NameIdentifier_when_sub_was_mapped 2026-08-10 18:34:01 +01:00
633a305c35 Activity protection 2026-08-10 18:12:59 +01:00
e17b24afe7 re-refacto BlogPost serialization 2026-08-05 21:11:22 +01:00
0a76784858 refacto BlogPost serialization 2026-08-05 21:05:14 +01:00
7755e214e4 Merge pull request 'publish android' (#13) from build into main 1.0.4
Reviewed-on: #13
2026-08-03 02:36:11 +01:00
22d8974aab publish android 2026-08-03 02:35:50 +01:00
42ae86f050 Merge pull request 'build' (#12) from build into main
Reviewed-on: #12
2026-08-03 02:17:32 +01:00
17e33ebea9 build 2026-08-03 02:16:57 +01:00
c3388e3e2a Enable blogs on connected status 2026-08-03 01:48:15 +01:00
ec0085b7e3 refacto blogPost 2026-08-03 01:36:12 +01:00
d9d5aed385 Merge pull request 'ci: publish APK to GitHub release on v* tag' (#11) from release into main
Reviewed-on: #11
2026-08-02 23:29:21 +01:00
c6366bbda4 ci: publish APK to GitHub release on v* tag
Adds a publish-release job that triggers only on tag pushes (refs/tags/v*).
It reuses the APK artifact uploaded by apk-deploy, publishes a GitHub
release via softprops/action-gh-release, and attaches the APK.

Result: a stable permalink to the latest APK at
  https://github.com/<owner>/<repo>/releases/latest/download/PostIt.Android.apk
2026-08-02 23:23:00 +01:00
367afb005b Merge pull request 'Le créateur vient de l'authentification, donc on ne le prend pas du post' (#10) from fix/OIDC-debugging into main
Reviewed-on: #10
2026-08-02 23:04:09 +01:00
ce075b3aee Le créateur vient de l'authentification, donc on ne le prend pas du post 2026-08-02 23:02:54 +01:00
337884d831 Merge pull request 'postit: allow self-signed OIDC TLS in Development' (#9) from fix/OIDC-debugging into main
Reviewed-on: #9
2026-08-02 21:32:49 +01:00
e92be558de Navigate to Main Page 2026-08-02 21:08:25 +01:00
d8ee77b9de refacto error handling 2026-07-12 17:56:23 +01:00
96d175f13d Hsts 2026-07-12 16:27:13 +01:00
49292b1fa0 Hsts 2026-07-12 16:26:43 +01:00
e539acd599 Post logout redirect uri 2026-07-12 16:14:37 +01:00
3b3635758b org: show full error details in development 2026-07-12 16:07:28 +01:00
4723d1b1b8 postit: allow self-signed OIDC TLS in Development 2026-07-12 15:51:55 +01:00
d70069cf01 Merge pull request 'fix/auth-redirect-message' (#8) from fix/auth-redirect-message into main
Reviewed-on: #8
2026-07-12 15:22:20 +01:00
afcb6167e6 Localisation 1.0.2 2026-07-12 15:18:07 +01:00
fd773529ff Audiences 2026-07-12 15:17:53 +01:00
0957efb876 code format 2026-07-12 15:17:41 +01:00
33f8f2b74e auth: fix JWT default scheme and multi-audience validation 2026-07-12 14:53:17 +01:00
0bb3cf5add Merge pull request 'fic/jwt-validation' (#7) from fic/jwt-validation into main
Reviewed-on: #7
2026-07-12 06:46:05 +01:00
c295d1d463 blogs: use centralized JWT audience handling 2026-07-12 06:45:00 +01:00
1730e10207 tests: log warning when OIDC token fallback is used 2026-07-12 06:43:07 +01:00
41dadc7909 Merge remote-tracking branch 'origin/main' into fic/jwt-validation 2026-07-12 06:12:19 +01:00
99f29f926a WIP audiences 2026-07-12 06:10:24 +01:00
7e5efdc4fd Merge pull request 'fix/testing' (#6) from fix/testing into main
Reviewed-on: #6
2026-07-12 06:03:39 +01:00
4f958f4502 use an available port for authority 2026-07-12 06:01:42 +01:00
3a02eb253a tests: configure static fixture ports and update org test config 2026-07-12 05:48:47 +01:00
c129a1f9e3 ? 2026-07-12 04:36:35 +01:00
d7c8ef242b Revert "Test host: bind Kestrel to Site:Authority instead of dynamic port"
This reverts commit d58fad552a.
2026-07-12 03:48:49 +01:00
b2706466c6 using clauses cleanup 2026-07-12 03:48:30 +01:00
d58fad552a Test host: bind Kestrel to Site:Authority instead of dynamic port
The Yavsc.Org integration tests were failing 'Internal Server Error' on
the OIDC discovery document when run as part of the full test suite.

Root cause: WebHostFixture bound Kestrel to IPAddress.Loopback on a
dynamically-allocated port and exposed it via IServerAddressesFeature.
But the OIDC issuer URLs (and the issuer claim) come from Site:Authority,
which was left at the production value (mercure.pschneider.fr). So
IdentityServer8's discovery document advertised URLs unreachable from
the test process, and the discovery call returned a 500.

Fix:
  - WebServerFixture now overrides Site:Authority and Site:ExternalUrl
    in AddInMemoryCollection to 'https://localhost:44300' (the ASP.NET
    Core dev HTTPS convention).
  - WebHostFixture reads Site:Authority from configuration and binds
    Kestrel to that fixed URL. The exposed Addresses list is sourced
    from the same configuration value instead of the
    IServerAddressesFeature, so the listen URL and the OIDC issuer
    URLs always match.

Remoting.cs (Mandatory/Remoting.cs): add 'using
Microsoft.Extensions.DependencyInjection;' so the existing OIDC/DB
diagnostic block (capture raw HTTP response + dump OIDC-related DB
state on discovery failure) compiles. The diagnostic itself is left
in place — it's what surfaced the 500 in the first place.
2026-07-12 03:43:22 +01:00
587fdd13c2 Merge pull request 'fix/issue-3-splitquery' (#5) from fix/issue-3-splitquery into main
Reviewed-on: #5
2026-07-12 02:47:15 +01:00
3febd63b06 WIP audiences 2026-07-12 02:42:13 +01:00
d80fd598f5 ApplicationDbContext: drop redundant HasOne on 3 Client navs
LoadClientAsync(id) on ClientController used to trip an
IndexOutOfRangeException at the InMemory shaper for any
.Include() of one of three Client navs: RedirectUris,
AllowedScopes, AllowedGrantTypes. Five other Client navs (with
the same EF shape and the same application-level config) worked
fine.

Bisection pointed at the InMemory provider; that hypothesis was
wrong. The real cause is in ApplicationDbContext.OnModelCreating:
yavsc was redeclaring the HasOne<Client>().WithMany(...).
HasForeignKey(e => e.ClientId) for all eight Client* navs. The
same relation is already declared (more completely, with
.IsRequired().OnDelete(DeleteBehavior.Cascade)) by
IdentityServer8's ConfigureClientStore via ModelBuilderExtensions.

The redundant mapping on three specific entities — ClientScope,
ClientRedirectUri, ClientGrantType — interacts with the InMemory
provider's shaper in a way that throws IndexOutOfRange. Removing
the redundancy fixes it.

This commit also walks back e940a241:
- Drops .AsSplitQuery() from LoadClientAsync (no longer needed
  for the InMemory shaper, and the Postgres path it was a hedge
  against was a false alarm — there is no Postgres production
  bug here, only an InMemory shaper quirk surfaced by the
  redundant mapping).
- Removes the 9 Bisect_*_alone tests that were the artefact of
  the provider-hypothesis phase. They pointed at the right
  entities but for the wrong reason.
- Keeps EditRedirectUris_GET_after_add_lists_both_uris as the
  end-to-end regression sentinel: with the fix in place, it
  loads a Client with two RedirectUris and asserts both are
  rendered. Without the fix, it fails with IndexOutOfRange.
2026-07-12 02:39:13 +01:00
e940a241c9 ClientController: split LoadClientAsync into per-collection subqueries
LoadClientAsync chains 9 .Include() calls on dbContext.Clients.
On Postgres (and InMemory for some IdentityServer8 nav types), the
resulting cartesian product trips the query shaper with
IndexOutOfRangeException at IncludeCollection materialisation time.
Bug reproduces in production on the Blog admin pages that load a
Client by id.

AsSplitQuery() rewrites the load as 9 separate SELECTs joined by
client id, which sidesteps the cartesian explosion and any shaper
ambiguity between Claims/Properties/ClientSecrets (which share
Type/Value column names across some IdentityServer8 versions).

Tests:
- EditRedirectUris_GET_after_add_lists_both_uris: end-to-end
  reproducer that adds a second RedirectUri via POST then re-GETs
  the editor. Guards the fix on the integration path.
- Bisect_*_alone: nine unit tests that exercise the same
  .SingleOrDefaultAsync(c => c.Id == id).Include(nav) on the
  InMemory provider, one nav at a time. Pinpointed three
  problematic navs (RedirectUris, AllowedScopes, AllowedGrantTypes)
  on InMemory; kept as a regression net for any future shaper
  regressions on the InMemory provider (not the Postgres path).
2026-07-12 01:15:02 +01:00
c6714b4eeb Revert "repoduces the bug"
This reverts commit 93d625d270.
2026-07-11 22:17:58 +01:00
Lum
93d625d270 repoduces the bug 2026-07-11 21:56:25 +01:00