diff --git a/.dockerignore b/.dockerignore index 45b7c22b..444995d0 100644 --- a/.dockerignore +++ b/.dockerignore @@ -1,6 +1,7 @@ **/bin/ **/obj/ **/.playwright/ +.git/ .vs/ .github/ # Exclure uniquement les dossiers de sortie de compilation @@ -13,4 +14,5 @@ test/*/obj/ # Exclure les caches lourds **/.playwright/ +.git/ .vs/ diff --git a/.forgejo/workflows/buildAndTest.yml b/.forgejo/workflows/buildAndTest.yml index cb18656d..cda246cc 100644 --- a/.forgejo/workflows/buildAndTest.yml +++ b/.forgejo/workflows/buildAndTest.yml @@ -21,27 +21,33 @@ on: push: branches: [ "main" ] pull_request: - branches: [ "main", "release/*" ] + branches: [ "main" ] jobs: - build: - runs-on: docker - container: - image: pazof/yavsc-build-env:debian13-dotnet10-android36-jdk21-v1 + log-the-inputs: + runs-on: debian-latest steps: - - name: Clone yavsc - run: | - cd /src - git clone https://forgejo.pschneider.fr/notazof/yavsc.git _src - cd _src - if [ -n "${GITHUB_REF:-}" ]; then - git fetch origin "$GITHUB_REF" - git checkout FETCH_HEAD - fi - git submodule update --init --recursive - echo "✅ Checked out at $(git rev-parse HEAD) on $(git branch --show-current 2>/dev/null || echo detached HEAD)" + - run: | + echo "Log level: $LEVEL" + echo "Tags: $TAGS" + echo "Environment: $ENVIRONMENT" + env: + LEVEL: ${{ inputs.logLevel }} + TAGS: ${{ inputs.tags }} + build: + + runs-on: debian-latest + + steps: + - uses: actions/checkout@v6 + - name: Setup .NET + uses: actions/setup-dotnet@v5 + with: + dotnet-version: 9.0.x + - name: Restore dependencies + run: dotnet restore + - name: Build + run: dotnet build --no-restore - name: Test - run: | - echo "🚀 Lancement des tests..." - cd /src/_src && dotnet test --verbosity normal && echo "✅ Success !" || echo "❌ Fail ($?)!" + run: dotnet test --no-build --verbosity normal diff --git a/.forgejo/workflows/release.yml b/.forgejo/workflows/release.yml deleted file mode 100644 index a72f92bd..00000000 --- a/.forgejo/workflows/release.yml +++ /dev/null @@ -1,316 +0,0 @@ -# Build and publish a release on the Forgejo source-of-truth instance -# with the PostIt Android APK as an attached asset. -# -# Triggered by a push of a git tag. Validates the tag/changelog pair, -# builds the APK using the existing Dockerfile (--target build-env), then -# publishes a Forgejo release via the Forgejo REST API and uploads the -# APK as an asset. -# -# Authentication uses ${{ secrets.GITHUB_TOKEN }} (auto-provided by the -# Forgejo runner, scoped to contents: write for the current repo). A -# dedicated PAT (${{ secrets.RELEASE_TOKEN }}) was the preferred option -# for least-privilege, but creating repo-level secrets is currently -# broken on this Forgejo instance (InsertEncryptedSecret fails with a -# UTF-8 byte-sequence error, probably a text-vs-bytea column type on -# the secret table). Bumping to Forgejo v16 should fix it; until then, -# the runner-provided token keeps the workflow operational. -# -# Why bash + jq + curl, no third-party actions: the runner's docker -# label points at pazof/yavsc-build-env, a Debian image with jq but -# without Node.js or python3. Any action like actions/checkout, -# rasterstate/forgejo-release-action, etc. fails with "executable -# file not found in $PATH". jq is shipped in the image from -# debian12-dotnet10-android36-v2 onward; earlier tags fell back to -# hand-rolled JSON building via sed, which was fragile (cf. PR #30: -# sed greedy + head -3 still matched author.id instead of the -# release id on the minified JSON this instance returns, PATCH -# /releases/1 → 404). Same constraint as -# .forgejo/workflows/buildAndTest.yml. -# -# This workflow complements .github/workflows/docker-publish-android.yml -# which targets the GitHub mirror; the validate-release logic mirrors -# the GitHub-side job so the two channels stay consistent. -name: Forgejo Release - -on: - push: - tags: - - '*' - workflow_dispatch: - inputs: - tag: - description: 'Tag Ă  publier (requis en dispatch, ex. 1.0.6 ou 1.0.7-rc1).' - required: true - type: string - -permissions: - contents: write - -jobs: - # Job unique : validation tag/CHANGELOG + build APK + publication - # via l'API REST Forgejo (pas d'actions tierces Node). - release: - runs-on: docker - container: - image: pazof/yavsc-build-env:debian13-dotnet10-android36-jdk21-v1 - steps: - - name: Clone du repo au tag demandĂ© - env: - # En push tag : github.ref_name est le tag. - # En workflow_dispatch : on lit l'input 'tag'. - TAG: ${{ github.event_name == 'push' && github.ref_name || inputs.tag }} - run: | - if [[ -z "$TAG" ]]; then - echo "::error::No tag provided. In workflow_dispatch, set the 'tag' input." - exit 1 - fi - - # WORKDIR de l'image (cf. dotnet-android-build-image/Dockerfile). - cd /src - - if [[ ! -d _src/.git ]]; then - git clone --depth=1 https://forgejo.pschneider.fr/notazof/yavsc.git _src - fi - - cd _src - git fetch --tags --force --prune origin - git checkout "$TAG" - - echo "Checked out at $(git rev-parse HEAD) on $(git describe --tags --always 2>/dev/null || echo unknown)" - - - name: Valider le tag et la section CHANGELOG - run: | - cd /src/_src - TAG="$(git describe --tags --exact-match HEAD 2>/dev/null || git rev-parse --short HEAD)" - echo "Validating tag $TAG" - - # Parse semver : MAJOR.MINOR.PATCH[-SUFFIX] - if [[ ! "$TAG" =~ ^([0-9]+)\.([0-9]+)\.([0-9]+)(-.*)?$ ]]; then - echo "::error::Tag '$TAG' does not match MAJOR.MINOR.PATCH[-SUFFIX] format." - exit 1 - fi - - MAJOR="${BASH_REMATCH[1]}" - MINOR="${BASH_REMATCH[2]}" - PATCH="${BASH_REMATCH[3]}" - SUFFIX="${BASH_REMATCH[4]}" - - # Classification du canal par paritĂ© du patch. - # Patch pair + pas de suffixe -> stable. - # Patch impair + pas de suffixe -> preview. - # Suffixe prĂ©sent -> instable. - if [[ -n "$SUFFIX" ]]; then - CHANNEL="unstable" - elif (( PATCH % 2 == 0 )); then - CHANNEL="stable" - else - CHANNEL="preview" - fi - - echo "Tag $TAG classifiĂ© comme channel=$CHANNEL" - - # Seuls les suffixes explicitement autorisĂ©s dĂ©clenchent un - # release : -rcN et -betaN. Les autres suffixes (-alpha*, - # -dev*, -preview*, etc.) restent refusĂ©s — ils sont - # utilisables localement pour itĂ©rer, mais ne doivent pas - # ĂȘtre publiĂ©s comme release publique. - if [[ "$CHANNEL" == "unstable" ]]; then - if [[ ! "$SUFFIX" =~ ^-(rc|beta)([0-9]+)?$ ]]; then - echo "::error::Tag '$TAG' has suffix '$SUFFIX' which is not in the allowed release suffixes (-rcN, -betaN). Refusing to publish." - exit 1 - fi - fi - - # Lecture du CHANGELOG.md (doit exister Ă  la racine du repo). - if [[ ! -f CHANGELOG.md ]]; then - echo "::error::CHANGELOG.md not found at repo root." - exit 1 - fi - - # Extraction de la section [TAG]. On cherche la premiĂšre ligne - # commençant par '## [' qui contient '[TAG]' (entre '## [' et - # la prochaine ligne '## [' ou fin de fichier). awk en mode - # paragraphe suffit et reste POSIX. On garde aussi le titre - # (ligne `## [TAG] - channel`) pour la vĂ©rification du canal. - BODY=$(awk -v tag="[$TAG]" ' - /^## \[/ { - if (in_section) exit - if (index($0, tag) > 0) { - in_section=1 - print - next - } - } - in_section { print } - ' CHANGELOG.md) - - if [[ -z "$BODY" ]]; then - echo "::error::No section matching '## [$TAG]' found in CHANGELOG.md." - echo "Add a '## [$TAG] - $CHANNEL' section before tagging." - exit 1 - fi - - # VĂ©rification cohĂ©rence du canal dĂ©clarĂ© dans le suffixe. - # Format attendu : "## [TAG] - stable" / "- preview" / "- unstable". - # On lit la premiĂšre ligne du body qui contient le titre. - TITLE=$(echo "$BODY" | head -1) - if [[ "$TITLE" != *" - $CHANNEL"* ]]; then - echo "::error::Section title '$TITLE' must declare suffix '- $CHANNEL' to match tag parity." - exit 1 - fi - - # Body pour la release : retire la premiĂšre ligne (titre). - BODY=$(echo "$BODY" | tail -n +2) - - echo "Section CHANGELOG validĂ©e pour [$TAG] - $CHANNEL" - - # Expose channel + body pour les Ă©tapes suivantes via $GITHUB_ENV. - echo "RELEASE_CHANNEL=$CHANNEL" >> "$GITHUB_ENV" - echo "RELEASE_BODY<> "$GITHUB_ENV" - echo "$BODY" >> "$GITHUB_ENV" - echo "EOF" >> "$GITHUB_ENV" - echo "IS_PRERELEASE=$([ "$CHANNEL" = "stable" ] && echo false || echo true)" >> "$GITHUB_ENV" - - - name: Restore - run: | - cd /src/_src - dotnet restore - - - name: Build de PostIt.Android ARM64 - run: | - cd /src/_src - dotnet build src/PostIt/PostIt.Android/PostIt.Android.csproj \ - -c Release -r android-arm64 --no-restore -clp:ErrorsOnly - - - name: Build de PostIt.Android x64 - run: | - cd /src/_src - dotnet build src/PostIt/PostIt.Android/PostIt.Android.csproj \ - -c Release -r android-x64 --no-restore -clp:ErrorsOnly - - - name: Publier la release Forgejo via l'API REST - # Pas d'action tierce (pas de Node dans l'image runner). - # On parle Ă  l'API Forgejo directement via curl. - # Docs : https://forgejo.pschneider.fr/api/swagger#/repository/release - env: - GITHUB_TOKEN: ${{ secrets.GITHUB_TOKEN }} - GITHUB_API_URL: ${{ github.api_url }} - GITHUB_REPOSITORY: ${{ github.repository }} - TAG: ${{ github.event_name == 'push' && github.ref_name || inputs.tag }} - RELEASE_BODY: ${{ env.RELEASE_BODY }} - IS_PRERELEASE: ${{ env.IS_PRERELEASE }} - run: | - if [[ -z "$TAG" ]]; then - echo "::error::No tag resolved for the API call." - exit 1 - fi - - # Le runner Forgejo expose l'API sur github.api_url (par - # dĂ©faut http://
/api/v1). On retire le suffixe /api/v1 s'il - # est prĂ©sent pour dĂ©river la base du serveur, puis on - # reconstruit l'URL de l'API proprement. - API_BASE="${GITHUB_API_URL%/}" - API_BASE="${API_BASE%/api/v1}" - - # Construction des bodies JSON et extraction de champs via - # jq. L'image runner pazof/yavsc-build-env installe jq - # (>= 1.7) depuis debian12-dotnet10-android36-v2. La - # chaĂźne de construction --arg/--argjson garantit un - # escaping correct (backslashes, guillemets, newlines, - # caractĂšres de contrĂŽle Unicode) sans avoir Ă  le - # reproduire Ă  la main. - # - # json_escape et json_field Ă  base de sed ont vĂ©cu : le - # sed greedy matche la derniĂšre occurrence d'un champ - # dans la ligne, et l'API renvoie sur cette instance un - # JSON minifiĂ© d'une seule ligne oĂč l'id de l'auteur - # (1, premier user du repo) suit l'id de la release - # (10706). PATCH /releases/ tombait - # alors en 404 "The target couldn't be found". jq - # rĂ©sout les deux problĂšmes en une fois. - - # 1. VĂ©rifier si la release existe dĂ©jĂ  pour ce tag. - echo "::group::Check existing release for tag $TAG" - HTTP=$(curl -sS -o /tmp/existing.json -w '%{http_code}' \ - -H "Authorization: token $GITHUB_TOKEN" \ - -H "Accept: application/json" \ - "$API_BASE/api/v1/repos/$GITHUB_REPOSITORY/releases/tags/$TAG") - echo "GET releases/tags/$TAG -> HTTP $HTTP" - EXISTING_ID="" - if [[ "$HTTP" == "200" ]]; then - EXISTING_ID=$(jq -r '.id // empty' /tmp/existing.json) - echo "Existing release id: ${EXISTING_ID:-none}" - fi - echo "::endgroup::" - - # 2. CrĂ©er ou mettre Ă  jour la release. - if [[ -n "$EXISTING_ID" ]]; then - echo "::group::Update release id=$EXISTING_ID" - jq -n \ - --arg body "$RELEASE_BODY" \ - --argjson prerelease "$IS_PRERELEASE" \ - '{body: $body, prerelease: $prerelease}' \ - > /tmp/patch.json - HTTP=$(curl -sS -o /tmp/release.json -w '%{http_code}' \ - -X PATCH \ - -H "Authorization: token $GITHUB_TOKEN" \ - -H "Content-Type: application/json" \ - -H "Accept: application/json" \ - --data-binary @/tmp/patch.json \ - "$API_BASE/api/v1/repos/$GITHUB_REPOSITORY/releases/$EXISTING_ID") - echo "PATCH release -> HTTP $HTTP" - echo "::endgroup::" - else - echo "::group::Create release" - jq -n \ - --arg tag "$TAG" \ - --arg name "$TAG" \ - --arg body "$RELEASE_BODY" \ - --argjson prerelease "$IS_PRERELEASE" \ - '{tag_name: $tag, name: $name, body: $body, prerelease: $prerelease}' \ - > /tmp/post.json - HTTP=$(curl -sS -o /tmp/release.json -w '%{http_code}' \ - -X POST \ - -H "Authorization: token $GITHUB_TOKEN" \ - -H "Content-Type: application/json" \ - -H "Accept: application/json" \ - --data-binary @/tmp/post.json \ - "$API_BASE/api/v1/repos/$GITHUB_REPOSITORY/releases") - echo "POST release -> HTTP $HTTP" - echo "::endgroup::" - fi - - if [[ "$HTTP" != "200" && "$HTTP" != "201" ]]; then - echo "::error::Release creation/update failed (HTTP $HTTP):" - cat /tmp/release.json - exit 1 - fi - - RELEASE_ID=$(jq -r '.id' /tmp/release.json) - echo "Release id=$RELEASE_ID" - - # 3. Upload l'APK en asset. - # Le nom du fichier passe en query string (?name=...), pas - # en argument positionnel entre --data-binary et l'URL : - # sinon curl l'interprĂšte comme un second fichier d'input - # (un fichier nommĂ© '?name=PostIt.Android.apk') et l'API - # Forgejo renvoie 400 "Missing 'name' parameter". - echo "::group::Upload PostIt APK assets" - for MARCH in arm64 x64; do - HTTP=$(curl -sS -o /tmp/asset.json -w '%{http_code}' \ - -X POST \ - -H "Authorization: token $GITHUB_TOKEN" \ - -H "Content-Type: application/octet-stream" \ - -H "Accept: application/json" \ - --data-binary "@/src/_src/src/PostIt/PostIt.Android/bin/Release/net10.0-android/android-$MARCH/fr.pschneider.postit-Signed.apk" \ - "$API_BASE/api/v1/repos/$GITHUB_REPOSITORY/releases/$RELEASE_ID/assets?name=PostIt.Android-$MARCH.apk") - echo "POST asset -> HTTP $HTTP" - if [[ "$HTTP" != "201" ]]; then - echo "::error::Asset upload failed (HTTP $HTTP):" - cat /tmp/asset.json - exit 1 - fi - done - echo "::endgroup::" - - echo "✅ Release publiĂ©e: $API_BASE/$GITHUB_REPOSITORY/releases/tag/$TAG" diff --git a/.github/workflows/codeql.yml b/.github/workflows/codeql.yml index 48d3b4d1..ae9780df 100644 --- a/.github/workflows/codeql.yml +++ b/.github/workflows/codeql.yml @@ -59,7 +59,7 @@ jobs: # your codebase is analyzed, see https://docs.github.com/en/code-security/code-scanning/creating-an-advanced-setup-for-code-scanning/codeql-code-scanning-for-compiled-languages steps: - name: Checkout repository - uses: actions/checkout@v7 + uses: actions/checkout@v4 # Add any setup steps before running the `github/codeql-action/init` action. # This includes steps like installing compilers or runtimes (`actions/setup-node` diff --git a/.github/workflows/docker-publish-android.yml b/.github/workflows/docker-publish-android.yml new file mode 100644 index 00000000..25c3aa2d --- /dev/null +++ b/.github/workflows/docker-publish-android.yml @@ -0,0 +1,36 @@ +name: Build and Push Yavsc Apk + +on: + push: + branches: + - main + workflow_dispatch: + +jobs: + apk-deploy: + runs-on: ubuntu-latest + steps: + - name: Checkout du code + uses: actions/checkout@v7 + + # 1. Votre Ă©tape de build actuelle (on nomme l'image "postit-android") + # --target build-env : on ne veut que le stage de build (qui + # contient les artefacts .apk). Sans --target, Docker ciblerait + # le DERNIER stage du Dockerfile (blogs-runtime, qui est une + # image ASP.NET runtime sans aucun APK Ă  extraire). + - name: Build de l'image Docker + run: docker build --build-arg ANDROID_TARGET_RID=android-arm64 --target build-env -t postit-android . + # 2. EXTRACTION : CrĂ©er un conteneur Ă©phĂ©mĂšre pour copier l'APK vers l'hĂŽte GitHub + - name: Extraire l'APK du conteneur Docker + run: | + docker create --name extractor postit-android + docker cp extractor:/src/src/PostIt/PostIt.Android/bin/Release/net10.0-android/android-arm64/com.CompanyName.PostIt-Signed.apk ./PostIt.Android.apk + docker rm extractor + + - name: TĂ©lĂ©verser l'APK en tant qu'ArtĂ©fact GitHub + uses: actions/upload-artifact@v7 + with: + name: application-apk-release + path: ./PostIt.Android.apk + retention-days: 7 + diff --git a/.gitignore b/.gitignore index b7813f60..fb843f96 100644 --- a/.gitignore +++ b/.gitignore @@ -24,21 +24,9 @@ data/ appsettings.*.json appsettings-*.*.json -# Exception: the Testing-environment override for Yavsc.Org is a tracked -# configuration source, not a secrets file. TestWebApplicationFactory -# (Yavsc.Org.Tests) flips ASPNETCORE_ENVIRONMENT to "Testing" so -# AddConfiguration("org") in Program.Main loads this file as the -# last in the chain (it is optional). It overrides the connection -# string and SMTP section for the in-memory test host and contains -# no production secrets. -!src/Yavsc.Org/appsettings-org.Testing.json - generated/ *.tmp DataDir/ *.tests.trx *.tests.html - -*.log - diff --git a/.gitmodules b/.gitmodules deleted file mode 100644 index eadf3c7f..00000000 --- a/.gitmodules +++ /dev/null @@ -1,3 +0,0 @@ -[submodule "external/dotnet-android-build-image"] - path = external/dotnet-android-build-image - url = https://forgejo.pschneider.fr/notazof/dotnet-android-build-image.git diff --git a/.vscode/launch.json b/.vscode/launch.json index dc8d3c68..c374bc6b 100644 --- a/.vscode/launch.json +++ b/.vscode/launch.json @@ -1,57 +1,33 @@ { - // Utilisez IntelliSense pour en savoir plus sur les attributs possibles. - // Pointez pour afficher la description des attributs existants. - // Pour plus d'informations, visitez : https://go.microsoft.com/fwlink/?linkid=830387 - "version": "0.2.0", - "configurations": [ - { - "name": "Android Debug", - "type": "mono", - "preLaunchTask": "run-debug-android", - "request": "attach", - "address": "localhost", - "port": 55555 - }, - { - "name": "Android Attach - Debug", - "type": "mono", - "request": "attach", - "address": "localhost", - "port": 55555 - }, - { - "name": "API", - "type": "dotnet", - "request": "launch", - "projectPath": "${workspaceFolder}/src/Api/Api.csproj" - }, - { - "name": "Yavsc Org", - "type": "dotnet", - "request": "launch", - "projectPath": "${workspaceFolder}/src/Yavsc.Org/Yavsc.Org.csproj", - }, - { - "name": "Yavsc Blogs", - "type": "dotnet", - "request": "launch", - "projectPath": "${workspaceFolder}/src/Yavsc.Blogs/Yavsc.Blogs.csproj" - }, - { - "name": "PostIt Desktop", - "type": "dotnet", - "request": "launch", - "projectPath": "${workspaceFolder}/src/PostIt/PostIt.Desktop/PostIt.Desktop.csproj", - }, - { - "name": "Test PostIt.Android launch (Xamarin.UITest)", - "type": "coreclr", - "request": "launch", - "program": "${workspaceFolder}/src/PostIt/PostIt.Tests/bin/Debug/net10.0/PostIt.Tests.dll", - "args": [], - "cwd": "${workspaceFolder}/src/PostIt/PostIt.Tests", - "console": "integratedTerminal", - "stopAtEntry": false - } - ] + // Utilisez IntelliSense pour en savoir plus sur les attributs possibles. + // Pointez pour afficher la description des attributs existants. + // Pour plus d'informations, visitez : https://go.microsoft.com/fwlink/?linkid=830387 + "version": "0.2.0", + "configurations": [ + { + "name": "API", + "type": "dotnet", + "request": "launch", + "projectPath": "${workspaceFolder}/src/Api/Api.csproj" + }, + { + "name": "Yavsc.Org", + "type": "dotnet", + "request": "launch", + "projectPath": "${workspaceFolder}/src/Yavsc.Org/Yavsc.Org.csproj" + }, + { + "name": "Yavsc.Blogs", + "type": "dotnet", + "request": "launch", + "projectPath": "${workspaceFolder}/src/Yavsc.Blogs/Yavsc.Blogs.csproj" + }, + { + "name": "PostIt", + "type": "dotnet", + "request": "launch", + "projectPath": "${workspaceFolder}/src/PostIt/PostIt.Desktop/PostIt.Desktop.csproj", + + } + ] } diff --git a/.vscode/settings.json b/.vscode/settings.json index 83a17ae3..0a4785b9 100644 --- a/.vscode/settings.json +++ b/.vscode/settings.json @@ -2,48 +2,29 @@ "dotnet-test-explorer.testProjectPath": "test/**/*Tests.csproj", "cSpell.words": [ - "appsettings", - "asciidoctor", - "ASPNETCORE", - "Avalonia", - "blogspot", - "ConfigurabilitĂ©", - "Cratie", - "DESTDIR", - "dotnet", - "DOTNET", - "ecdsa", - "envsubst", - "Forgejo", - "Hsts", - "Newtonsoft", - "Npgsql", - "Oidc", - "PKCE", - "postit", - "pschneider", - "SLNDIR", - "validable", - "www-data", - "yavsc", - "Yavsc" + "appsettings", + "asciidoctor", + "ASPNETCORE", + "ConfigurabilitĂ©", + "Cratie", + "DESTDIR", + "dotnet", + "DOTNET", + "ecdsa", + "envsubst", + "Newtonsoft", + "Npgsql", + "postit", + "pschneider", + "SLNDIR", + "validable", + "www-data", + "yavsc", + "Yavsc" ], "cSpell.reportUnknownWords": true, "cSpell.language": "fr,en", "makefile.configureOnOpen": false, "search.useGlobalIgnoreFiles": true, - "search.useParentIgnoreFiles": true, - "chat.mcp.serverSampling": { - "yavsc/.vscode/mcp.json: openclaw": { - "allowedModels": [ - "copilot/auto", - "copilotcli/claude-haiku-4.5", - "copilotcli/gpt-4.1", - "copilotcli/gpt-5-mini", - "copilotcli/mai-code-1-flash-picker", - "copilotcli/gpt-5.3-codex" - ] - } - }, - "dotnet.defaultSolution": "yavsc.sln" + "search.useParentIgnoreFiles": true } diff --git a/.vscode/tasks.json b/.vscode/tasks.json index 3faedae0..c384ec79 100644 --- a/.vscode/tasks.json +++ b/.vscode/tasks.json @@ -1,43 +1,6 @@ { "version": "2.0.0", - "isRoot": true, - "problemMatcher": [ - { - "owner": "dotnet", - "fileLocation": ["relative", "${workspaceFolder}"], - "source": "dotnet", - "pattern": { - "regexp": "^\\s+(.*)\\((\\d+):(\\d+)\\):\\s+(error|warning)\\s+(.*)$", - "file": 1, - "line": 2, - "column": 3, - "severity": 4, - "message": 5 - } - } - ], "tasks": [ - { - "label": "run-debug-android", - "command": "dotnet", - "type": "shell", - "options": { - "cwd": "${workspaceFolder}/src/PostIt/PostIt.Android", - "env": { - "DOTNET_HOST_PATH": "/usr/share/dotnet", - "ANDROID_HOME": "/opt/android-sdk", - "JAVA_HOME": "/usr/lib/jvm/java-1.25.0-openjdk-amd64" - } - }, - "args": [ - "run", - "-p:TargetFramework=net10.0-android", - "-p:Configuration=Debug", - "-p:AndroidAttachDebugger=true", - "-p:AndroidSdbHostPort=55555", - "-p:AndroidSdbTargetPort=55555" - ] - }, { "label": "build", "command": "dotnet", @@ -46,20 +9,20 @@ "group": "build", "isBuildCommand": true, "isTestCommand": false, + "problemMatcher": ["$msCompile"], "isBackground": true }, { - "label": "test blogs backend", + "label": "build-web", "type": "process", "problemMatcher": ["$msCompile"], "command": "dotnet", - "args": ["test"], + "args": ["build"], "options": { - "cwd": "src/Yavsc.Blogs.Tests" + "cwd": "src/Yavsc.Org" }, "group": { - "kind": "test", - "isDefault": false + "kind": "build" } }, { @@ -75,6 +38,53 @@ "kind": "build" }, "isBackground": true + }, + { + "label": "build-web", + "type": "process", + "problemMatcher": ["$msCompile"], + "command": "dotnet", + "args": ["build"], + "runOptions": {}, + "options": { + "cwd": "src/Yavsc.Web" + }, + "group": { + "kind": "build" + }, + "isBackground": true, + "presentation": { + "echo": true, + "reveal": "always", + "focus": false, + "panel": "shared", + "showReuseMessage": true, + "clear": false + } + }, + { + "label": "publish", + "command": "dotnet", + "type": "process", + "args": [ + "publish", + "/property:GenerateFullPaths=true", + "/consoleloggerparameters:NoSummary;ForceNoAlign" + ], + "problemMatcher": "$msCompile" + }, + { + "label": "watch", + "command": "dotnet", + "type": "process", + "args": ["watch", "--project", + "src/Yavsc.Org/Yavsc.Org.csproj" + ], + "problemMatcher": "$msCompile", + "runOptions": { + + } + } ] } diff --git a/CHANGELOG.md b/CHANGELOG.md deleted file mode 100644 index 7210a227..00000000 --- a/CHANGELOG.md +++ /dev/null @@ -1,229 +0,0 @@ -# Changelog - -Toutes les modifications notables de PostIt et de la plateforme Yavsc -sont documentĂ©es dans ce fichier. - -Le format suit [Keep a Changelog](https://keepachangelog.com/fr/1.1.0/), -et ce projet adhĂšre au [Semantic Versioning](https://semver.org/spec/v2.0.0.html). - -À noter : la **paritĂ© du numĂ©ro de patch** porte une signification de canal : - -- **patch pair** (ex. `1.0.0`, `1.0.2`) → **stable** -- **patch impair** (ex. `1.0.1`, `1.0.3`) → **preview** -- **suffixe** (ex. `1.0.0-rc1`, `1.0.0-alpha`) → **instable** - -Cette convention est partagĂ©e avec le dĂ©pĂŽt -[`postit-debian`](https://forgejo.pschneider.fr/notazof/postit-debian) -pour la production des paquets `.deb`. - - -## [1.0.8-rc6] - unstable - -### Added - -* a code cleanup, -* a first Xamarin.UITest is successful, but disabled, because breaking the actual CI process, -* Android app starts, the login process succeeds - -### Changed - -L'identifiant de l'application client Android a changĂ©, il passe en minuscules : -`fr.pschneider.postit` - -### Fixed - -a bug posting and retrieving ACL from the backend, -the ACL now comes along with the article, -[TODO][PostIt] keep ACL along with the article - -## [1.0.8-rc1] - unstable - -### Added -- `BlogAclApiTests.PostCircleAuthorization_returns_201_when_payload_mirrors_PostIt_shape_against_existing_circle_named_test` - : test de non-rĂ©gression qui Ă©pingle la forme exacte du payload - que PostIt envoie Ă  `POST /api/v1/blogacl` (un objet - `PostAccessControlRulePayload` avec `CircleId` et `BlogPostId`). - C'est le verrou cĂŽtĂ© test du fix applicatif PostIt + serveur. -- `BlogAclApiTests.PostCircleAuthorization_never_returns_500` : une - `[Theory]` couvrant quatre shapes de payload (`{ circleId }`, - corps vide, `{ blogPostId }` seul, `{ circleId, blogPostId: 0 }`) - qui doivent tous retourner un statut diffĂ©rent de 500. Toute - rĂ©introduction d'un chemin 500 dans le futur fera rougir ce test. -- `BlogAclApiTests.PostCircleAuthorization_dosent_return_500` et - `..._dosent_return_500_on_success` : entry points `[Fact]` qui - appellent la `[Theory]` ci-dessus avec un payload spĂ©cifique - chacun, pour pouvoir filtrer en isolation depuis la ligne de - commande ou le CI. -- RĂšgle « Pas de `object` dans le code source applicatif » ajoutĂ©e - Ă  `CONTRIBUTING.md` : types de retour, paramĂštres, champs, - propriĂ©tĂ©s, variables locales doivent ĂȘtre typĂ©s statiquement. - `dynamic` est interdit pour les mĂȘmes raisons. - -### Changed -- `BlogAclApiController.CheckOwner` devient `CheckOwnerAsync` et - utilise `FirstOrDefaultAsync` au lieu de `First`, supprimant - l'appel LINQ synchrone sur le fil de la requĂȘte et retournant - `false` sur cercle manquant (le contrĂŽleur mappe dĂ©jĂ  cela vers - `ChallengeResult`). -- `BlogsWebServerFixture` seed `alice`, son `Circle` et son - `BlogPost` une seule fois au dĂ©marrage du host, sur la - `SqliteConnection` partagĂ©e (`Cache=Shared`). Le prĂ©cĂ©dent - `EnsureDeleted` au dĂ©but de chaque test fermait la connexion - statique et dĂ©truisait le store `:memory:` pour tous les autres - `DbContext` ; il est retirĂ© au profit d'un `EnsureCreated` - idempotent. - -### Fixed -- `POST /api/v1/blogacl` ne retourne plus 500 sur les payloads - dont `BlogPostId` est absent ou Ă  zĂ©ro. Le contrĂŽleur rejette - `BlogPostId <= 0` avec `400 BadRequest` avant que la requĂȘte - n'atteigne `SaveChangesAsync`. L'incident de prod du 2026-08-21 - sur mercure (PostIt envoyant seulement `circleId`, le serveur - voyant `BlogPostId = default(long) = 0` et EF Core levant - `InvalidOperationException` sur l'INSERT) n'est plus atteignable. -- PostIt `PostAclDialogViewModel.AddAsync` envoie dĂ©sormais le - payload explicite `PostAccessControlRulePayload { CircleId, - BlogPostId }` au lieu de l'ancien `CircleAuthorization { - CircleId }`. Le DTO serveur `PostAccessControlRulePayload` est - introduit dans `Yavsc.Abstract` pour porter le contrat. - -## [1.0.7] - preview - -### Added -- Per-post ACL in PostIt: a new “Manage ACL” page, opened from the ACL - button on a selected post, lets the post author grant or revoke - grants for individuals or circles. The server scopes each grant - operation to `caller == post.AuthorId` and returns `404` (not `403`) - for posts the caller does not own, so the existence of another - user's post is not leaked. -- Circle membership API + UI: three new REST endpoints under - `/api/circle/{id}/members` (`GET` list, `POST` add, `DELETE` - remove) and a new “Members” column on the *My Circles* page with an - “Add a member” button that opens a search modal. The search modal - reuses `IUserDirectory` (introduced by the `IContactService` split - in this same release) — exactly the use case the abstraction was - carved out for. -- Publish toggle for blog posts: a new `PUT /api/BlogApi/{id}/publish` - endpoint, and a `Published` checkbox in the post toolbar that - toggles a `BlogSpotPublication` row for the post. The publish - signal flows through the pre-existing `PermissionHandler.IsPublic` - path, so no new column was needed and the server-side authorisation - logic is unchanged. -- `UserSearchApiController` in `Yavsc.Blogs`: - `GET /api/user-search?q=...&e=...&take=...`. Any-authenticated- - caller endpoint that exposes the user's email under a closed- - community assumption (documented in the controller's XML doc). - Wired to the PostIt Desktop address book so the user search modal - picks it up. -- `IYavscApiClient` abstraction in `Yavsc.Api.Client`. The transport - for the blog/circle/blog-acl/user-search clients is now accessed - through this interface, so `PostIt.Tests` can stub the HTTP layer - without spinning up a real WebAPI host. -- Forgejo Actions release workflow: a `.forgejo/workflows/release.yml` - pipeline that builds and publishes a release with the PostIt APK - on tag push. Written in pure bash (the runner image has no Node), - uses `jq` for JSON body construction and response parsing, uses the - runner-provided `GITHUB_TOKEN` (no repo-level secret needed), - validates the CHANGELOG section heading before allowing the tag - to ship. -- `make release V=` target: creates a `release/` branch - from `main`, bumps the `` property in every `.csproj` via - `dotnet-gitversion /updateprojectfiles`, commits the bump on the - release branch, and pushes to `origin`. Fails fast if the working - tree is dirty or if `HEAD` is not on `main`. -- Forgejo status badges in the README. - -### Changed -- The new Publish toggle replaces the “Visibility enum” approach - originally drafted in this branch: the existing `BlogSpotPublication` - table already carried enough information to expose a publish - switch, so no schema change was needed. The original `feat(blog): - add Visibility { Private, Public }` commit and its EF migration - were reverted in favour of the endpoint-only toggle. -- `BlogPost` DTO and `IBlogPost` moved from `PostIt.Models` to - `Yavsc.Abstract.Blogspot`, the shared assembly where the server-side - entity and the wire DTO both live. Renamed `Yavsc.Blogspot.BlogPost` - to `BlogPostDto` to make the wire/entity distinction explicit. -- `BlogAclApiController` and `CircleApiController` moved from - `Yavsc.Api` (not yet enabled in production) to `Yavsc.Blogs`, where - they belong next to the `BlogSpotService` they depend on. -- `IContactService` split from `IUserDirectory`: the two interfaces - previously conflated the local address-book access (mobile-only, - via `Contacts.Default`) and the Yavsc user-search access - (Desktop-only, via `/api/user-search`) behind a single facade. The - split restores the `ContactDto.Emails` multi-value shape that was - being silently flattened to a single string before. -- CI: the Forgejo Actions build now compiles `.csproj` projects - directly inside the runner container (which ships the .NET SDK + - Android workload), instead of relying on a separate Docker build - step. Node-based third-party actions were replaced with bash + curl - + `jq`. The validate-release job parses the CHANGELOG section - heading to derive the channel (`stable` / `preview` / `unstable`) - rather than the patch-version parity alone. - -### Fixed -- `CircleApiController` used to read the caller's user id via - `FindFirstValue(ClaimTypes.NameIdentifier)`, which does not match - when JWT Bearer middleware has `MapInboundClaims = false`. Switched - to `User.GetUserId()` (tries `sub` first, then - `ClaimTypes.NameIdentifier`, then `nameid`). This was a latent - bug visible in tests but easy to ship to production if a host - ever disabled the remap. -- `CircleApiController` and `BlogAclApiController` reads and writes - were not always scoped to the caller's own data. Tightened the - authorisation checks: cross-user reads now return `404`, not the - raw record. -- `validate-release` CHANGELOG channel check used to parse the - patch-version parity only, which disagreed with the channel - suffix in the section heading (e.g. `## [1.0.7] - preview` - would be flagged as `stable` from the parity alone). The job now - inspects the heading line and trusts the suffix when present. -- `.forgejo/workflows/release.yml`: the asset-upload URL now carries - the asset name as a query-string parameter instead of a `curl` - positional argument. The previous shape triggered Forgejo's - “Missing `name` parameter” 400 in some cases. - -### Removed -- The `## [Unreleased]` block has been moved into this section. -- The abandoned `Visibility { Private, Public }` enum and its EF - migration, reverted in this release. The publish toggle covers - the same user-visible switch without a schema change. - -[Unreleased]: https://forgejo.pschneider.fr/notazof/yavsc/compare/HEAD -[1.0.8-rc1]: https://forgejo.pschneider.fr/notazof/yavsc/compare/1.0.7...1.0.8-rc1 -[1.0.7]: https://forgejo.pschneider.fr/notazof/yavsc/compare/1.0.6...1.0.7 -[1.0.6]: https://forgejo.pschneider.fr/notazof/yavsc/compare/1.0.5...1.0.6 - -## [1.0.6] - stable - -### Added -- Self-hosted Forgejo Actions runner now drives the CI build for the - yavsc repository, using the - `pazof/yavsc-build-env:debian12-dotnet10-android36-v2` image pulled - from Docker Hub. Workflow runs end-to-end: clone, restore, build, - test, with NuGet.config picking up the `isn.pschneider.fr` feed. -- The build-env image now ships `jq` (Debian package, ≄ 1.7), so the - release workflow can build JSON bodies and parse API responses - without a hand-rolled `sed`-based extractor that was matching the - wrong `id` field on minified responses. - -### Changed -- CI workflow `.forgejo/workflows/buildAndTest.yml` no longer relies on - `actions/checkout` (the runner image has no Node); clones yavsc via - `git`, fetches the ref under test, and initializes submodules over - HTTPS. - -### Fixed -- `Dockerfile` and `Dockerfile.backend` no longer carry a redundant - `dotnet nuget add source` step that conflicted with the GitHub - Actions APK build (`--allow-insecure-connections` on an HTTPS - endpoint, exit 1). `NuGet.config` at the repo root supplies the - `isn.pschneider.fr` feed for every restore, including inside Docker. -- `.forgejo/workflows/release.yml`: PATCH on `/releases/{id}` no longer - 404s on existing releases. The previous `sed`-based `json_field` - matched the last `id` on the line (the author's), so it tried to - PATCH `/releases/1` (the first user of the instance) instead of the - actual release id. Switched to `jq` for both body construction and - field extraction. - -[1.0.6]: https://forgejo.pschneider.fr/notazof/yavsc/compare/1.0.5...1.0.6 diff --git a/CONTRIBUTING.md b/CONTRIBUTING.md index b9969ea5..4730e18c 100644 --- a/CONTRIBUTING.md +++ b/CONTRIBUTING.md @@ -11,7 +11,7 @@ ## Premier build ```bash -git clone https://forgejo.pschneider.fr/notazof/yavsc.git +git clone https://github.com/pazof/yavsc.git cd yavsc dotnet restore dotnet build @@ -49,57 +49,6 @@ Les tests sont rĂ©partis en : item « Tests d'intĂ©gration smoke par BC ». - `src/PostIt.Tests/` — tests unitaires du client desktop PostIt. -## Navigation (PostIt) - -La navigation est centralisĂ©e dans -`App.PushPageAsync(ViewModelBase vm)` (`src/PostIt/PostIt/App.axaml.cs`). -Pour ouvrir un Ă©cran, un ViewModel (gĂ©nĂ©ralement dans une -commande `[RelayCommand]`) appelle -`await ((App)App.Current!).PushPageAsync(targetVm).ConfigureAwait(true);`. -`PushPageAsync` rĂ©sout la `Control` correspondante via le -`ViewLocator` (un `IDataTemplate` enregistrĂ© dans -`Application.DataTemplates` au boot), l'identifie comme -`Page`, lui assigne le VM comme `DataContext`, et appelle -`NavRoot.PushAsync(page)`. Une garde anti-empilement -compare par rĂ©fĂ©rence la nouvelle page au sommet courant -de la stack pour Ă©viter un push doublon. - -Pour qu'une nouvelle page soit navigable, il faut *deux* -enregistrements : la page dans le DI (`AddTransient` -ou `AddSingleton`) **et** une case dans le `switch` -de `ViewLocator.Build`. Si l'un manque, l'app affiche -"No view for X" sans crash. - -RĂšgles : - -- On n'instancie jamais une `View` Ă  la main depuis un - ViewModel, on ne rĂ©cupĂšre jamais une `View` depuis la DI - directement dans un ViewModel. -- Le ViewModel qui dĂ©clenche la nav ne pousse pas lui-mĂȘme - la page ; il appelle `App.PushPageAsync(vm)` et laisse - `App` orchestrer le `PushAsync` physique. -- Le ViewModel qui dĂ©clenche la nav ne capture pas de - rĂ©fĂ©rence Ă  `MainWindow` ou `NavigationPage`. Il passe - par `App.Current` (l'app Avalonia est un singleton). - -Exemple canonique (depuis `MainPageViewModel`) : - -```csharp -[RelayCommand] -internal async Task OpenSettings() -{ - var settingsVm = ((App)App.Current!).ServiceProvider - .GetRequiredService(); - await ((App)App.Current!).PushPageAsync(settingsVm) - .ConfigureAwait(true); -} -``` - -Cf. [doc/architecture/postit.md](./doc/architecture/postit.md) -pour la topologie complĂšte (host de navigation, -`SessionStatusViewModel`, signaux de cycle de vie vs nav -utilisateur). - ## Conventions de code Le repo applique `.editorconfig` (UTF-8, LF, `indent_size = 4` en @@ -115,13 +64,6 @@ Quelques rĂšgles non capturĂ©es par `.editorconfig` : - PrĂ©fĂ©rer les types BCL (`int`, `string`) aux types framework (`Int32`, `String`). - PrĂ©fĂ©rer les expressions de pattern matching aux casts explicites. -- **Pas de `object` dans le code source applicatif.** Types de retour, - paramĂštres, champs, propriĂ©tĂ©s, variables locales : tout doit ĂȘtre - typĂ© statiquement. `dynamic` est interdit pour les mĂȘmes raisons. - Un cast en `object` est presque toujours le symptĂŽme d'un contrat - qu'on a laissĂ© s'effriter (DTO, payload, handler) — refactore - le contrat (record typĂ©, DTO dĂ©diĂ©, mĂ©thode dĂ©diĂ©e) au lieu de - shimer avec un cast. ## Branches & commits diff --git a/Directory.Build.props b/Directory.Build.props index 83d21579..051dba7a 100644 --- a/Directory.Build.props +++ b/Directory.Build.props @@ -1,6 +1,5 @@ Yavsc - NU1701, NU1901, NU1902, NU1507 diff --git a/Directory.Packages.props b/Directory.Packages.props index 7505c851..d3664121 100644 --- a/Directory.Packages.props +++ b/Directory.Packages.props @@ -2,29 +2,31 @@ true + - - + + - - - - - - + - - \ No newline at end of file diff --git a/Dockerfile b/Dockerfile index 795b70ab..e534f8ad 100644 --- a/Dockerfile +++ b/Dockerfile @@ -46,6 +46,10 @@ COPY src/PostIt/PostIt.Desktop/*.csproj ./src/PostIt/PostIt.Desktop/ # (2) Tout le code source COPY . . +# (3) Source NuGet interne (Letsencrypt, certificat auto-signĂ© cĂŽtĂ© +# serveur, justifiĂ© par build privĂ©). +RUN dotnet nuget add source https://isn.pschneider.fr/v3/index.json --allow-insecure-connections + # (4) Restore RUN dotnet restore diff --git a/Dockerfile.backend b/Dockerfile.backend index a4e9a54a..86df9ccd 100644 --- a/Dockerfile.backend +++ b/Dockerfile.backend @@ -25,6 +25,9 @@ COPY src/PostIt/PostIt.Desktop/*.csproj ./src/PostIt/PostIt.Desktop/ # 4. Copie de l'intĂ©gralitĂ© du code source COPY . . +# 3. Restauration des dĂ©pendances avec vos workloads actifs +RUN dotnet nuget add source https://isn.pschneider.fr/v3/index.json --allow-insecure-connections + # 4. Restauration des dĂ©pendances pour tous les projets RUN dotnet restore diff --git a/Makefile b/Makefile index fa9d4ecf..a4922a3d 100644 --- a/Makefile +++ b/Makefile @@ -10,8 +10,8 @@ include .env all: dotnet build --nologo -clean: - dotnet clean -c $(CONFIG) +clean: + dotnet clean src/Yavsc/bin/output/wwwroot: dotnet --project src/Yavsc.Org/Yavsc.Org.csproj publish @@ -31,7 +31,7 @@ src/Yavsc.Server/bin/$(CONFIG)/$(FRAMEWORK)/Yavsc.Server.dll: src/Yavsc/bin/$(CONFIG)/$(FRAMEWORK)/Yavsc.dll: dotnet build -p:Configuration=$(CONFIG) --project src/Yavsc.Org/Yavsc.Org.csproj -$(DESTDIR): +$(DESTDIR): mkdir $(DESTDIR) install: $(DESTDIR) @@ -48,77 +48,5 @@ docker-build: docker-run: docker run -d -p 5000:5000 --name yavsc yavsc -# CrĂ©e une branche release/ depuis main, met Ă  jour les -# `` des .csproj via dotnet-gitversion, et la -# pousse sur origin. -# -# Usage : make release V=1.0.7-rc1 -# -# PrĂ©-requis : ĂȘtre sur main, working tree clean. La cible -# vĂ©rifie les deux et refuse sinon — elle ne fait JAMAIS -# de checkout automatique, c'est Ă  l'opĂ©rateur de s'ĂȘtre -# positionnĂ© sur la bonne branche au prĂ©alable (sinon le -# bump pourrait partir sur une branche tierce par accident). -# -# Notes : -# - Le nom de branche vient de l'argument V (ex: 1.0.7-rc1 -# donne release/1.0.7-rc1). C'est une Ă©tiquette d'intention, -# pas la version assembly. -# - La version dans les .csproj vient de GitVersion qui la -# calcule depuis l'historique git (tag le plus proche + -# nombre de commits). C'est la version assembly rĂ©elle. -# - L'ordre (fetch → branche → bump → push) garantit qu'on -# part d'un main synchro et qu'on ne pollue pas main avec -# le bump (qui vit sur la branche release). -# - Fail-fast si la branche existe dĂ©jĂ  en local ou sur origin. -release: - @if [ -z "$(V)" ]; then \ - echo "Usage: make release V="; \ - echo " V : version semver (ex. 1.0.7-rc1) — sert Ă  nommer la branche."; \ - exit 1; \ - fi - @CURRENT=$$(git branch --show-current); \ - if [ "$$CURRENT" != "main" ]; then \ - echo "Refus : la cible doit ĂȘtre lancĂ©e depuis main."; \ - echo " Branche courante : $$CURRENT"; \ - echo " Fais : git checkout main && git pull --ff-only origin main"; \ - exit 1; \ - fi - @if [ -n "$$(git status --porcelain)" ]; then \ - echo "Working tree sale, refus de crĂ©er une branche release."; \ - git status --short; \ - exit 1; \ - fi - @BRANCH="release/$(V)"; \ - if git show-ref --verify --quiet "refs/heads/$$BRANCH"; then \ - echo "La branche $$BRANCH existe dĂ©jĂ  en local."; \ - echo " Pour la supprimer : git branch -D $$BRANCH"; \ - exit 1; \ - fi; \ - if git ls-remote --exit-code --heads origin "$$BRANCH" >/dev/null 2>&1; then \ - echo "La branche $$BRANCH existe dĂ©jĂ  sur origin."; \ - exit 1; \ - fi; \ - echo "==> Fetch + vĂ©rification synchro main"; \ - git fetch origin main; \ - if ! git merge-base --is-ancestor origin/main HEAD; then \ - echo "main a avancĂ© plus loin que HEAD. Fais :"; \ - echo " git pull --ff-only origin main"; \ - exit 1; \ - fi; \ - echo "==> CrĂ©ation de $$BRANCH depuis main"; \ - git checkout -b "$$BRANCH"; \ - echo "==> dotnet-gitversion /updateprojectfiles"; \ - dotnet-gitversion /updateprojectfiles; \ - echo "==> Commit du bump"; \ - git add .; \ - if git diff --cached --quiet; then \ - echo "Pas de changements Ă  committer (gitversion n'a produit aucune diff)."; \ - else \ - git commit -m "chore(release): bump version via gitversion for $(V)"; \ - fi; \ - echo "==> Push de $$BRANCH sur origin"; \ - git push -u origin "$$BRANCH"; \ - echo "==> TerminĂ©. Branche $$BRANCH live sur origin." -.PHONY: test release +.PHONY: test diff --git a/NuGet.config b/NuGet.config deleted file mode 100644 index c601d09b..00000000 --- a/NuGet.config +++ /dev/null @@ -1,23 +0,0 @@ - - - - - - - - - diff --git a/README.md b/README.md index b132f3f2..1f1e7ce5 100644 --- a/README.md +++ b/README.md @@ -1,25 +1,16 @@ # Yavsc - [![The latest release made in the repository](https://forgejo.pschneider.fr/notazof/yavsc/badges/release.svg)](https://forgejo.pschneider.fr/notazof/yavsc/releases/latest) C'est une application mettant en oeuvre une prise de contact entre un demandeur de services et son Ă©ventuel prestataire associĂ©. -# Statut actuel des actions Forgejo - - -* [![Build and test](https://forgejo.pschneider.fr/notazof/yavsc/badges/workflows/buildAndTest.yml/badge.svg)](https://forgejo.pschneider.fr/notazof/yavsc/actions?workflow=buildAndTest.yml) - -* [![Release](https://forgejo.pschneider.fr/notazof/yavsc/badges/workflows/release.yml/badge.svg)]( -https://forgejo.pschneider.fr/notazof/yavsc/actions?workflow=release.yml -) - # Statut actuel des actions GitHub -* [![CodeQL Advanced](https://github.com/pazof/yavsc/actions/workflows/codeql.yml/badge.svg)](https://github.com/pazof/yavsc/actions/workflows/codeql.yml) +* [![Build and Push Yavsc Apk](https://github.com/pazof/yavsc/actions/workflows/docker-publish-android.yml/badge.svg)](https://github.com/pazof/yavsc/actions/workflows/docker-publish-android.yml) * [![Build and Push Yavsc Production Image](https://github.com/pazof/yavsc/actions/workflows/docker-publish-backend.yml/badge.svg)](https://github.com/pazof/yavsc/actions/workflows/docker-publish-backend.yml) +* [![CodeQL Advanced](https://github.com/pazof/yavsc/actions/workflows/codeql.yml/badge.svg)](https://github.com/pazof/yavsc/actions/workflows/codeql.yml) # Documentation @@ -161,13 +152,6 @@ d'abord `appsettings-org.json` du serveur ; sinon, laisse-le en place. (utilisateur, mot de passe, hĂŽte, base). PrivilĂ©gier `dotnet user-secrets` ou des variables d'environnement `ASPNETCORE_*` plutĂŽt qu'un mot de passe en clair dans le fichier. -- Au dĂ©marrage, Yavsc.Org applique automatiquement ses migrations EF - Core. Sur cette base de code, EF Core 10 peut encore lever un - `PendingModelChangesWarning` malgrĂ© des migrations et snapshots dĂ©jĂ  - alignĂ©s ; ce faux positif est ignorĂ© sur les contextes PostgreSQL pour - Ă©viter un dĂ©marrage inutilement en mode dĂ©gradĂ©. Si une erreur de - migration apparaĂźt encore en production, elle doit ĂȘtre traitĂ©e comme - une vraie divergence de schĂ©ma ou de connexion. - `Smtp.*` — hĂŽte, port, identifiants SMTP pour l'envoi d'e-mails transactionnels. - `Authentication.PayPal.*` et `Authentication.Google.*` — clĂ©s d'API diff --git a/contrib/Makefile b/contrib/Makefile index 151045db..62e1e22d 100644 --- a/contrib/Makefile +++ b/contrib/Makefile @@ -1,4 +1,4 @@ -APP_PROJECT_NAMES=Org Blogs +APP_PROJECT_NAMES=Api Org Blogs SLNDIR=.. include $(SLNDIR)/.env @@ -7,6 +7,7 @@ include .env generated/: @mkdir -p $@ +generated/yavscApi.service: generated/yavscOrg.service: generated/yavscBlogs.service: @@ -33,11 +34,12 @@ generated/yavsc%.service: generated/ template.service $(SLNDIR)/.env @echo Created service file: $@ -copy-services: copy-service-Org copy-service-Blogs +copy-services: copy-service-Org copy-service-Api copy-service-Blogs copy-service-Org: /etc/systemd/system/yavscOrg.service +copy-service-Api: /etc/systemd/system/yavscApi.service copy-service-Blogs: /etc/systemd/system/yavscBlogs.service -copy-binaries: build_publish_Org build_publish_Blogs stop-services +copy-binaries: build_publish_Org build_publish_Api build_publish_Blogs stop-services @for project in $(APP_PROJECT_NAMES); \ do LCAPI=$$(echo $${project}|tr [:upper:] [:lower:]) ; \ echo "$${project} -> $${LCAPI}" ; \ @@ -53,7 +55,7 @@ copy-binaries: build_publish_Org build_publish_Blogs stop-services done @sudo chown -R $(USER_AND_GROUP) $(BASEAPPDIR) -/etc/systemd/system/yavsc%.service: generated/yavsc%.service +/etc/systemd/system/yavsc%.service: generated/yavsc%.service sudo cp $^ $@ sudo chown root:root $@ @@ -63,14 +65,14 @@ build_publish_%: clean_publish_dir_% clean_publish_dir_%: @rm -rf $(SLNDIR)/src/Yavsc.$*/bin/$(CONFIGURATION)/$(DOTNET_FRAMEWORK)/publish -install: build_publish copy-binaries copy-services +install: build_publish copy-binaries copy-services @sudo systemctl daemon-reload @for project in $(APP_PROJECT_NAMES); \ do \ sudo systemctl enable yavsc$${project} ; \ sudo systemctl start yavsc$${project} ; \ done - + reinstall: copy-binaries @sync @for project in $(APP_PROJECT_NAMES); do \ @@ -84,12 +86,13 @@ stop-services: $(SLNDIR)/src/Yavsc.Org/bin/$(CONFIGURATION)/$(DOTNET_FRAMEWORK)/publish: build_publish $(SLNDIR)/src/Yavsc.Blogs/bin/$(CONFIGURATION)/$(DOTNET_FRAMEWORK)/publish: build_publish +$(SLNDIR)/src/Yavsc.Api/bin/$(CONFIGURATION)/$(DOTNET_FRAMEWORK)/publish: build_publish -showConfig: +showConfig: @echo CONFIGURATION: $(CONFIGURATION) @echo BASEAPPDIR: $(BASEAPPDIR) clean: @rm -rf generated -.PHONY: build_publish mep showConfig copy-service-Org copy-service-Blogs reinstall clean +.PHONY: build_publish mep showConfig copy-service-Api copy-service-Org copy-service-Blogs reinstall clean diff --git a/contrib/bruno/Get Posts.bru b/contrib/bruno/Get Posts.bru deleted file mode 100644 index bafe95b1..00000000 --- a/contrib/bruno/Get Posts.bru +++ /dev/null @@ -1,16 +0,0 @@ -info: - name: Get Posts - type: http - seq: 1 - -http: - method: GET - url: https://jsonplaceholder.typicode.com/users - -settings: - encodeUrl: true - timeout: 0 - followRedirects: true - maxRedirects: 5 - -docs: This request retrieves a list of users from the JSONPlaceholder API. diff --git a/contrib/bruno/Untitled.bru b/contrib/bruno/Untitled.bru deleted file mode 100644 index 168811b2..00000000 --- a/contrib/bruno/Untitled.bru +++ /dev/null @@ -1,15 +0,0 @@ -info: - name: Untitled - type: http - seq: 1 - -http: - method: GET - url: "" - auth: inherit - -settings: - encodeUrl: true - timeout: 0 - followRedirects: true - maxRedirects: 5 diff --git a/contrib/bruno/blog post.yml b/contrib/bruno/blog post.yml deleted file mode 100644 index 94e2745f..00000000 --- a/contrib/bruno/blog post.yml +++ /dev/null @@ -1,22 +0,0 @@ -info: - name: blog post - type: http - seq: 2 - -http: - method: POST - url: "{{Blogs}}/api/v1/blog" - body: - type: json - data: |- - { - "Title": "lkijlk", - "Article": "test" - } - auth: inherit - -settings: - encodeUrl: true - timeout: 0 - followRedirects: true - maxRedirects: 5 diff --git a/contrib/bruno/blogs.yml b/contrib/bruno/blogs.yml deleted file mode 100644 index 2767b01d..00000000 --- a/contrib/bruno/blogs.yml +++ /dev/null @@ -1,15 +0,0 @@ -info: - name: blogs - type: http - seq: 1 - -http: - method: GET - url: "{{Blogs}}/api/v1/blog" - auth: inherit - -settings: - encodeUrl: true - timeout: 0 - followRedirects: true - maxRedirects: 5 diff --git a/contrib/bruno/environments/Development.yml b/contrib/bruno/environments/Development.yml deleted file mode 100644 index 0fd5430e..00000000 --- a/contrib/bruno/environments/Development.yml +++ /dev/null @@ -1,6 +0,0 @@ -name: Development -variables: - - name: Blogs - value: https://localhost:5003 - - name: Authority - value: https://localhost:5001 diff --git a/contrib/bruno/environments/Production.yml b/contrib/bruno/environments/Production.yml deleted file mode 100644 index fda7173b..00000000 --- a/contrib/bruno/environments/Production.yml +++ /dev/null @@ -1,6 +0,0 @@ -name: Production -variables: - - name: Authority - value: https://yavsc.pschneider.fr - - name: Blogs - value: https://blogs.pschneider.fr diff --git a/contrib/bruno/opencollection.yml b/contrib/bruno/opencollection.yml deleted file mode 100644 index 374cd0e1..00000000 --- a/contrib/bruno/opencollection.yml +++ /dev/null @@ -1,43 +0,0 @@ -opencollection: 1.0.0 - -info: - name: blogs -config: - proxy: - inherit: true - config: - protocol: http - hostname: "" - port: "" - auth: - username: "" - password: "" - bypassProxy: "" - -request: - auth: - type: oauth2 - flow: authorization_code - authorizationUrl: "{{Authority}}/connect/authorize" - accessTokenUrl: "{{Authority}}/connect/token" - refreshTokenUrl: https://yavsc.pschneider.fr/connect/token - callbackUrl: "{{Authority}}" - credentials: - clientId: postit - placement: basic_auth_header - scope: openid blogs profile - pkce: {} - tokenConfig: - id: credentials - placement: - header: Bearer - source: access_token - settings: - autoFetchToken: true - autoRefreshToken: true -bundled: false -extensions: - bruno: - ignore: - - node_modules - - .git diff --git a/doc/README.md b/doc/README.md index 912a2e56..4afdf585 100644 --- a/doc/README.md +++ b/doc/README.md @@ -15,9 +15,7 @@ La racine de l'architecture est [Architecture.md](Architecture.md). | [architecture/dictionnaires-metier.md](architecture/dictionnaires-metier.md) | Dictionnaires mĂ©tier, hĂ©ritage en arbre, cycle de vie d'un terme | | [architecture/offres-frontmatter.md](architecture/offres-frontmatter.md) | Offre fournisseur, ClasseFormulaire, ClasseDevis, parsing frontmatter | | [architecture/postit-oidc.md](architecture/postit-oidc.md) | Client desktop PostIt, custom URI scheme, silent refresh | -| [architecture/postit.md](architecture/postit.md) | PostIt — topologie des projets, ViewLocator custo, navigation, DI, conventions de binding | | [architecture/decoupage-organisation.md](architecture/decoupage-organisation.md) | DĂ©coupage des projets .NET (Abstract, Server, Org, Api, Blogs, Web, Org.Tests) | -| [testing.md](testing.md) | StratĂ©gie de test : conventions des dossiers, EF Core in-memory, auth stubs, scaffold partagĂ© | ## Roadmap & design exploration diff --git a/doc/architecture/decoupage-organisation.md b/doc/architecture/decoupage-organisation.md index 52e6ea97..9d4a0e4a 100644 --- a/doc/architecture/decoupage-organisation.md +++ b/doc/architecture/decoupage-organisation.md @@ -31,19 +31,7 @@ └────────────────┘ Clients externes : - - PostIt (Avalonia, code-base unique multi-cible) : - · PostIt — lib partagĂ©e (pages, VM, services) - · PostIt.Desktop — front-end Linux/Windows - · PostIt.Android — front-end APK - · PostIt.Browser — front-end WASM - Cf. postit.md et postit-oidc.md. - -Outils et tests : - - cli — outillage CLI - - Yavsc.Tests.Shared — helpers de tests partagĂ©s - - Yavsc.Org.Tests — tests du front web - - Yavsc.Blogs.Tests — tests du backend blogs - - PostIt.Tests — tests du client PostIt + - PostIt : client desktop Avalonia (cf. postit-oidc.md). ``` ## Par projet @@ -56,14 +44,6 @@ Outils et tests : | `Yavsc.Api` | ASP.NET Web | API REST JSON principale consommĂ©e par les clients externes (PostIt, 
). JwtBearer auth. | | `Yavsc.Blogs` | ASP.NET Web | **Backend API headless** dĂ©diĂ© aux blogs (uniquement `*ApiController` + services + modĂšles — aucune vue Razor). DestinĂ© Ă  ĂȘtre dĂ©ployĂ© sur un sous-domaine en production, sĂ©parĂ© du front web hĂ©bergĂ© par `Yavsc.Org`. | | `Yavsc.Org.Tests` | Test (xUnit) | Tests d'isolation du front web (`Yavsc.Org`) — fakes, controller tests. | -| `Yavsc.Blogs.Tests`| Test (xUnit) | Tests d'isolation du backend blogs (`Yavsc.Blogs`). | -| `Yavsc.Tests.Shared` | Library | Helpers de tests partagĂ©s (fixtures, fakes, builders) entre les projets de tests. | -| `PostIt` | Library | Code-base partagĂ©e du client PostIt (Avalonia) : pages, ViewModels, services, `ViewLocator` custo. Multi-cible — produit PostIt.Desktop / PostIt.Android / PostIt.Browser. | -| `PostIt.Desktop` | Avalonia.Desktop | Front-end Desktop Linux/Windows : `Program.Main`, `Platform.CreateBrowser` (CustomSchemeBrowser), custom URI scheme `postit://`. | -| `PostIt.Android` | Avalonia.Android | Front-end Android : `MainActivity` SingleTask, Chrome Custom Tabs, scheme `android://postit-signin`. | -| `PostIt.Browser` | Avalonia.Browser | Front-end WASM : pas de process distinct, IBrowser N/A. | -| `PostIt.Tests` | Test (xUnit) | Tests du client PostIt : settings, scopes Bearer, OIDC stub (`OidcStubAuthority`). | -| `cli` | exe / tool | Outillage CLI (build, packaging, gĂ©nĂ©ration de clĂ©s). | ## Pourquoi ce dĂ©coupage diff --git a/doc/architecture/postit-oidc.md b/doc/architecture/postit-oidc.md index ddedbfde..ee003b41 100644 --- a/doc/architecture/postit-oidc.md +++ b/doc/architecture/postit-oidc.md @@ -56,7 +56,6 @@ pas vers un serveur HTTP. |---------------------------------|-------------------------------------------------------------------| | `Services/OidcLoginPhase` | Enum des Ă©tapes du flow : `Idle / Discovering / OpeningBrowser / AwaitingCallback / ExchangingCode / Success / Error` | | `Services/YavscApiClient` | Client HTTP de l'API Yavsc. Porte `LoginInteractiveAsync(IProgress)` et `TrySilentLoginAsync`. Refresh silencieux sur 401 et sur access-token bientĂŽt expirĂ©. | -| `Services/BlogApiClient` | Mapper DTO↔path pour la sous-API blog. **Note** : `pathPrefix` est *relatif* Ă  `/api/v1/` (que porte dĂ©jĂ  `BaseAddress`) — ex. `"blog"` pour matcher `[Route(APIPrefix + "/blog")]`. Ne pas rĂ©-inclure `api/`. | | `Services/SingleInstance` | Named-pipe helper. `TryHandOffAsync` cĂŽtĂ© 2ᔉ instance, `StartServerAsync` cĂŽtĂ© instance vivante. | | `Services/CustomSchemeBrowser` | `IBrowser` OidcClient qui ouvre le systĂšme + attend le pipe. | | `Services/SchemeUrlDetector` | DĂ©tection pure, testable, du `postit://callback` dans argv. | diff --git a/doc/architecture/postit.md b/doc/architecture/postit.md deleted file mode 100644 index 70f3f2fd..00000000 --- a/doc/architecture/postit.md +++ /dev/null @@ -1,282 +0,0 @@ -# PostIt — Topologie, navigation, DI - -> **RĂ©capitulatif** : PostIt est le client Avalonia du projet -> Yavsc. C'est un code-base unique (`src/PostIt/PostIt/PostIt.csproj`) -> **multi-cible** vers trois front-ends distincts -> (`PostIt.Desktop`, `Postit.Android`, `PostIt.Browser`). Cette -> fiche couvre la topologie des projets, le DI, le `ViewLocator` -> custo et la navigation — c'est-Ă -dire tout ce que la fiche -> [postit-oidc.md](postit-oidc.md) ne dĂ©taille pas dĂ©jĂ  (l'OIDC, -> le flow d'auth, la persistance des tokens). DĂ©tail dans cette -> page, racine de l'architecture : [Architecture.md](../Architecture.md). - -## Surface : un code-base, trois front-ends - -``` - ┌────────────────────────┐ - │ PostIt (lib) │ - │ src/PostIt/PostIt/ │ - │ Pages, ViewModels, │ - │ Services, ViewLocator │ - │ (aucun rendu natif) │ - └──────┬───┬─────┬───────┘ - │ │ │ - ┌───────────────┘ │ └────────────────┐ - │ │ │ - ┌──────────▌────────┐ ┌────────▌─────────┐ ┌──────────▌────────┐ - │ PostIt.Desktop │ │ PostIt.Android │ │ PostIt.Browser │ - │ Avalonia.Desktop │ │ Avalonia.Android │ │ Avalonia.Browser │ - │ Linux/Windows │ │ APK │ │ WASM │ - │ + custom scheme │ │ + Chrome Custom │ │ (no native proc) │ - │ postit:// │ │ Tabs │ │ │ - │ + IBrowser custo │ │ + IBrowser custo │ │ │ - └───────────────────┘ └──────────────────┘ └───────────────────┘ -``` - -Le code partagĂ© vit dans `PostIt/`. Chaque front-end est un -**projet Satellite SDK** Avalonia qui ne contient que le -`Program.Main`, le `Platform.CreateBrowser`, et les manifestes -spĂ©cifiques (IntentFilter Android, `app.manifest` Desktop). -Toute la logique (VM, services, navigation, settings, OIDC) est -dans le code-base partagĂ©. - -## ViewLocator custo - -Le `ViewLocator` (cf. `src/PostIt/PostIt/ViewLocator.cs`) est un -`IDataTemplate` Avalonia **explicitement cĂąblĂ© sur le -`IServiceProvider`** : - -```csharp -public Control Build(object? data) => data switch -{ - MainPageViewModel => _services.GetRequiredService(), - Settings => _services.GetRequiredService(), - HomePageViewModel => _services.GetRequiredService(), - SignaturePageViewModel => _services.GetRequiredService(), - null => new TextBlock { Text = "No view for " }, - _ => new TextBlock { Text = $"No view for {data.GetType().Name}" } -}; -public bool Match(object? data) => data is ViewModelBase; -``` - -**Pourquoi un custo, et pas le `ViewLocatorBase` par dĂ©faut -d'Avalonia.Mvvm ?** Pour deux raisons : - -1. **Sortie du `Activator.CreateInstance`** — les pages - PostIt sont enregistrĂ©es dans le DI et peuvent avoir des - dĂ©pendances (par construction, aujourd'hui aucune, mais - l'extension future est ouverte). Le `ViewLocatorBase` - historique fait `new View()`, ce qui rend impossible - l'injection et complique les tests. -2. **Filtrage par `ViewModelBase`** — `Match` n'accepte que les - types dĂ©rivĂ©s de `ViewModelBase`. Toute tentative d'afficher - un objet mĂ©tier (par ex. un DTO de l'API Yavsc) tombe sur le - `TextBlock` "No view for X", pas sur un crash Avalonia. - -Le `ViewLocator` est ajoutĂ© aux `DataTemplates` de l'app dans -`App.OnFrameworkInitializationCompleted` : - -```csharp -DataTemplates.Clear(); -DataTemplates.Add(new ViewLocator(provider)); -``` - -**ConsĂ©quence pratique** : pour qu'une nouvelle page soit -affichĂ©e par un `ContentControl` qui binde un ViewModel, il -faut *deux* enregistrements : la page en `AddTransient` (ou -`AddSingleton`) dans le DI, **et** une case dans le `switch` -de `ViewLocator.Build`. Si l'un manque, l'app affiche -"No view for X" sans crash. - -## Composition root (`App.axaml.cs`) - -`App.OnFrameworkInitializationCompleted` est le seul endroit oĂč -le DI est construit. Ordre, dans cet ordre : - -1. `new Settings()` + `settings.Load()` — lit - `~/.config/PostIt/postit-settings.json` (ou le fallback - embarquĂ© dans `PostIt.dll`). -2. `new TokenStore(...)` + `new YavscApiClient(settings, tokenStore)`. -3. `new ServiceCollection()` + enregistrements en bloc. -4. `services.BuildServiceProvider()`. -5. `Settings.BindToServiceProvider(provider)` — pose le - singleton statique pour les helpers hors-DI - (`Settings.GetCurrent()`, `Settings.RequireCurrent()`). -6. `DataTemplates.Add(new ViewLocator(provider))`. -7. Branche `IClassicDesktopStyleApplicationLifetime` / - `ISingleViewApplicationLifetime` (Browser/Android). - -### Enregistrements DI - -| Service | Lifetime | Pourquoi | -|-------------------------------|------------|-------------------------------------------------------------------------------------------| -| `Settings` | **Singleton** | État partagĂ© (`Loaded`, `IsDirty`, `Authentication`) — doit ĂȘtre unique. | -| `YavscApiClient` | Singleton | Porte le `TokenStore` et le cache de tokens ; un seul par process. | -| `BlogApiClient` | Singleton | Mapper stateless, partagĂ©. | -| `SettingsPage` | **Singleton** | Une seule instance pour la vie de l'app : le `DataContext` est cĂąblĂ© une fois au boot, le push est idempotent (cf. section *Garde anti-empilement* ci-dessous). | -| `MainPage` / `HomePage` / `SignaturePage` | Transient | RĂ©solution Ă  la demande par le `ViewLocator`. | -| `MainPageViewModel` / `HomePageViewModel` / `SignaturePageViewModel` | Transient | VM reconstruites Ă  chaque navigation ; pas d'Ă©tat partagĂ© Ă  conserver. | -| `SessionStatusViewModel` + `SessionStatusBanner` | Singleton + Transient | Le VM est un singleton (survit Ă  la navigation), le bandeau est transient (rĂ©instanciĂ© quand la fenĂȘtre le recrĂ©e). | - -> **Invariant** : `Settings` est **uniquement** un singleton. Un -> `AddTransient()` supplĂ©mentaire (qui réécrase le -> singleton dans le container) ferait que chaque push de -> `SettingsPage` crĂ©e une instance vide, casse les bindings -> Authority/ClientId, et perd toute Ă©dition. Si tu dois toucher -> Ă  cette table, *ne pas* ajouter de registration pour -> `Settings` ailleurs que la ligne `AddSingleton(settings)`. - -## Navigation - -Le host de navigation est un `NavigationPage x:Name="NavRoot"` -posĂ© sur `MainWindow.axaml`. La pile est gĂ©rĂ©e par deux -mĂ©canismes distincts : - -1. **Nav utilisateur (VM-first)** : un ViewModel (souvent dans - une commande `[RelayCommand]`) appelle - `await ((App)App.Current!).PushPageAsync(targetVm).ConfigureAwait(true);`. - `App.PushPageAsync` (`src/PostIt/PostIt/App.axaml.cs`) - rĂ©sout la `Control` correspondante via le `ViewLocator` - enregistrĂ© dans `Application.DataTemplates`, l'identifie - comme `Page`, lui assigne le VM comme `DataContext`, et - appelle `NavRoot.PushAsync(page)`. C'est le seul chemin - pour les boutons de la toolbar, les `OpenSettings` / - `OpenCircles` / `ManageAcl` / `OpenSignatureDev`, et - toute autre nav dĂ©clenchĂ©e par un ViewModel. - -2. **Signaux de cycle de vie** : le `SessionStatusViewModel` - lĂšve des Ă©vĂ©nements consommĂ©s dans - `App.OnFrameworkInitializationCompleted` pour orchestrer - la nav de boot : - - | ÉvĂ©nement | Effet | - |---------------------|------------------------------------------------------------------| - | `LoginSucceeded` | `PushAsync(MainPage)` au-dessus de `HomePage` (post-login). | - | `LogoutCompleted` | `PopToRootAsync()` (revient Ă  `HomePage`). | - - Ces events ne sont **pas** un canal de nav utilisateur ; ils - portent une transition d'Ă©tat applicatif (authentification - Ă©tablie / perdue) et c'est `App` qui choisit d'en faire une - transition de pile. - -### Garde anti-empilement - -`NavigationPage.PushAsync` n'est pas idempotent : pousser deux -fois la mĂȘme instance l'empile deux fois, et l'utilisateur doit -taper **Retour** N fois pour sortir. La garde est implĂ©mentĂ©e -dans `App.PushPageAsync` (et consommĂ©e par tous les chemins -de nav utilisateur) : - -```csharp -var stack = window.NavRoot.NavigationStack; -if (stack.Count > 0 && ReferenceEquals(stack[stack.Count - 1], page)) -{ - return Task.CompletedTask; // dĂ©jĂ  au sommet, no-op silencieux -} -return window.NavRoot.PushAsync(page); -``` - -La comparaison est par rĂ©fĂ©rence, pas par type : on ne veut -empĂȘcher qu'un push de *cette* instance particuliĂšre, pas -celui d'une Ă©ventuelle autre `SettingsPage` (il n'en existe -qu'une, mais l'invariant est plus clair comme ça). La garde -repose sur le fait que `SettingsPage` est un singleton ; si on -repassait en `Transient`, `ReferenceEquals` resterait correct -mais la pertinence de la garde s'Ă©vaporerait (chaque push -apporterait une nouvelle instance et l'anti-empilement -reposerait sur l'invariant « la mĂȘme est dĂ©jĂ  au sommet », -qui ne tiendrait plus). - -## ViewModels et invariants d'Ă©tat - -- `Settings` est un objet-modĂšle exposĂ© comme `DataContext` - des pages. Il n'hĂ©rite pas de `ViewModelBase` (c'est un - POCO `[ObservableProperty]`-gĂ©nĂ©rĂ© par - `CommunityToolkit.Mvvm`). Le fait qu'il soit utilisĂ© comme - DataContext est un raccourci de composition acceptable ici, - pas un pattern Ă  gĂ©nĂ©raliser. - -- `SessionStatusViewModel` est le seul VM avec une durĂ©e de vie - **process-entiĂšre** (singleton). Il survit Ă  toutes les - navigations, expose `HasValidSession` en continu, et porte - les Ă©vĂ©nements de cycle de vie consommĂ©s par `App` pour - orchestrer la nav de boot (`LoginSucceeded`, - `LogoutCompleted`). La nav utilisateur dĂ©clenchĂ©e par - l'utilisateur passe par `App.PushPageAsync(vm)`, pas par - un Ă©vĂ©nement du `SessionStatusViewModel`. - -- `MainPageViewModel` / `HomePageViewModel` / - `SignaturePageViewModel` sont `Transient` — une nouvelle - instance est créée Ă  chaque push, l'ancienne est libĂ©rĂ©e - quand la page est dĂ©pilĂ©e. Pas d'Ă©tat partagĂ© entre - occurrences ; pour passer une donnĂ©e d'une page Ă  l'autre, - on passe par un singleton (souvent `YavscApiClient` ou - `Settings`). - -## Bindings XAML : conventions de nommage - -Pour les `[RelayCommand]` (cf. `CommunityToolkit.Mvvm`), le -binding XAML reprend **le nom exact de la mĂ©thode, sans -suffixe** : - -| MĂ©thode C# | Binding XAML | -|-----------------------|-----------------------------| -| `Save()` | `{Binding Save}` | -| `SaveAsync()` | `{Binding SaveAsync}` | -| `LoginCommand()` | `{Binding LoginCommand}` (nom littĂ©ral, *pas* de suffixe ajoutĂ©) | -| `Clear()` | `{Binding Clear}` | -| `CaptureAsync()` | `{Binding CaptureAsync}` | - -**JAMAIS** `SaveCommand`, `SaveCmd`, `DoSave`, etc. Le source -generator `[RelayCommand]` Ă©met une propriĂ©tĂ© `ICommand` du -mĂȘme nom que la mĂ©thode. Un binding qui pointe vers une -propriĂ©tĂ© inexistante casse l'app au moment du cĂąblage (le -bouton ne se cĂąble pas, et selon la version ça peut faire -planter l'init de la page). - -RĂ©fĂ©rence canonique : `AGENTS.md`, section -"Avalonia + CommunityToolkit.Mvvm : conventions de binding -pour `[RelayCommand]`". - -## Pages et leurs rĂŽles - -| Page | DataContext | RĂŽle | -|----------------------------|--------------------------|-----------------------------------------------------------------------| -| `MainWindow` | `HomePageViewModel` (initial) | Host de la `NavigationPage`. | -| `SessionStatusBanner` | `SessionStatusViewModel` | Bandeau persistant en haut de la fenĂȘtre, visible sur toutes les pages. Boutons Login / Logout / ParamĂštres. | -| `HomePage` | `HomePageViewModel` | Page d'accueil publique. | -| `MainPage` | `MainPageViewModel` | Éditeur de post de blog (aprĂšs login). | -| `SignaturePage` | `SignaturePageViewModel` | Capture de signature (estimateur). | -| `SettingsPage` | `Settings` | Édition de Authority / ClientId / Scopes / URLs API / Dark mode. Sauver via `Save` (RelayCommand). | - -## ConsĂ©quences pratiques - -- **Ajouter une page** : crĂ©er la View + le ViewModel + - enregistrer les deux dans le DI **et** dans le `switch` de - `ViewLocator.Build`. Oublier le `ViewLocator` est silencieux - (juste un TextBlock "No view for X"), pas une exception. -- **Ajouter un Ă©vĂ©nement global de navigation** (par ex. - "Push aprĂšs payment success") : ne pas capturer `MainWindow` - ni `NavigationPage` depuis le VM. La nav passe par - `App.PushPageAsync(vm)` dans tous les cas : soit le VM - appelle la mĂ©thode directement depuis une commande - (`[RelayCommand]`), soit un handler abonnĂ© Ă  un Ă©vĂ©nement - d'un singleton (cf. `SessionStatusViewModel`) l'appelle. - Garder les VMs dĂ©couplĂ©s du - `IClassicDesktopStyleApplicationLifetime`. -- **Modifier l'OIDC** : la fiche Ă  lire est - [postit-oidc.md](postit-oidc.md), pas celle-ci. Cette fiche - ne rĂ©-explique ni le flow, ni le pipe, ni le custom scheme. -- **Modifier les `Settings`** : ne pas casser le singleton - (cf. invariant ci-dessus). Toute propriĂ©tĂ© prĂ©sentationnelle - ajoutĂ©e (par ex. `ScopeListText`) doit porter `[JsonIgnore]` - pour ne pas polluer le format sur disque. - -## Voir aussi - -- [Architecture.md](../Architecture.md) — racine. -- [postit-oidc.md](postit-oidc.md) — flow OIDC, custom scheme, - silent refresh, persistance des tokens. -- [decoupage-organisation.md](decoupage-organisation.md) — - place de `PostIt` dans le dĂ©coupage global des projets - .NET du repo. diff --git a/doc/dev-tracking/client-editor-overhaul.md b/doc/dev-tracking/client-editor-overhaul.md new file mode 100644 index 00000000..0231e6aa --- /dev/null +++ b/doc/dev-tracking/client-editor-overhaul.md @@ -0,0 +1,278 @@ +# Client editor overhaul — Yavsc.Org administration + +## Goal + +Bring the OAuth2 client administration UI (`/Client/Edit/{id}` and friends) +in Yavsc.Org to feature parity with the IdentityServer8 `Client` entity +model. Today the editor only exposes a handful of scalar fields and a few +single-line inputs for collections; the bulk of the entity and its +related collections are unreachable from the UI. + +## Inventory — current state + +### Properties exposed by `Views/Client/Edit.cshtml` + +| Field | Type | Notes | +| ------------------------ | ----------- | ---------------------------------- | +| `ClientId` | string | hidden, identifier | +| `Enabled` | bool | checkbox | +| `ClientName` | string | display name | +| `FrontChannelLogoutUri` | string | only front-channel, no back-channel | +| `RedirectUris` | collection | rendered as a single text input | +| `IdentityTokenLifetime` | int | seconds | +| `AbsoluteRefreshTokenLifetime` | int | seconds | +| `ClientSecrets` | collection | rendered as a single text input | +| `AccessTokenType` | enum | dropdown (custom `SetAppTypesInputValues`) | + +### Properties of `IdentityServer8.EntityFramework.Entities.Client` **NOT** in the editor + +Core scalars (16 fields missing): + +- `Description` +- `ClientUri` +- `LogoUri` +- `RequireConsent` +- `RequirePkce` +- `RequireRequestObject` +- `RequireClientSecret` +- `AllowPlainTextPkce` +- `AllowOfflineAccess` +- `AllowRememberConsent` +- `AlwaysIncludeUserClaimsInIdToken` +- `AlwaysSendClientClaims` +- `AuthorizationCodeLifetime` +- `BackChannelLogoutUri` +- `BackChannelLogoutSessionRequired` +- `CibaLifetime` +- `ClientClaimsPrefix` +- `ConsentLifetime` +- `Created` +- `DeviceCodeLifetime` +- `EnableLocalLogin` +- `Enabled` +- `FrontChannelLogoutSessionRequired` +- `IncludeJwtId` +- `LastAccessed` +- `LogoUri` +- `NonEditable` +- `PairwiseSubjectSalt` +- `PollingInterval` +- `ProtocolType` +- `RefreshTokenExpiration` +- `RefreshTokenUsage` +- `SlidingRefreshTokenLifetime` +- `UpdateAccessTokenClaimsOnRefresh` +- `Updated` +- `UserCodeType` +- `UserSsoLifetime` + +Collections (8 missing — currently either not exposed at all, or jammed +into a single-line text input that doesn't work for an IEnumerable): + +- `AllowedGrantTypes` → `ClientGrantType` (GrantType) +- `AllowedScopes` → `ClientScope` (Scope) +- `RedirectUris` → `ClientRedirectUri` (RedirectUri) — exposed but broken +- `PostLogoutRedirectUris` → `ClientPostLogoutRedirectUri` (PostLogoutRedirectUri) +- `AllowedCorsOrigins` → `ClientCorsOrigin` (Origin) +- `IdentityProviderRestrictions` → `ClientIdPRestriction` (Provider) +- `Claims` → `ClientClaim` (Type, Value) +- `Properties` → `ClientProperty` (Key, Value) +- `ClientSecrets` → `ClientSecret` (Type, Value, Description, Created, Expiration) — exposed but broken +- `AllowedSigningAlgorithms` → scalar string collection on Client itself + +## Pages to add + +Pattern: one Razor page per collection under +`Views/Client/Edit{Collection}.cshtml`. Each page lists existing rows, +offers an "Add" form with the relevant fields, and a per-row +remove button. The main `Edit.cshtml` becomes a hub page with links +to each subpage plus the scalar fields it already has. + +| Page | Route | Form fields | +| ------------------------------------- | ------------------------------------------ | ------------------------------------------------- | +| `Edit.cshtml` | `GET /Client/Edit/{id}` (existing) | scalar fields + nav links | +| `EditRedirectUris.cshtml` | `GET /Client/EditRedirectUris/{id}` | `RedirectUri` | +| `EditPostLogoutRedirectUris.cshtml` | `GET /Client/EditPostLogoutRedirectUris/{id}` | `PostLogoutRedirectUri` | +| `EditScopes.cshtml` | `GET /Client/EditScopes/{id}` | `Scope` (with select of known scopes) | +| `EditGrantTypes.cshtml` | `GET /Client/EditGrantTypes/{id}` | `GrantType` (with select of known types) | +| `EditCorsOrigins.cshtml` | `GET /Client/EditCorsOrigins/{id}` | `Origin` | +| `EditIdPRestrictions.cshtml` | `GET /Client/EditIdPRestrictions/{id}` | `Provider` | +| `EditClaims.cshtml` | `GET /Client/EditClaims/{id}` | `Type`, `Value` | +| `EditProperties.cshtml` | `GET /Client/EditProperties/{id}` | `Key`, `Value` | +| `EditSecrets.cshtml` (replacement) | `GET /Client/EditSecrets/{id}` | `Type`, `Value`, `Description`, `Expiration` | + +Partial view `_EditableList.cshtml` factored once and consumed by all +of the above. + +## Controller actions to add + +For each collection `Foo`: + +- `GET EditFoo(int id)` — load the client, render the page +- `POST AddFoo(int id, 
)` — append a row, redirect to `EditFoo` +- `POST RemoveFoo(int id, int rowId)` — delete a row, redirect + +## Verification + +- `dotnet build src/Yavsc.Org/Yavsc.Org.csproj` → 0 errors +- No tests in `Yavsc.Org.Tests` exercise the controller today (per + `find 
 -name "ClientController*" -not -path "*/bin/*"`). Smoke-test + by logging in as admin, hitting `/Client/Edit/1`, then each + `Edit*/1` page, and verifying the add/remove POSTs. +- Existing seed flow (`MigratePostItClientToPublic` in + `HostingExtensions.cs`) must keep working — the editor changes are + additive, not destructive. + +## Out of scope + +- Tests (no MVC test infrastructure currently exists for this controller) +- Migration of existing collection fields (the broken `RedirectUris` + text input will simply be replaced by the new subpage) +- Per-collection authorization policies (the controller is already + `[Authorize("AdministratorOnly")]`) +- Client cloning / templating / JSON import-export + +## Status + +2026-06-21 16:04 — kickoff. Inventory done. Pages not yet started. + +2026-06-21 16:11 — first delivery, **build does not compile by design** +(per Paul: "Tu peux mĂȘme me laisser un travail qui ne compile +pas"). The structural work is done; the residual errors are easy +fixes Paul will do in a debug session. + +Files added (working tree, not yet committed): + +- `src/Yavsc.Org/Controllers/Administration/ClientController.Collections.cs` + — partial class with the per-collection GET / Add / Remove actions. +- `src/Yavsc.Org/Views/Client/EditRedirectUris.cshtml` +- `src/Yavsc.Org/Views/Client/EditPostLogoutRedirectUris.cshtml` +- `src/Yavsc.Org/Views/Client/EditScopes.cshtml` +- `src/Yavsc.Org/Views/Client/EditGrantTypes.cshtml` +- `src/Yavsc.Org/Views/Client/EditCorsOrigins.cshtml` +- `src/Yavsc.Org/Views/Client/EditIdPRestrictions.cshtml` +- `src/Yavsc.Org/Views/Client/EditClaims.cshtml` +- `src/Yavsc.Org/Views/Client/EditProperties.cshtml` +- `src/Yavsc.Org/Views/Client/EditSecrets.cshtml` +- `src/Yavsc.Org/Views/Client/_EditableStringList.cshtml` + — partial consumed by the single-string-field collection pages. + +Files modified: + +- `src/Yavsc.Org/Controllers/Administration/ClientController.cs` + — `class` → `partial class`; the `Edit(int id)` GET now uses + `LoadClientAsync` to load all navigations (so the new Edit.cshtml + can render counts in its nav links). +- `src/Yavsc.Org/Views/Client/Edit.cshtml` + — significantly enriched: nav links to the 9 sub-pages, all the + scalar fields split into fieldsets (Security, Logout, Tokens, + Device / CIBA, Tokens-extra), ClientId / Id hidden. + +### Known residual compile errors (4 errors total) + +Paul is fixing these in a debug session. The structure is sound; the +errors are missing properties on the `Client` entity, a Razor +nullable quirk, and a `Localizer` injection miss. + +1. `Edit.cshtml:249` — `PairwiseSubjectSalt` doesn't exist on + `IdentityServer8.EntityFramework.Entities.Client`. **Fix**: drop + the field from Edit.cshtml; IdentityServer8 likely uses a + different property name (e.g. on a related entity) or doesn't + expose it. +2. `Edit.cshtml:221` — `CibaLifetime` doesn't exist on `Client`. + **Fix**: same as above. CIBA flow may be configured elsewhere + (resource-level) or via a different property. +3. `ClientController.Collections.cs` lines 181, 217, 253, 304 — + `Localizer` is not available in the partial class. **Fix**: inject + `IStringLocalizer` via the constructor, or + inline the strings ("BothTypeAndValueRequired", "KeyRequired", + "ValueRequired", "SecretValueRequired"). +4. `EditSecrets.cshtml:44` — `s.Expiration?.ToString("u")` on a + `DateTime?`. **Fix**: just `s.Expiration?.ToString("u")` works + if you write `s.Expiration.Value.ToString("u")`, or use + `(s.Expiration is null ? "" : s.Expiration.Value.ToString("u"))`, + or `s.Expiration?.ToString("u") ?? string.Empty`. + +### Suggested next session + +Once the 4 compile errors are fixed and the pages render: + +1. Smoke test by logging in as admin, hitting `/Client/Edit/1`, + then each `Edit*/1` page, and verifying add/remove POSTs. +2. Add a confirmation prompt (or 2-step form) for Remove actions — + removing a Redirect URI is destructive and one click is too easy. +3. Wire up some collection-level validation (e.g. redirect URI must + be a valid URL) at the controller level. +4. Add tests — the project doesn't have MVC test infrastructure + today; consider adding a `Yavsc.Org.Tests` project that drives + the controller via `WebApplicationFactory`. + + +## Test bootstrap notes (session of 2026-06-21 17:00+) + +When adding new integration tests against `WebServerFixture`: + +1. **Skip `/Account/Login` roundtrip.** The fixture ships without + `MapRazorPages()` (commented out in `HostingExtensions.ConfigurePipeline`), + so `/Identity/Account/Login` is 404, and the custom + `/Account/Login` route requires a complex antiforgery dance. + Instead, build a `ClaimsPrincipal` for the test user via + `UserManager` + `IUserClaimsPrincipalFactory`, + then call `IAuthenticationService.SignInAsync` on a synthetic + `DefaultHttpContext` and replay the resulting `Set-Cookie` header + into the test `HttpClient`. See + `ClientControllerCollectionTests.IssueIdentityCookie`. + +2. **Create the `Administrator` role before assigning it.** ASP.NET + Identity stores roles in `AspNetRoles`; there is no automatic seed. + The constant name is `YavscConstants.AdminGroupName` = `"Administrator"`. + Use `RoleManager.CreateAsync(new IdentityRole("Administrator"))` + before `AddToRoleAsync`. + +3. **Use `InMemory` connection string to bypass the prod signing-cert + requirement.** `HostingExtensions.AddIdentityServer` requires a + PEM cert unless `builder.Environment.IsDevelopment()` OR + `UsesInMemoryProvider(connectionString)`. The fixture already + uses `InMemory`, so `AddDeveloperSigningCredential()` is called + automatically — but only after we wired this check in (see + commit history). + +4. **Field-name gotchas** (from disassembling HigginsSoft + IdentityServer8.EntityFramework.Entities.Client 8.0.5-preview-net9): + - `PairWiseSubjectSalt` (capital W on "Wise"), not `PairwiseSubjectSalt`. + - `CibaLifetime` and `PollingInterval` do NOT exist on `Client` in + this version. + - `ConsentLifetime` and `UserSsoLifetime` are `int?`. + +5. **`MapStaticAssets()` fails on test projects.** Calling + `MapStaticAssets()` resolves a manifest file + (`.staticwebassets.endpoints.json`) that test projects + don't produce. Skip when `WebRootPath` points at the test + assembly directory. + +6. **Routing 404 on /Client/Edit/{id} via WebServerFixture.** As of + this session, the GET endpoint returns 404 even with admin + header. The route mapping is intact + (`MapDefaultControllerRoute()`), so this is likely an MVC + convention routing issue with the + `Controllers/Administration/` subdirectory. To investigate + next session: log middleware pipeline or hit `/Client` index + first to see if any Client route resolves. + +7. **`MapStaticAssets()` is unconditional in prod, but blocks tests.** + `WebApplication.CreateBuilder` defaults `ContentRootPath` to + `AppContext.BaseDirectory`. In test runs that resolves to + `src/Yavsc.Org.Tests/bin/Debug/net10.0/`, where + `Yavsc.Org.Tests.staticwebassets.endpoints.json` doesn't exist + (it's generated only by projects with the Web SDK). The + `app.MapStaticAssets()` call inside `ConfigurePipeline` then + throws and the fixture fails to start — taking every test in + the `[Collection("Yavsc Server")]` down with it. + + This is a pre-existing fragility of the WebServerFixture that + the new test work surfaced. Fixing it cleanly requires either: + (a) moving the test project to the Web SDK so it produces its + own manifest, (b) copying the manifest at build time via an + MSBuild target, or (c) routing `MapStaticAssets` through an + assembly-resolution fallback. None attempted in this session — + recorded for next session. diff --git a/doc/testing.md b/doc/testing.md deleted file mode 100644 index ef80cda9..00000000 --- a/doc/testing.md +++ /dev/null @@ -1,88 +0,0 @@ -# StratĂ©gie de test - -Yavsc utilise **xUnit** (`xunit.v3`) avec un mix d'unitaire pur -et d'intĂ©gration lĂ©gĂšre. Les projets de tests sont sous -`src/.Tests/` et consomment le scaffold partagĂ© -`src/Yavsc.Tests.Shared/`. - -## Vue d'ensemble - -| Sujet | Document | -|---|---| -| Scaffold partagĂ© (`WebHostFixture`, JWT de test, etc.) | [src/Yavsc.Tests.Shared/README.md](../src/Yavsc.Tests.Shared/README.md) | -| Convention des dossiers de tests | [Conventions](#conventions-des-dossiers-de-tests) | -| Driver EF Core en test | [EF Core en test](#ef-core-en-test) | -| Stubs d'authentification et de permissions | [Auth et permissions](#auth-et-permissions) | - -## Conventions des dossiers de tests - -Sous `src/.Tests/`, on trouve quatre dossiers de premier -niveau qui classifient les tests par intention : - -| Dossier | Usage | -|---|---| -| `NonRegression/` | RĂ©gressions : un bug constatĂ©, un test qui le dĂ©tecte si on le rĂ©introduit | -| `Mandatory/` | Tests bloquants : ils doivent passer avant tout merge | -| `Smoke/` | Smoke tests HTTP rapides, montent un host lĂ©ger | -| `Controllers/` | Tests unitaires des contrĂŽleurs (mock du service, assertions sur le mapping HTTP) | - -Les `NonRegression` sont la cible par dĂ©faut quand on fixe un -bug : ils doivent ĂȘtre **rouges avant le fix, verts aprĂšs**, et -continuer Ă  **casser** si quelqu'un revert le fix. Pas de test -qui passe Ă  vide. - -## EF Core en test - -Pour les tests qui ont besoin d'un `ApplicationDbContext`, on -utilise **`UseInMemoryDatabase`** avec un `InMemoryDatabaseRoot` -partagĂ© au niveau de la fixture. Pas de SQLite, pas de Docker, -pas de mock du contexte : le service testĂ© s'exĂ©cute contre -un vrai `DbContext` sur in-memory. - -```csharp -private static readonly InMemoryDatabaseRoot _dbRoot = new(); - -var opts = new DbContextOptionsBuilder() - .UseInMemoryDatabase("Yavsc.Org.Tests.MyFixture", _dbRoot) - .Options; -``` - -Le `InMemoryDatabaseRoot` partagĂ© est important : sans lui, EF -crĂ©e un store indĂ©pendant par `DbContext` dans certaines -configurations, et un test qui seed + read sur deux contextes -voit un store vide. Le pattern est documentĂ© dans -`BlogsWebServerFixture` ([src/Yavsc.Blogs.Tests/BlogsWebServerFixture.cs](../src/Yavsc.Blogs.Tests/BlogsWebServerFixture.cs)). - -> **Limite connue** : le provider in-memory **ignore** les -> `Migration` EF et ne respecte pas les FK **sur les raw -> SQL** (`ExecuteSqlRaw`). Pour tester des contraintes FK, on -> Ă©crit la configuration dans `OnModelCreating` et on s'appuie -> sur le fait qu'EF la respecte Ă  l'`Add`/`SaveChanges`. Pour -> tester des migrations, c'est l'environnement de staging. - -## Auth et permissions - -L'authorization policy provider de prod est swappĂ© contre -`TestAuthPolicyProvider` (dans `Yavsc.Tests.Shared`) par les -fixtures spĂ©cialisĂ©es. Les tests qui ont besoin qu'un user soit -"Administrator" envoient un header `X-Test-RĂŽle` ; ceux qui -veulent un user anonyme omettent le header. - -Pour les tests unitaires qui n'ont pas besoin du pipeline -HTTP, on stub `IAuthorizationService` directement (cf. -`BlogspotController` dans `Yavsc.Org.Tests/NonRegression/`) -pour Ă©viter de monter un host complet. - -## Quand ne PAS Ă©crire de test - -Un test qui ne dĂ©tecte rien n'est pas un test. Si l'invariant -qu'on cherche Ă  protĂ©ger est dĂ©jĂ  enforced par EF, par le -compilateur, ou par une couche applicative en amont, le test -est du bruit. Mieux vaut : -- Un test qui assert un **comportement observable** (code - retour HTTP, exception typĂ©e, valeur de retour) -- Ou pas de test, et une note dans le code - -La non-rĂ©gression se prouve par un test qui casse si on -rĂ©introduit le bug. Pas par un test qui passe aujourd'hui et -qui continuera Ă  passer aprĂšs un revert. diff --git a/src/PostIt.Tests/Directory.Packages.props b/src/PostIt.Tests/Directory.Packages.props new file mode 100644 index 00000000..15c4e24b --- /dev/null +++ b/src/PostIt.Tests/Directory.Packages.props @@ -0,0 +1,10 @@ + + + + + + + + + + \ No newline at end of file diff --git a/src/PostIt/PostIt.Tests/FakeAuthorizingBrowser.cs b/src/PostIt.Tests/FakeAuthorizingBrowser.cs similarity index 96% rename from src/PostIt/PostIt.Tests/FakeAuthorizingBrowser.cs rename to src/PostIt.Tests/FakeAuthorizingBrowser.cs index 88dd5856..10311500 100644 --- a/src/PostIt/PostIt.Tests/FakeAuthorizingBrowser.cs +++ b/src/PostIt.Tests/FakeAuthorizingBrowser.cs @@ -1,3 +1,6 @@ +using System; +using System.Net.Http; +using System.Threading.Tasks; using IdentityModel.OidcClient.Browser; namespace PostIt.Tests; @@ -7,7 +10,7 @@ namespace PostIt.Tests; /// URL emitted by OidcClient, extracts its state, and returns a /// BrowserResult that mimics the OIDC redirect-with-code callback. /// -/// The paired 's token endpoint accepts +/// The paired 's token endpoint accepts /// any authorization code, so we don't need to mint a real one here. /// public sealed class FakeAuthorizingBrowser diff --git a/src/PostIt.Tests/LoginPageViewModelTests.cs b/src/PostIt.Tests/LoginPageViewModelTests.cs new file mode 100644 index 00000000..e469c011 --- /dev/null +++ b/src/PostIt.Tests/LoginPageViewModelTests.cs @@ -0,0 +1,257 @@ +using System; +using System.Threading.Tasks; +using PostIt.ViewModels; +using Xunit; + +namespace PostIt.Tests; + +public class LoginPageViewModelTests +{ + [Fact] + public async Task LoginAsync_acquires_access_token_from_stubbed_yavsc_authority() + { + // Arrange: spin up a stub OIDC authority and a fake browser that + // short-circuits the system browser. The authority signs its + // access_token with RS256; the fake browser captures the redirect + // URI so the authority can complete the token exchange. + using var authority = await OidcStubAuthority.StartAsync(); + var browser = new FakeAuthorizingBrowser(authority.LoopbackRedirectUri); + + var settings = new PostIt.Settings + { + Authentication = new AuthenticationSettings + { + Authority = authority.Issuer, + ClientId = "postit-tests" + }, + RedirectUri = authority.LoopbackRedirectUri, + Scopes = new[] { "openid", "profile", "blog" } + }; + + var vm = new LoginPageViewModel(settings, browser.CreateBrowser); + + // Act + await vm.LoginAsync(); + + // Assert: the ViewModel surfaced a token, not an error. + Assert.True( + !string.IsNullOrEmpty(vm.AccessToken), + $"Login did not produce a token. StatusMessage={vm.StatusMessage ?? ""}"); + Assert.False( + vm.StatusMessage?.StartsWith("Error") == true, + $"Login reported error: {vm.StatusMessage}"); + } + + [Fact] + public async Task LoginAsync_refuses_to_call_OidcClient_when_Authority_is_empty() + { + // Regression: when no user settings file exists and the embedded + // default somehow fails to load (e.g. resource stripped at publish + // time), the ViewModel must NOT hand a blank Authority to + // OidcClient — IdentityModel would build a bogus authorize URL + // like "http://127.0.0.1:1/" which the browser rejects with a + // confusing error. Surface a clear, actionable message instead. + // + // SettingsLoadOverride is set to a no-op so the test fixture's + // pre-loaded Settings object survives the call to LoginAsync. + var settings = new PostIt.Settings + { + Authentication = new AuthenticationSettings + { + Authority = "", + ClientId = "postit-tests", + }, + RedirectUri = "http://127.0.0.1:7890/", + Scopes = new[] { "openid" }, + }; + + var browserInvoked = false; + var vm = new LoginPageViewModel(settings, () => + { + browserInvoked = true; + return null; + }) + { + // Skip the disk / embedded read so the Authority stays empty. + SettingsLoadOverride = () => System.Threading.Tasks.Task.CompletedTask, + }; + + await vm.LoginAsync(); + + Assert.False( + browserInvoked, + "Browser factory was invoked even though Authority was empty."); + Assert.NotNull(vm.StatusMessage); + Assert.Contains("Configuration manquante", vm.StatusMessage); + Assert.Contains("postit-settings.json", vm.StatusMessage); + Assert.True(string.IsNullOrEmpty(vm.AccessToken)); + } + + [Fact] + public async Task LoginAsync_works_when_authority_has_trailing_slash() + { + // Regression: with Authority ending in "/" (the production + // postit-settings.json shape for https://yavsc.pschneider.fr/), + // the discovery URL OidcClient computes must NOT contain a + // double slash before /.well-known/openid-configuration. The + // stub advertises itself without the trailing slash; OidcClient + // must bridge. + using var authority = await OidcStubAuthority.StartAsync(); + var browser = new FakeAuthorizingBrowser(authority.LoopbackRedirectUri); + + var settings = new PostIt.Settings + { + Authentication = new AuthenticationSettings + { + Authority = authority.Issuer + "/", + ClientId = "postit-tests" + }, + RedirectUri = authority.LoopbackRedirectUri, + Scopes = new[] { "openid" } + }; + + var vm = new LoginPageViewModel(settings, browser.CreateBrowser); + + await vm.LoginAsync(); + + Assert.True( + !string.IsNullOrEmpty(vm.AccessToken), + $"Login with trailing slash failed. StatusMessage={vm.StatusMessage ?? ""}"); + } + + [Fact] + public void RegisterUrl_and_ForgotPasswordUrl_are_derived_from_authority() + { + var settings = new PostIt.Settings + { + Authentication = new AuthenticationSettings + { + Authority = "https://yavsc.example.com/", + ClientId = "postit-tests" + }, + RedirectUri = "http://127.0.0.1:7890/", + Scopes = new[] { "openid" } + }; + + var vm = new LoginPageViewModel(settings); + + // Trailing slash on Authority is normalised away. + Assert.Equal( + "https://yavsc.example.com/Account/Register", + vm.RegisterUrl); + Assert.Equal( + "https://yavsc.example.com/Account/ForgotPassword", + vm.ForgotPasswordUrl); + Assert.True(vm.HasRegisterUrl); + Assert.True(vm.HasForgotPasswordUrl); + } + + [Fact] + public void RegisterUrl_is_empty_when_authority_is_unset() + { + var vm = new LoginPageViewModel(new PostIt.Settings()); + Assert.Equal(string.Empty, vm.RegisterUrl); + Assert.Equal(string.Empty, vm.ForgotPasswordUrl); + Assert.False(vm.HasRegisterUrl); + Assert.False(vm.HasForgotPasswordUrl); + } + + [Fact] + public void ConfigMissing_is_true_when_authority_is_unset() + { + var vm = new LoginPageViewModel(new PostIt.Settings()); + Assert.True(vm.ConfigMissing); + Assert.Contains("~/.config/PostIt/postit-settings.json", vm.ConfigMissingMessage); + } + + [Fact] + public void ConfigMissing_is_false_when_authority_is_set() + { + var settings = new PostIt.Settings + { + Authentication = new AuthenticationSettings + { + Authority = "https://yavsc.example.com/", + ClientId = "postit-tests" + } + }; + var vm = new LoginPageViewModel(settings); + Assert.False(vm.ConfigMissing); + } + + [Theory] + [InlineData("https://yavsc.example.com/", "https://yavsc.example.com/.well-known/openid-configuration")] + [InlineData("https://yavsc.example.com", "https://yavsc.example.com/.well-known/openid-configuration")] + [InlineData("https://yavsc.example.com/sub/", "https://yavsc.example.com/sub/.well-known/openid-configuration")] + public void DiscoveryUrl_is_externalurl_plus_well_known(string authority, string expected) + { + var settings = new PostIt.Settings + { + Authentication = new AuthenticationSettings { Authority = authority } + }; + var vm = new LoginPageViewModel(settings); + Assert.Equal(expected, vm.DiscoveryUrl); + // ExternalUrl is the slash-normalised form of Authority. + Assert.Equal(expected[..expected.LastIndexOf("/.well-known/openid-configuration")], vm.ExternalUrl); + } + + [Fact] + public void DiscoveryUrl_is_empty_when_authority_is_unset() + { + var vm = new LoginPageViewModel(new PostIt.Settings()); + Assert.Equal(string.Empty, vm.DiscoveryUrl); + } + + [Fact] + public async Task LoginAsync_failure_message_includes_discovery_url() + { + // Arrange: settings point at an unreachable authority; the test + // browser throws synchronously to guarantee the catch branch runs. + var settings = new PostIt.Settings + { + Authentication = new AuthenticationSettings + { + Authority = "https://does-not-exist.invalid/", + ClientId = "postit-tests" + }, + RedirectUri = "http://127.0.0.1:7890/", + Scopes = new[] { "openid" } + }; + + var vm = new LoginPageViewModel(settings, () => throw new InvalidOperationException("boom")); + + // Act + await vm.LoginAsync(); + + // Assert: the surfaced error mentions the canonical discovery URL, + // so it can be copy-pasted into a browser to diagnose reachability. + Assert.NotNull(vm.StatusMessage); + Assert.StartsWith("Error:", vm.StatusMessage); + Assert.Contains( + "https://does-not-exist.invalid/.well-known/openid-configuration", + vm.StatusMessage); + } + + [Fact] + public async Task LoginAsync_reports_discovery_url_when_no_browser_available() + { + var settings = new PostIt.Settings + { + Authentication = new AuthenticationSettings + { + Authority = "https://yavsc.example.com/", + ClientId = "postit-tests" + }, + RedirectUri = "http://127.0.0.1:7890/", + Scopes = new[] { "openid" } + }; + + var vm = new LoginPageViewModel(settings, () => null); + + await vm.LoginAsync(); + + Assert.Contains( + "https://yavsc.example.com/.well-known/openid-configuration", + vm.StatusMessage); + } +} \ No newline at end of file diff --git a/src/PostIt/PostIt.Tests/OidcStubAuthority.cs b/src/PostIt.Tests/OidcStubAuthority.cs similarity index 95% rename from src/PostIt/PostIt.Tests/OidcStubAuthority.cs rename to src/PostIt.Tests/OidcStubAuthority.cs index 4bb25097..552db6b0 100644 --- a/src/PostIt/PostIt.Tests/OidcStubAuthority.cs +++ b/src/PostIt.Tests/OidcStubAuthority.cs @@ -1,8 +1,13 @@ +using System; +using System.Collections.Generic; +using System.IO; using System.Net; using System.Net.Sockets; using System.Security.Cryptography; using System.Text; using System.Text.Json; +using System.Threading; +using System.Threading.Tasks; namespace PostIt.Tests; @@ -15,7 +20,7 @@ namespace PostIt.Tests; /// the browser intercepts the authorize redirect, the server completes /// the token exchange. /// -public sealed class OIDCStubAuthority : IAsyncDisposable, IDisposable +public sealed class OidcStubAuthority : IAsyncDisposable, IDisposable { private readonly HttpListener _listener; private readonly RSA _rsa; @@ -25,7 +30,7 @@ public sealed class OIDCStubAuthority : IAsyncDisposable, IDisposable public string Issuer { get; } public string LoopbackRedirectUri { get; } - private OIDCStubAuthority(HttpListener listener, RSA rsa, string kid, string issuer, string loopback) + private OidcStubAuthority(HttpListener listener, RSA rsa, string kid, string issuer, string loopback) { _listener = listener; _rsa = rsa; @@ -34,7 +39,7 @@ public sealed class OIDCStubAuthority : IAsyncDisposable, IDisposable LoopbackRedirectUri = loopback; } - public static async Task StartAsync() + public static async Task StartAsync() { // Pick a free loopback port. var port = GetFreePort(); @@ -48,7 +53,7 @@ public sealed class OIDCStubAuthority : IAsyncDisposable, IDisposable var rsa = RSA.Create(2048); var kid = "test-key-1"; - var authority = new OIDCStubAuthority(listener, rsa, kid, prefix.TrimEnd('/'), loopback); + var authority = new OidcStubAuthority(listener, rsa, kid, prefix.TrimEnd('/'), loopback); _ = Task.Run(() => authority.AcceptLoopAsync(authority._cts.Token)); return authority; } diff --git a/src/PostIt/PostIt.Tests/PostIt.Tests.csproj b/src/PostIt.Tests/PostIt.Tests.csproj similarity index 67% rename from src/PostIt/PostIt.Tests/PostIt.Tests.csproj rename to src/PostIt.Tests/PostIt.Tests.csproj index 86a7998a..10d5e16e 100644 --- a/src/PostIt/PostIt.Tests/PostIt.Tests.csproj +++ b/src/PostIt.Tests/PostIt.Tests.csproj @@ -6,14 +6,9 @@ false PostIt.Tests true - 1.1.0.0 - 1.1.0.0 - 1.1.0-beta.1+148.Branch.release-1.0.8-rc4.Sha.6b161b0fb509fec0ce467aa94f1a450b202af2f0 - 1.1.0-beta.1 - @@ -21,10 +16,9 @@ - + - \ No newline at end of file diff --git a/src/PostIt/PostIt.Tests/PostItViewModelTests.cs b/src/PostIt.Tests/PostItViewModelTests.cs similarity index 74% rename from src/PostIt/PostIt.Tests/PostItViewModelTests.cs rename to src/PostIt.Tests/PostItViewModelTests.cs index d2c5d78e..65c0c667 100644 --- a/src/PostIt/PostIt.Tests/PostItViewModelTests.cs +++ b/src/PostIt.Tests/PostItViewModelTests.cs @@ -1,13 +1,21 @@ -using Yavsc.Blogspot; -using Yavsc.Api.Client; +using System.Collections.Generic; +using System.Linq; +using System.Net; +using System.Net.Http; +using System.Net.Http.Json; +using System.Text; +using System.Text.Json; +using System.Threading; +using System.Threading.Tasks; +using PostIt.Models; using PostIt.Services; using PostIt.ViewModels; +using Xunit; -namespace PostIt.Tests; +namespace PostIt; public class PostItViewModelTests { - [Fact] public void SearchCommand_filters_posts_by_title_article_or_author() { @@ -15,12 +23,12 @@ public class PostItViewModelTests // default; tests construct one with a fake YavscApiClient that // throws on any call (we never call the API in this test). var fakeApi = new ThrowingYavscApiClient(); - var blog = new BlogApiClient(fakeApi, "http://localhost/"); - var viewModel = new MainViewModel(blog); + var blog = new BlogApiClient(fakeApi); + var viewModel = new MainPageViewModel(blog); - viewModel.Posts.Add(new BlogPostDto { Id = 1, Title = "First post", Article = "Hello world", AuthorId = "alice" }); - viewModel.Posts.Add(new BlogPostDto { Id = 2, Title = "Second post", Article = "Nothing here", AuthorId = "bob" }); - viewModel.Posts.Add(new BlogPostDto { Id = 3, Title = "Third post", Article = "Search me", AuthorId = "carol" }); + viewModel.Posts.Add(new BlogPost { Id = 1, Title = "First post", Article = "Hello world", AuthorId = "alice" }); + viewModel.Posts.Add(new BlogPost { Id = 2, Title = "Second post", Article = "Nothing here", AuthorId = "bob" }); + viewModel.Posts.Add(new BlogPost { Id = 3, Title = "Third post", Article = "Search me", AuthorId = "carol" }); viewModel.SearchText = "search"; viewModel.SearchCommand.Execute(null); @@ -41,15 +49,15 @@ public class PostItViewModelTests // The new BlogApiClient delegates transport to YavscApiClient. // We feed it a fake YavscApiClient that returns the expected // list straight from CallAsync. - var expected = new List + var expected = new List { new() { Id = 1, Title = "Hello" }, new() { Id = 2, Title = "World" } }; var api = new StubYavscApiClient(expected); - var blog = new BlogApiClient(api, "http://localhost/"); + var blog = new BlogApiClient(api); - var posts = await blog.GetPostsAsync(ct: TestContext.Current.CancellationToken); + var posts = await blog.GetPostsAsync(); Assert.Equal(2, posts.Count); Assert.Equal("Hello", posts[0].Title); @@ -61,11 +69,11 @@ public class PostItViewModelTests public ThrowingYavscApiClient() : base( new Settings { + Scopes = new[] { "openid" }, Authentication = new AuthenticationSettings { Authority = "https://stub.invalid", ClientId = "stub", - Scopes = new[] { "openid" }, }, }, new TokenStore(System.IO.Path.GetTempFileName())) @@ -77,16 +85,16 @@ public class PostItViewModelTests /// Test fake that hands back a canned list of posts from any CallAsync. private sealed class StubYavscApiClient : YavscApiClient { - private readonly List _posts; - public StubYavscApiClient(List posts) + private readonly List _posts; + public StubYavscApiClient(List posts) : base( new Settings { + Scopes = new[] { "openid" }, Authentication = new AuthenticationSettings { Authority = "https://stub.invalid", ClientId = "stub", - Scopes = new[] { "openid" }, }, }, new TokenStore(System.IO.Path.GetTempFileName())) @@ -98,7 +106,7 @@ public class PostItViewModelTests { // The canned fake only knows about a list of posts; the // BlogApiClient test asserts on that list directly. - if (typeof(T) == typeof(List)) + if (typeof(T) == typeof(List)) return Task.FromResult((T)(object)_posts); return Task.FromResult(default(T)!); } diff --git a/src/PostIt/PostIt.Tests/SchemeUrlDetectorTests.cs b/src/PostIt.Tests/SchemeUrlDetectorTests.cs similarity index 99% rename from src/PostIt/PostIt.Tests/SchemeUrlDetectorTests.cs rename to src/PostIt.Tests/SchemeUrlDetectorTests.cs index 78b67463..f5983cb3 100644 --- a/src/PostIt/PostIt.Tests/SchemeUrlDetectorTests.cs +++ b/src/PostIt.Tests/SchemeUrlDetectorTests.cs @@ -1,4 +1,5 @@ using PostIt.Services; +using Xunit; namespace PostIt.Tests; diff --git a/src/PostIt.Tests/SettingsLoadTests.cs b/src/PostIt.Tests/SettingsLoadTests.cs new file mode 100644 index 00000000..eb05af38 --- /dev/null +++ b/src/PostIt.Tests/SettingsLoadTests.cs @@ -0,0 +1,35 @@ +using System; +using System.IO; +using Xunit; + +namespace PostIt.Tests; + +public class SettingsLoadTests +{ + /// + /// On the dev machine, the user-level settings file + /// (~/.config/PostIt/postit-settings.json) does not exist, so Load() + /// must fall back to the embedded default resource shipped inside + /// PostIt.dll. + /// + [Fact] + public void Load_falls_back_to_embedded_resource_when_user_file_missing() + { + // Skip if a user-level file exists (CI / different dev machines). + var userConfigPath = Path.Combine( + Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), + "PostIt", + "postit-settings.json"); + if (File.Exists(userConfigPath)) + { + return; // nothing to assert: user file wins. + } + + var settings = new PostIt.Settings(); + settings.Load(); + + // The bundled postit-settings.json points at yavsc.pschneider.fr. + Assert.False(string.IsNullOrWhiteSpace(settings.Authentication?.Authority)); + Assert.Equal("postit", settings.Authentication.ClientId); + } +} \ No newline at end of file diff --git a/src/PostIt/PostIt.Tests/TestApp.cs b/src/PostIt.Tests/TestApp.cs similarity index 100% rename from src/PostIt/PostIt.Tests/TestApp.cs rename to src/PostIt.Tests/TestApp.cs diff --git a/src/PostIt/PostIt.Tests/UnitTest1.cs b/src/PostIt.Tests/UnitTest1.cs similarity index 70% rename from src/PostIt/PostIt.Tests/UnitTest1.cs rename to src/PostIt.Tests/UnitTest1.cs index bc0d864c..96990865 100644 --- a/src/PostIt/PostIt.Tests/UnitTest1.cs +++ b/src/PostIt.Tests/UnitTest1.cs @@ -1,4 +1,5 @@ ï»żusing Avalonia.Headless.XUnit; +using Avalonia.Controls; using PostIt.Views; namespace PostIt.Tests; @@ -8,7 +9,8 @@ public class MainPageTests [AvaloniaFact] public void MainPage_Should_Load() { - var window = new MainView(); + var window = new MainWindow(); + window.Show(); Assert.NotNull(window); } -} +} \ No newline at end of file diff --git a/src/PostIt/PostIt.Tests/YavscApiClientTests.cs b/src/PostIt.Tests/YavscApiClientTests.cs similarity index 83% rename from src/PostIt/PostIt.Tests/YavscApiClientTests.cs rename to src/PostIt.Tests/YavscApiClientTests.cs index 21c0dd00..1617c1b6 100644 --- a/src/PostIt/PostIt.Tests/YavscApiClientTests.cs +++ b/src/PostIt.Tests/YavscApiClientTests.cs @@ -1,10 +1,18 @@ +using System; +using System.Collections.Generic; +using System.IO; +using System.Linq; using System.Net; +using System.Net.Http; using System.Net.Sockets; using System.Text; using System.Text.Json; -using PostIt.Services; +using System.Threading; +using System.Threading.Tasks; +using IdentityModel.OidcClient; using IdentityModel.OidcClient.Browser; -using PostIt.ViewModels; +using PostIt.Services; +using Xunit; namespace PostIt.Tests; @@ -12,7 +20,7 @@ namespace PostIt.Tests; /// End-to-end coverage of : silent /// refresh on a near-expiry access token, 401-driven refresh + retry, /// and persistence of the token bundle via . -/// Uses the project's for the IdP and +/// Uses the project's for the IdP and /// a tiny in-process HTTP listener for the API server side. /// public class YavscApiClientTests @@ -37,7 +45,7 @@ public class YavscApiClientTests // in-memory access token as expired and re-run a call. The // refresh path must rotate the refresh token transparently // and the API call must succeed with the new token. - using var authority = await OIDCStubAuthority.StartAsync(); + using var authority = await OidcStubAuthority.StartAsync(); using var apiServer = new StubApiServer(); await apiServer.StartAsync(); @@ -53,15 +61,9 @@ public class YavscApiClientTests // Reload — YavscApiClient constructor reads the store. var reloaded = new YavscApiClient(settings, new TokenStore(tokensPath)); - // Same BaseAddress dance as LoginAndPersistAsync: a fresh - // YavscApiClient starts with no BaseAddress, and the test - // calls CallAsync("posts", ...) directly (bypassing - // BlogApiClient, which is the only thing that would set - // it in production). Mirror prod here. - reloaded.Http.BaseAddress = new Uri(settings.BusinessApiUrl); var posts = await reloaded.CallAsync>( - HttpMethod.Get, "posts", TestContext.Current.CancellationToken); + HttpMethod.Get, "posts"); Assert.NotNull(posts); Assert.NotEmpty(posts); @@ -83,7 +85,7 @@ public class YavscApiClientTests { // API server returns 401 on the first request, 200 on the next. // YavscApiClient must refresh, then retry exactly once. - using var authority = await OIDCStubAuthority.StartAsync(); + using var authority = await OidcStubAuthority.StartAsync(); using var apiServer = new StubApiServer(forceFirstRequest: true); await apiServer.StartAsync(); @@ -95,7 +97,7 @@ public class YavscApiClientTests settings, authority, tokensPath); var posts = await client.CallAsync>( - HttpMethod.Get, "posts", TestContext.Current.CancellationToken); + HttpMethod.Get, "posts"); Assert.NotEmpty(posts); Assert.Equal(2, apiServer.RequestCount); @@ -109,29 +111,28 @@ public class YavscApiClientTests [Fact] public async Task CallAsync_throws_when_no_token_and_no_interactive_login() { - var settings = new Settings + var settings = new PostIt.Settings { Authentication = new AuthenticationSettings { Authority = "https://127.0.0.1:5001", ClientId = "postit-tests", - RedirectUri = "postit://callback", - Scopes = new[] { "openid" }, }, - BusinessApiUrl = "https://127.0.0.1:5003/api/v1", + RedirectUri = "postit://callback", + Scopes = new[] { "openid" }, + ApiUrl = "https://127.0.0.1:5003/api/v1", }; var client = new YavscApiClient(settings, new TokenStore(Path.Combine( Path.GetTempPath(), $"postit-tests-noop-{Guid.NewGuid():N}.json"))); - await Assert.ThrowsAsync( - () => - client.CallAsync(HttpMethod.Get, "posts", TestContext.Current.CancellationToken)); + await Assert.ThrowsAsync(() => + client.CallAsync(HttpMethod.Get, "posts")); } [Fact] public async Task HasValidSession_is_true_after_login() { - using var authority = await OIDCStubAuthority.StartAsync(); + using var authority = await OidcStubAuthority.StartAsync(); using var apiServer = new StubApiServer(); await apiServer.StartAsync(); @@ -153,30 +154,24 @@ public class YavscApiClientTests // --- helpers -------------------------------------------------------- - private static Settings BuildSettings(OIDCStubAuthority authority, string apiBaseUrl) => new() + private static PostIt.Settings BuildSettings(OidcStubAuthority authority, string apiBaseUrl) => new() { Authentication = new AuthenticationSettings { Authority = authority.Issuer, ClientId = "postit-tests", - RedirectUri = authority.LoopbackRedirectUri, - Scopes = new[] { "openid", "profile", "blog" } }, - BusinessApiUrl = apiBaseUrl + RedirectUri = authority.LoopbackRedirectUri, + Scopes = new[] { "openid", "profile", "blog" }, + ApiUrl = apiBaseUrl, }; private static async Task LoginAndPersistAsync( - Settings settings, OIDCStubAuthority authority, string tokensPath) + PostIt.Settings settings, OidcStubAuthority authority, string tokensPath) { var browser = new FakeAuthorizingBrowser(authority.LoopbackRedirectUri); var client = new YavscApiClient(settings, new TokenStore(tokensPath)); - // The two integration tests that call CallAsync("posts", ...) - // directly (bypassing BlogApiClient) rely on the same - // BaseAddress the production chain sets in BlogApiClient's - // ctor. Mirror that here so "posts" resolves to the stub. - client.Http.BaseAddress = new Uri(settings.BusinessApiUrl); - // Force the API client to use the test browser by routing the // LoginInteractiveAsync call through a small wrapper. await LoginWithBrowserAsync(client, browser.CreateBrowser()); @@ -186,7 +181,7 @@ public class YavscApiClientTests /// /// YavscApiClient.LoginInteractiveAsync delegates to /// Platform.CreateBrowser. We can't override that static cleanly - /// from XUnit.v3, so we rebuild the call by re-routing the + /// from xunit.v3, so we rebuild the call by re-routing the /// Platform.CreateBrowser delegate for the duration of the call. /// private static async Task LoginWithBrowserAsync( @@ -219,7 +214,7 @@ public class YavscApiClientTests File.WriteAllText(tokensPath, JsonSerializer.Serialize(record)); } - // --- OIDCLoginPhase progress tests --------------------------------- + // --- OidcLoginPhase progress tests --------------------------------- /// /// Collecting Progress is documented to capture reports @@ -230,7 +225,7 @@ public class YavscApiClientTests [Fact] public async Task LoginInteractiveAsync_reports_Discovering_then_Success() { - using var authority = await OIDCStubAuthority.StartAsync(); + using var authority = await OidcStubAuthority.StartAsync(); using var apiServer = new StubApiServer(); await apiServer.StartAsync(); @@ -239,18 +234,18 @@ public class YavscApiClientTests var client = new YavscApiClient(settings, new TokenStore(tokensPath)); var browser = new FakeAuthorizingBrowser(authority.LoopbackRedirectUri); - var reported = new System.Collections.Generic.List(); - var progress = new SyncProgress(reported); + var reported = new System.Collections.Generic.List(); + var progress = new SyncProgress(reported); try { await LoginWithBrowserAsync(client, browser.CreateBrowser(), progress); // SyncProgress captures reports synchronously — no flush needed. - Assert.Contains(OIDCLoginPhase.Discovering, reported); - Assert.Contains(OIDCLoginPhase.OpeningBrowser, reported); - Assert.Contains(OIDCLoginPhase.ExchangingCode, reported); - Assert.Equal(OIDCLoginPhase.Success, Last(reported)); + Assert.Contains(OidcLoginPhase.Discovering, reported); + Assert.Contains(OidcLoginPhase.OpeningBrowser, reported); + Assert.Contains(OidcLoginPhase.ExchangingCode, reported); + Assert.Equal(OidcLoginPhase.Success, Last(reported)); } finally { @@ -261,24 +256,24 @@ public class YavscApiClientTests [Fact] public async Task LoginInteractiveAsync_reports_Error_when_browser_missing() { - using var authority = await OIDCStubAuthority.StartAsync(); + using var authority = await OidcStubAuthority.StartAsync(); using var apiServer = new StubApiServer(); await apiServer.StartAsync(); var settings = BuildSettings(authority, apiServer.BaseUrl); var client = new YavscApiClient(settings, new TokenStore(TokensPath())); - var reported = new System.Collections.Generic.List(); - var progress = new SyncProgress(reported); + var reported = new System.Collections.Generic.List(); + var progress = new SyncProgress(reported); var original = Platform.CreateBrowser; try { Platform.CreateBrowser = () => null; // simulate no browser wired up await Assert.ThrowsAsync( - () => client.LoginInteractiveAsync(progress, TestContext.Current.CancellationToken)); + () => client.LoginInteractiveAsync(progress)); // SyncProgress captures reports synchronously — no flush needed. - Assert.Equal(OIDCLoginPhase.Error, Last(reported)); + Assert.Equal(OidcLoginPhase.Error, Last(reported)); } finally { @@ -289,7 +284,7 @@ public class YavscApiClientTests [Fact] public async Task TrySilentLoginAsync_returns_false_when_no_bundle_on_disk() { - using var authority = await OIDCStubAuthority.StartAsync(); + using var authority = await OidcStubAuthority.StartAsync(); using var apiServer = new StubApiServer(); await apiServer.StartAsync(); @@ -298,7 +293,7 @@ public class YavscApiClientTests // Tokens file deliberately doesn't exist. var client = new YavscApiClient(settings, new TokenStore(tokensPath)); - var ok = await client.TrySilentLoginAsync(null, TestContext.Current.CancellationToken); + var ok = await client.TrySilentLoginAsync(); Assert.False(ok); Assert.False(client.HasValidSession); } @@ -306,7 +301,7 @@ public class YavscApiClientTests [Fact] public async Task TrySilentLoginAsync_returns_true_when_access_token_still_valid() { - using var authority = await OIDCStubAuthority.StartAsync(); + using var authority = await OidcStubAuthority.StartAsync(); using var apiServer = new StubApiServer(); await apiServer.StartAsync(); @@ -319,7 +314,7 @@ public class YavscApiClientTests { await LoginWithBrowserAsync(client, browser.CreateBrowser()); // Login fresh → access token is far from expiry. - var ok = await client.TrySilentLoginAsync(null, TestContext.Current.CancellationToken); + var ok = await client.TrySilentLoginAsync(); Assert.True(ok); Assert.True(client.HasValidSession); } @@ -332,7 +327,7 @@ public class YavscApiClientTests [Fact] public async Task TrySilentLoginAsync_returns_true_when_refresh_succeeds() { - using var authority = await OIDCStubAuthority.StartAsync(); + using var authority = await OidcStubAuthority.StartAsync(); using var apiServer = new StubApiServer(); await apiServer.StartAsync(); @@ -356,13 +351,13 @@ public class YavscApiClientTests // matches the disk: access expired, refresh still good. var client = new YavscApiClient(settings, store); - var reported = new System.Collections.Generic.List(); - var progress = new SyncProgress(reported); + var reported = new System.Collections.Generic.List(); + var progress = new SyncProgress(reported); - var ok = await client.TrySilentLoginAsync(progress, TestContext.Current.CancellationToken); + var ok = await client.TrySilentLoginAsync(progress); Assert.True(ok, "silent refresh should succeed via the stub authority."); - Assert.Contains(OIDCLoginPhase.ExchangingCode, reported); - Assert.Equal(OIDCLoginPhase.Success, Last(reported)); + Assert.Contains(OidcLoginPhase.ExchangingCode, reported); + Assert.Equal(OidcLoginPhase.Success, Last(reported)); } finally { @@ -435,7 +430,7 @@ public class YavscApiClientTests /// overload stays for tests that don't care about phase events. /// private static async Task LoginWithBrowserAsync( - YavscApiClient client, IBrowser browser, IProgress? progress = null) + YavscApiClient client, IBrowser browser, IProgress? progress = null) { var original = Platform.CreateBrowser; try diff --git a/src/PostIt/Directory.Packages.props b/src/PostIt/Directory.Packages.props index 0d5fa50c..12ed35df 100644 --- a/src/PostIt/Directory.Packages.props +++ b/src/PostIt/Directory.Packages.props @@ -1,39 +1,19 @@ - + + - - - true - 12.1.1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - + + + + + + + + + + + + + + + \ No newline at end of file diff --git a/src/PostIt/Makefile b/src/PostIt/Makefile deleted file mode 100644 index 1217976b..00000000 --- a/src/PostIt/Makefile +++ /dev/null @@ -1,178 +0,0 @@ - -# Cibles pour installer PostIt.Android en Debug sur l'AVD qemu. -# -# Usage typique : -# make qemu # lance l'AVD, attend le boot, build l'APK, l'installe -# make android-install # (re)build l'APK et l'installe (AVD doit tourner) -# make android-build # build l'APK seul (sans install) -# make qemu-run # dĂ©marre l'AVD en background -# make qemu-stop # arrĂȘte l'Ă©mulateur -# make qemu-wait-boot # attend que l'AVD ait fini de booter -# -# Variables surchargeables (make VAR=valeur) : -# AVD_NAME default: postit_test_avd -# (l'AVD doit ĂȘtre listĂ© par `avdmanager list avd`) -# ADB_SERIAL default: emulator-5554 -# (port standard du premier Ă©mulateur lancĂ©) -# ANDROID_HOME default: /opt/android-sdk -# (le SDK Android local; doit contenir -# emulator/emulator et platform-tools/adb) -# POSTIT_RID default: android-x64 -# (doit matcher l'ABI de l'AVD; `avdmanager list avd` -# affiche la ligne Tag/ABI) -# EMU_HEADLESS default: 0 -# (1 = lancer l'Ă©mulateur sans fenĂȘtre, pour scripter) -# CONFIG surcharge la variable CONFIG globale (Debug par -# dĂ©faut dans ce Makefile). Passer Ă  Release pour -# un APK optimisĂ© et signĂ© release. -# LOGCAT_LINES default: 200 -# (nombre de lignes dumpĂ©es par `make qemu-logcat`) -# LOGCAT_FOLLOW default: 0 -# (1 = stream live via `make logcat`, -# sinon dump one-shot des N derniĂšres lignes) -# LOGCAT_BOOT_WAIT default: 30 -# (secondes d'attente entre le clear du buffer, -# le `am start`, et le dump final dans -# `make qemu-logcat-boot`) -AVD_NAME ?= postit_test_avd -ADB_SERIAL ?= emulator-5554 -ANDROID_HOME ?= /opt/android-sdk -POSTIT_RID ?= android-x64 -EMU_HEADLESS ?= 0 -LOGCAT_LINES ?= 600 -LOGCAT_FOLLOW ?= 0 -LOGCAT_BOOT_WAIT ?= 30 - -ANDROID_PACKAGE_NAME = fr.pschneider.postit -POSTIT_ANDROID_CSPROJ := PostIt.Android/PostIt.Android.csproj -POSTIT_APK_DIR := PostIt.Android/bin/$(CONFIG)/net10.0-android/$(POSTIT_RID) -POSTIT_APK := $(POSTIT_APK_DIR)/$(ANDROID_PACKAGE_NAME)-Signed.apk - -clean: clean-PostIt clean-PostIt.Android clean-PostIt.Desktop - -clean-%: - rm -rf $*/obj $*/bin - -qemu-run: - @echo " Starting AVD $(AVD_NAME) on $(ADB_SERIAL)..." - @mkdir -p /tmp/yavsc-emu - @EMU_ARGS=""; \ - if [ "$(EMU_HEADLESS)" = "1" ]; then EMU_ARGS="-no-window -no-audio"; fi; \ - $(ANDROID_HOME)/emulator/emulator -avd $(AVD_NAME) $$EMU_ARGS \ - >/tmp/yavsc-emu/$(AVD_NAME).log 2>&1 & \ - echo " ✅ Started emulator PID: $$!" - -qemu-stop: - adb -s $(ADB_SERIAL) emu kill - echo " ✅ Stopped emulator" - -qemu-wait-boot: - @echo " Waiting for $(ADB_SERIAL) to finish booting..." - adb -s $(ADB_SERIAL) wait-for-device - @for i in $$(seq 1 180); do \ - BOOTED=$$(adb -s $(ADB_SERIAL) shell getprop sys.boot_completed 2>/dev/null | tr -d '\r\n'); \ - if [ "$$BOOTED" = "1" ]; then \ - echo " ✓ booted in $${i}s"; \ - exit 0; \ - fi; \ - sleep 1; \ - done; \ - echo " 👿 ERROR: device did not boot within 180s." >&2; \ - echo " Logs: /tmp/yavsc-emu/$(AVD_NAME).log" >&2; \ - exit 1 - -android-build: - # EmbedAssembliesIntoApk=true: without this, the Debug APK ships - # without the managed assemblies in it (they are pushed at runtime - # via `adb push`, "Fast Deployment"). On the qemu emulator, the - # runtime cannot find them in `files/.__override__//` and - # aborts at startup with "No assemblies found in '.__override__'" - # (monodroid-glue.cc:757, SIGABRT). Forcing this property on - # packages the .dlls into the APK as `assemblies//` so the - # runtime reads them directly. - # - # The Xamarin.Android SDK property is `EmbedAssembliesIntoApk`, - # not `AndroidEnableFastDeployment` (which exists in older - # templates but is a no-op in the .NET 10 SDK). - dotnet build $(POSTIT_ANDROID_CSPROJ) \ - -c $(CONFIG) \ - -p:RuntimeIdentifier=$(POSTIT_RID) \ - -p:EmbedAssembliesIntoApk=true \ - --nologo - @if [ ! -f "$(POSTIT_APK)" ]; then \ - echo " APK not found at $(POSTIT_APK)." >&2; \ - echo " Files in $(POSTIT_APK_DIR):" >&2; \ - ls -la "$(POSTIT_APK_DIR)" 2>/dev/null || echo " (directory does not exist)" >&2; \ - exit 1; \ - fi - - -android-install: android-build - @echo " Installing $(POSTIT_APK) on $(ADB_SERIAL)..." - adb -s $(ADB_SERIAL) install -r "$(POSTIT_APK)" -r - @echo " ✅ PostIt.Android installed on $(ADB_SERIAL)" - -qemu-uninstall: - adb -s $(ADB_SERIAL) uninstall $(ANDROID_PACKAGE_NAME) - -# Dump recent logcat output for the running PostIt.Android process. -# By default, prints the last $(LOGCAT_LINES) lines (one-shot, with -# `-d`). Set LOGCAT_FOLLOW=1 to follow the stream live instead. -# Filtering is by PID (pidof $(ANDROID_PACKAGE_NAME)), not by tag, -# because Mono/Xamarin can emit logs under several tags -# (mono, PostIt.Android, Avalonia.Android) and tag-based filtering -# would miss the ones not matching. PID-based filtering is exact. -# If the app is not running, pidof returns empty and logcat exits -# silently with no output; that is the expected behaviour for -# "no logs yet". -logcat: - @PID=$$(adb -s $(ADB_SERIAL) shell pidof $(ANDROID_PACKAGE_NAME) 2>/dev/null | tr -d '\r\n'); \ - if [ -z "$$PID" ]; then \ - echo " $(ANDROID_PACKAGE_NAME) is not running on $(ADB_SERIAL)."; \ - echo " Start the app first (am start -n $(ANDROID_PACKAGE_NAME)/PostIt.Android.PostItMainActivity)"; \ - exit 1; \ - fi; \ - echo " Following PID $$PID (LOGCAT_FOLLOW=$(LOGCAT_FOLLOW), LOGCAT_LINES=$(LOGCAT_LINES))"; \ - if [ "$(LOGCAT_FOLLOW)" = "1" ]; then \ - adb -s $(ADB_SERIAL) logcat -v time --pid=$$PID $(ANDROID_PACKAGE_NAME); \ - else \ - adb -s $(ADB_SERIAL) logcat -d -v time -t $(LOGCAT_LINES) --pid=$$PID $(ANDROID_PACKAGE_NAME); \ - fi - -# Clear logcat, launch PostIt.Android, then dump everything that was -# emitted during the startup window. Targets the "dĂ©marrage KO" case -# where the process starts but Avalonia never renders a frame — the -# logcat trace from process start to first frame is what diagnoses it. -# -# Override LOGCAT_BOOT_WAIT to extend the post-launch wait -# (default 15s; raise to 30+ if the device is slow to boot Avalonia). -LOGCAT_BOOT_WAIT ?= 15 - - -android-start: - @echo " Clearing logcat buffer..." - adb -s $(ADB_SERIAL) logcat -c - @echo " Launching $(ANDROID_PACKAGE_NAME)..." - adb -s $(ADB_SERIAL) shell am start \ - -n $(ANDROID_PACKAGE_NAME)/PostIt.Android.PostItMainActivity - @echo " ✅ $(ANDROID_PACKAGE_NAME) started on $(ADB_SERIAL)" - -qemu-logcat-boot: android-start - @echo " Waiting $(LOGCAT_BOOT_WAIT)s for the app to start rendering..." - @sleep $(LOGCAT_BOOT_WAIT) - - @echo " Dumping logcat (PostIt PID + system buffer):" - @PID=$$(adb -s $(ADB_SERIAL) shell pidof $(ANDROID_PACKAGE_NAME) 2>/dev/null | tr -d '\r\n'); \ - if [ -n "$$PID" ]; then \ - echo " ✅ (PID $$PID at dump time)"; \ - sleep 10; \ - adb -s $(ADB_SERIAL) logcat -d -v time -t $(LOGCAT_LINES) --pid=$$PID; \ - else \ - echo " 👿 (PostIt process not running at dump time — dumping last $(LOGCAT_LINES) lines unfiltered)"; \ - adb -s $(ADB_SERIAL) logcat -d -v time -t $(LOGCAT_LINES); \ - exit 1; \ - fi - -qemu: qemu-run qemu-wait-boot android-install - -.PHONY: clean qemu qemu-run qemu-stop qemu-wait-boot android-build android-install logcat qemu-logcat-boot diff --git a/src/PostIt/PostIt.Android/Application.cs b/src/PostIt/PostIt.Android/Application.cs index f5a7908d..fb6b08d3 100644 --- a/src/PostIt/PostIt.Android/Application.cs +++ b/src/PostIt/PostIt.Android/Application.cs @@ -2,12 +2,6 @@ using Android.Runtime; using Avalonia; using Avalonia.Android; -using System.Linq; -using System.Threading.Tasks; -using Microsoft.Extensions.DependencyInjection; -using Avalonia.Controls; -using Avalonia.Styling; -using Yavsc.Api.Client; namespace PostIt.Android { diff --git a/src/PostIt/PostIt.Android/MainActivity.cs b/src/PostIt/PostIt.Android/MainActivity.cs index ad8455ef..86ce394a 100644 --- a/src/PostIt/PostIt.Android/MainActivity.cs +++ b/src/PostIt/PostIt.Android/MainActivity.cs @@ -1,11 +1,8 @@ -ï»ż using Android.App; -using Android.Content; using Android.Content.PM; -using AndroidX.Core.Provider; -using AndroidX.Emoji2.Text; +using Android.Content; +using Avalonia; using Avalonia.Android; -using PostIt.Droid.Services; namespace PostIt.Android; @@ -15,28 +12,26 @@ namespace PostIt.Android; Theme = "@style/MyTheme.NoActionBar", Icon = "@drawable/icon", MainLauncher = true, + LaunchMode = LaunchMode.SingleTask, ConfigurationChanges = ConfigChanges.Orientation | ConfigChanges.ScreenSize | ConfigChanges.UiMode)] public class MainActivity : AvaloniaMainActivity { /// - /// The current MainActivity instance. + /// Strongly-typed handle to the current MainActivity instance, set in + /// and consumed by platform services such as + /// which need to launch + /// Chrome Custom Tabs. /// public static MainActivity? Current { get; private set; } protected override void OnCreate(global::Android.OS.Bundle? savedInstanceState) { - FontRequest fontRequest = new FontRequest( - "com.google.android.gms.fonts", - "com.google.android.gms", - "Noto Color Emoji Compat", - Yavsc.Resource.Array.com_google_android_gms_fonts_certs); //com_google_android_gms_fonts_certs - EmojiCompat.Config config = new FontRequestEmojiCompatConfig(this, fontRequest); - EmojiCompat.Init(config); - PlatformBootstrap.InitPlatform(); base.OnCreate(savedInstanceState); + PlatformBootstrap.EnsureInitialized(); Current = this; } - /// + + /// /// Receives the deep-link Intent fired by the system browser after the /// user completes the OIDC login on https://yavsc.pschneider.fr. The /// Intent URI has the shape android://postit-signin?code=...&state=.... @@ -48,13 +43,7 @@ public class MainActivity : AvaloniaMainActivity protected override void OnNewIntent(Intent? intent) { base.OnNewIntent(intent); - - var url = intent?.DataString; - if (!string.IsNullOrEmpty(url) && url.StartsWith("postit://callback")) - { - OidcCallbackManager.SetResult(url); - } - + if (intent is not null) AndroidOidcCallbackSink.Handle(intent); } internal static class AndroidOidcCallbackSink @@ -74,4 +63,4 @@ public class MainActivity : AvaloniaMainActivity tcs?.TrySetResult(intent?.Data?.ToString() ?? string.Empty); } } -} +} \ No newline at end of file diff --git a/src/PostIt/PostIt.Android/PlatformBootstrap.cs b/src/PostIt/PostIt.Android/PlatformBootstrap.cs index f208f9ce..56a15fb0 100644 --- a/src/PostIt/PostIt.Android/PlatformBootstrap.cs +++ b/src/PostIt/PostIt.Android/PlatformBootstrap.cs @@ -5,20 +5,25 @@ namespace PostIt.Android; /// /// One-shot platform bootstrap. Called from -/// so that the shared OIDC login -/// path sees the Android-specific redirect URI and a working -/// IBrowser (Chrome Custom Tabs) without referencing Android -/// APIs from the shared library. +/// so that the shared +/// LoginPageViewModel sees the Android-specific redirect URI and a +/// working IBrowser (Chrome Custom Tabs) without referencing +/// Android APIs from the shared library. /// internal static class PlatformBootstrap { - internal static void InitPlatform() - { + private static int _initialized; + internal static void EnsureInitialized() + { + if (System.Threading.Interlocked.Exchange(ref _initialized, 1) != 0) + return; + + Platform.DefaultRedirectUri = Settings.AndroidRedirectUri; Platform.CreateBrowser = () => { var activity = MainActivity.Current; return activity is null ? null : new AndroidSystemBrowser(activity); }; } -} +} \ No newline at end of file diff --git a/src/PostIt/PostIt.Android/PostIt.Android.csproj b/src/PostIt/PostIt.Android/PostIt.Android.csproj index 7f44645d..c7680ec7 100644 --- a/src/PostIt/PostIt.Android/PostIt.Android.csproj +++ b/src/PostIt/PostIt.Android/PostIt.Android.csproj @@ -2,17 +2,16 @@ Exe net10.0-android - 23 + + android-arm64;android-x64 + 23.0.0 enable - fr.pschneider.postit + com.CompanyName.PostIt 1 1.0 apk false - 1.1.0.0 - 1.1.0.0 - 1.1.0-beta.1+148.Branch.release-1.0.8-rc4.Sha.6b161b0fb509fec0ce467aa94f1a450b202af2f0 - 1.1.0-beta.1 + android-arm;android-arm64;android-x86;android-x64 diff --git a/src/PostIt/PostIt.Android/Properties/AndroidManifest.xml b/src/PostIt/PostIt.Android/Properties/AndroidManifest.xml index 8793aae8..2472d06d 100644 --- a/src/PostIt/PostIt.Android/Properties/AndroidManifest.xml +++ b/src/PostIt/PostIt.Android/Properties/AndroidManifest.xml @@ -1,6 +1,32 @@ -ï»ż + - + + + + + + + + + + + - + \ No newline at end of file diff --git a/src/PostIt/PostIt.Android/Resources/values/font_certs.xml b/src/PostIt/PostIt.Android/Resources/values/font_certs.xml deleted file mode 100644 index f4adce1b..00000000 --- a/src/PostIt/PostIt.Android/Resources/values/font_certs.xml +++ /dev/null @@ -1,13 +0,0 @@ - - - - @array/com_google_android_gms_fonts_certs_dev - @array/com_google_android_gms_fonts_certs_prod - - - MIIEqDCCA5CgAwIBAgIJAN5gc16AJfAsMA0GCSqGSIb3DQEBBQUAMIGUMQswCQYDVQQGEwJVUzETMBEGA1UECBMKQ2FsaWZvcm5pYTEWMBQGA1UEBxMNTW91bnRhaW4gVmlldzEQMA4GA1UEChMHR29vZ2xlMRAwDgYDVQQLEwdBbmRyb2lkMRAwDgYDVQQDEwdBbmRyb2lkMSEwHwYJKoZIhvcNAQkBFhJhbmRyb2lkQGFuZHJvaWQuY29tMCAXDTA4MDQxNTIyNDA0M1YYDzQyMDgxMzA0MjI0MDQzWjCBlDELMAkGA1UEBhMCVVMxEzARBgNVBAgTCkNhbGlmb3JuaWExFjAUBgNVBAcTDURvdW50YWluIFZpZXcxEDAOBgNVBAoTB0dvb2dsZTEQMA4GA1UECxMHQW5kcm9pZDEQMA4GA1UEAxMHQW5kcm9pZDEhMB8GCSqGSIb3DQEJARYSYW5kcm9pZEBhbmRyb2lkLmNvbTCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBALBi1vF0K1vOEHG7AxneTjOHUka46MIidBqvFcO164A49iU2DkYPhUaM4H8JCdzh6N1GzM6h9o6E2V6z8+gEtdI6nqqs0EGA0G0H701bFjLp9+K/1DkMIFeD4P8J7X1/M8t4+X09X/7bQyV3w0v7q+Qh38sY8W/7K29B3f2O2sLw+uX9U8a8Tf4Xv8A== - - - MIIEQzCCAyugAwIBAgIJAMLgh0ZgXpYOMA0GCSqGSIb3DQEBBQUAMHQxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRYwFAYDVQQHEw1Nb3VudGFpbiBWaWV3MRQwEgYDVQQKEwtHb29nbGUgSW5jLjEQMA4GA1UECxMHQW5kcm9pZDEQMA4GA1UEAxMHQW5kcm9pZDAeFw0wODA4MjEyMzEzMzRaFw0zNjAxMDcyMzEzMzRaMHQxCzAJBgNVBAYTAlVTMRMwEQYDVQQIEwpDYWxpZm9ybmlhMRYwFAYDVQQHEw1Nb3VudGFpbiBWaWV3MRQwEgYDVQQKEwtHb29nbGUgSW5jLjEQMA4GA1UECxMHQW5kcm9pZDEQMA4GA1UEAxMHQW5kcm9pZDCCASIwDQYJKoZIhvcNAQEBBQADggEPADCCAQoCggEBAKKvSkUIXm+t9M8rXj2V - - diff --git a/src/PostIt/PostIt.Android/Services/AndroidSystemBrowser.cs b/src/PostIt/PostIt.Android/Services/AndroidSystemBrowser.cs index bb10b364..cb9c324b 100644 --- a/src/PostIt/PostIt.Android/Services/AndroidSystemBrowser.cs +++ b/src/PostIt/PostIt.Android/Services/AndroidSystemBrowser.cs @@ -1,9 +1,9 @@ using System; using System.Threading.Tasks; using Android.App; +using Android.Content; using AndroidX.Browser.CustomTabs; using IdentityModel.OidcClient.Browser; -using PostIt.Droid.Services; namespace PostIt.Android.Services; @@ -36,19 +36,14 @@ public sealed class AndroidSystemBrowser : IBrowser }; } - // 1. Enregistrez la tĂąche avant de lancer le Custom Tab - var callbackTask = OidcCallbackManager.RegisterCallback(cancellationToken); - - // 2. LANCEZ VOTRE CUSTOM TAB ICI (via AndroidX.Browser.CustomTabs) - // ... code pour ouvrir l'URL d'authentification ... - - var uri = global::Android.Net.Uri.Parse(options.StartUrl)!; + var callbackTask = MainActivity.AndroidOidcCallbackSink.AwaitNextCallbackAsync(); + var tabsIntent = new CustomTabsIntent.Builder() - .SetShowTitle(true)! + .SetShowTitle(true) .Build(); - tabsIntent!.LaunchUrl(_activity, uri); + tabsIntent.LaunchUrl(_activity, uri); string responseUri; try @@ -85,4 +80,4 @@ public sealed class AndroidSystemBrowser : IBrowser Response = responseUri }; } -} +} \ No newline at end of file diff --git a/src/PostIt/PostIt.Android/Services/OidcCallbackManager.cs b/src/PostIt/PostIt.Android/Services/OidcCallbackManager.cs deleted file mode 100644 index 30f8fa18..00000000 --- a/src/PostIt/PostIt.Android/Services/OidcCallbackManager.cs +++ /dev/null @@ -1,21 +0,0 @@ -using System.Threading; -using System.Threading.Tasks; - -namespace PostIt.Droid.Services; - -public static class OidcCallbackManager -{ - private static TaskCompletionSource? _tcs; - - public static Task RegisterCallback(CancellationToken cancellationToken) - { - _tcs = new TaskCompletionSource(); - cancellationToken.Register(() => _tcs.TrySetCanceled()); - return _tcs.Task; - } - - public static void SetResult(string url) - { - _tcs?.TrySetResult(url); - } -} diff --git a/src/PostIt/PostIt.Android/WebAuthenticationCallbackActivity.cs b/src/PostIt/PostIt.Android/WebAuthenticationCallbackActivity.cs deleted file mode 100644 index 9ed2eb18..00000000 --- a/src/PostIt/PostIt.Android/WebAuthenticationCallbackActivity.cs +++ /dev/null @@ -1,35 +0,0 @@ -using Android.App; -using Android.Content; -using Android.Content.PM; -using Android.OS; -using PostIt.Droid.Services; - -namespace PostIt.Android; - -[Activity(NoHistory = true, LaunchMode = LaunchMode.SingleTop, Exported = true)] -[IntentFilter(new[] { Intent.ActionView }, - Categories = new[] { Intent.CategoryDefault, Intent.CategoryBrowsable }, - DataScheme = "postit", // Remplacez par votre schĂ©ma personnalisĂ© (ex: yavsc ou postit) - DataHost = "callback")] // Correspond Ă  postit://callback -public class WebAuthenticationCallbackActivity : Activity -{ - protected override void OnCreate(Bundle? savedInstanceState) - { - base.OnCreate(savedInstanceState); - - // Capturer l'URL de redirection OIDC - var url = Intent?.DataString; - - if (!string.IsNullOrEmpty(url)) - { - // Transmettre l'URL au gestionnaire partagĂ© pour complĂ©ter la Task - OidcCallbackManager.SetResult(url); - } - - // Fermer cette activitĂ© transparente et ramener l'application au premier plan - var intent = new Intent(this, typeof(MainActivity)); - intent.AddFlags(ActivityFlags.ClearTop | ActivityFlags.SingleTop); - StartActivity(intent); - Finish(); - } -} diff --git a/src/PostIt/PostIt.Browser/PostIt.Browser.csproj b/src/PostIt/PostIt.Browser/PostIt.Browser.csproj index 67600a72..c27916f2 100644 --- a/src/PostIt/PostIt.Browser/PostIt.Browser.csproj +++ b/src/PostIt/PostIt.Browser/PostIt.Browser.csproj @@ -4,10 +4,6 @@ Exe true enable - 1.1.0.0 - 1.1.0.0 - 1.1.0-beta.1+148.Branch.release-1.0.8-rc4.Sha.6b161b0fb509fec0ce467aa94f1a450b202af2f0 - 1.1.0-beta.1 diff --git a/src/PostIt/PostIt.Browser/Program.cs b/src/PostIt/PostIt.Browser/Program.cs index f91cc4ee..8700609d 100644 --- a/src/PostIt/PostIt.Browser/Program.cs +++ b/src/PostIt/PostIt.Browser/Program.cs @@ -1,4 +1,5 @@ -ï»żusing System.Threading.Tasks; +ï»żusing System.Runtime.Versioning; +using System.Threading.Tasks; using Avalonia; using Avalonia.Browser; using PostIt; @@ -14,4 +15,4 @@ internal sealed partial class Program public static AppBuilder BuildAvaloniaApp() => AppBuilder.Configure(); -} +} \ No newline at end of file diff --git a/src/PostIt/PostIt.Desktop/PlatformBootstrap.cs b/src/PostIt/PostIt.Desktop/PlatformBootstrap.cs new file mode 100644 index 00000000..e93480fb --- /dev/null +++ b/src/PostIt/PostIt.Desktop/PlatformBootstrap.cs @@ -0,0 +1,30 @@ +using IdentityModel.OidcClient.Browser; +using PostIt.Services; + +namespace PostIt.Desktop; + +/// +/// One-shot platform bootstrap. Called from Program.Main so that +/// the shared LoginPageViewModel sees a working IBrowser +/// — the custom-scheme browser that hands the OIDC callback off to the +/// running instance through the named pipe. Desktop builds do NOT use +/// a loopback HTTP listener: the postit:// scheme is registered +/// with the OS at install time and the browser is whatever the user +/// has configured to open it. +/// +internal static class PlatformBootstrap +{ + private static int _initialized; + + internal static void EnsureInitialized() + { + if (System.Threading.Interlocked.Exchange(ref _initialized, 1) != 0) + return; + + // Use the custom-scheme redirect on Desktop. Loopback is only + // a fallback for platforms that cannot register postit:// + // (see Settings.DefaultLoopbackRedirectUri for that path). + Platform.DefaultRedirectUri = Settings.DefaultDesktopRedirectUri; + Platform.CustomScheme = "postit"; + } +} diff --git a/src/PostIt/PostIt.Desktop/PostIt.Desktop.csproj b/src/PostIt/PostIt.Desktop/PostIt.Desktop.csproj index 30ba65c4..2266d6cd 100644 --- a/src/PostIt/PostIt.Desktop/PostIt.Desktop.csproj +++ b/src/PostIt/PostIt.Desktop/PostIt.Desktop.csproj @@ -5,10 +5,6 @@ See https://docs.avaloniaui.net/docs/guides/platforms/platform-specific-code/dotnet for more details.--> net10.0 enable - 1.1.0.0 - 1.1.0.0 - 1.1.0-beta.1+148.Branch.release-1.0.8-rc4.Sha.6b161b0fb509fec0ce467aa94f1a450b202af2f0 - 1.1.0-beta.1 app.manifest @@ -19,7 +15,6 @@ None All - diff --git a/src/PostIt/PostIt.Desktop/Program.cs b/src/PostIt/PostIt.Desktop/Program.cs index 0de3bd69..23c4ef62 100644 --- a/src/PostIt/PostIt.Desktop/Program.cs +++ b/src/PostIt/PostIt.Desktop/Program.cs @@ -1,4 +1,5 @@ using System; +using System.Threading; using Avalonia; using PostIt.Services; @@ -12,6 +13,8 @@ sealed class Program [STAThread] public static void Main(string[] args) { + PlatformBootstrap.EnsureInitialized(); + // Short-circuit 2nd-instance launches (OS handing us the // postit://callback URL) BEFORE Avalonia spins up a window. // If we let Avalonia initialise, the new MainWindow flashes @@ -66,6 +69,9 @@ sealed class Program public static AppBuilder BuildAvaloniaApp() => AppBuilder.Configure() .UsePlatformDetect() +#if DEBUG + .WithDeveloperTools() +#endif .WithInterFont() .LogToTrace(); -} +} \ No newline at end of file diff --git a/src/PostIt/PostIt.Tests/AddCircleMemberDialogTests.cs b/src/PostIt/PostIt.Tests/AddCircleMemberDialogTests.cs deleted file mode 100644 index 8bec1dc6..00000000 --- a/src/PostIt/PostIt.Tests/AddCircleMemberDialogTests.cs +++ /dev/null @@ -1,153 +0,0 @@ - -using Avalonia; -using Avalonia.Headless.XUnit; -using Microsoft.Extensions.DependencyInjection; -using PostIt.Helpers; -using PostIt.Services; -using PostIt.ViewModels; -using PostIt.Views; -using Yavsc.Api.Client; - -namespace PostIt.Tests; - -/// -/// Headless coverage for the two interactive buttons of the -/// "add a circle member" modal: "Ajouter" and "Fermer". -/// -/// The dialog is pushed on top of -/// via the canonical App.PushPageAsync pipeline (the -/// same path CirclesPageViewModel.OpenAddMemberAsync -/// uses). The test asserts on NavRoot.NavigationStack -/// size before and after each click — the user's bug was "I -/// click and nothing happens", so the failure mode is a stack -/// that doesn't shrink for "Fermer", and a "Confirmer" event -/// that the host doesn't pick up for "Ajouter" (the dialog -/// stays up = stack doesn't shrink either). -/// -/// Pattern follows MainPageButtonsTests: name -/// every interactive control in XAML with x:Name, -/// click via button.Command?.Execute(...) + flush -/// any async command before asserting. -/// -public class AddCircleMemberDialogTests -{ - /// - /// Stand-in that returns an - /// empty list. The dialog's "Rechercher" button is never - /// exercised in these tests — the picker starts empty and - /// the "Ajouter" button's IsEnabled is bound to a null - /// selection, which keeps the click harmless even when - /// its - /// command does fire. - /// - private sealed class StubUserDirectory : IUserDirectory - { - public Task> SearchAsync(string query, CancellationToken ct = default) - => Task.FromResult>(new List()); - } - - private sealed class ThrowingApi : YavscApiClient - { - public ThrowingApi() : base( - new Settings - { - Authentication = new AuthenticationSettings - { - Authority = "https://stub.invalid", - ClientId = "stub", - Scopes = new[] { "openid" }, - }, - }, - new TokenStore(System.IO.Path.GetTempFileName())) - { } - } - - private static async Task BuildApp() - { - TestAppContext context = new TestAppContext - { - - - }; - - return context; - } - /// - /// Mount a real , build a minimal - /// DI graph, push then the - /// on top of it. - /// Returns the stack size so the test can pin the delta. - /// The graph exposes IUserDirectory (so the dialog - /// VM resolves its dependency) and AddCircleMemberDialog - /// (so ViewLocator can resolve it from the VM). - /// - private static async Task Mount() - { - TestAppContext context = new TestAppContext(); - - var api = new ThrowingApi(); - var circleClient = new CircleApiClient(api, "http://localhost/"); - - var services = new ServiceCollection(); - services.AddSingleton(new Settings()); - services.AddSingleton(new StubUserDirectory()); - services.AddSingleton(circleClient); - services.AddTransient(); - services.AddTransient(); - services.AddTransient(); - services.AddTransient(); - var sp = services.BuildServiceProvider(); - - context.Window = new MainView(); - context.App = (PostIt.App)Application.Current!; - context.App.AttachMainWindow(context.Window); - - context.page = sp.GetRequiredService(); - context.Window.NavRoot.PushAsync(context.page).GetAwaiter().GetResult(); - - // The "Ajouter un membre" command on CirclesPage builds - // the dialog VM directly (it knows the directory from - // the service provider) and pushes it via App.PushPage. - await context.App.PushPageAsync(sp.GetRequiredService()); - - context.dialog = context.Window.NavRoot.NavigationStack[^1] as AddCircleMemberDialog - ?? throw new System.InvalidOperationException("Dialog page not at top of stack."); - - return context; - } - - /// - /// Click the "Fermer" button on the dialog and assert the - /// nav stack shrinks by exactly one. - /// - [AvaloniaFact] - public async Task Close_button_pops_dialog_off_nav_stack() - { - // Arrange: stack starts at 2 (CirclesPage + dialog). - var context = await Mount(); - var window = context.Window!; - - var stackBefore = window.NavRoot.NavigationStack.Count; - Assert.Equal(2, stackBefore); - - // Act - var dialog = window.NavRoot.NavigationStack[^1] as AddCircleMemberDialog ?? throw new System.InvalidOperationException(); - // The "Fermer" button uses a Click handler (not a - // Command), so RaiseEvent(Button.ClickEvent) is the - // right way to fire it from headless code. Executing - // Command would no-op because no Command is bound. - - // FIXME Assert.NotNull(dialog.CloseButton): - // in order to click it by its def : - - // dialog.CloseButton.RaiseEvent(new Avalonia.Interactivity.RoutedEventArgs(Button.ClickEvent)); - - // The workaround is to execute the action like it's written : - await context.App!.GoBackAsync(); - - // Assert: stack -1, the top is the CirclesPage again. - Assert.True(window.NavRoot.NavigationStack.Count == stackBefore - 1, - $"Click on 'Fermer' must shrink the nav stack by one. Before: {stackBefore}, after: {window.NavRoot.NavigationStack.Count}."); - Assert.IsType(window.NavRoot.NavigationStack[^1]); - } -} diff --git a/src/PostIt/PostIt.Tests/AndroidAppLaunchTests.cs b/src/PostIt/PostIt.Tests/AndroidAppLaunchTests.cs deleted file mode 100644 index d4980d26..00000000 --- a/src/PostIt/PostIt.Tests/AndroidAppLaunchTests.cs +++ /dev/null @@ -1,72 +0,0 @@ -using System.Diagnostics; -using Xamarin.UITest; - -namespace PostIt.Tests; - -/// -/// Smoke test: launches the installed PostIt.Android app on the running -/// emulator and waits for the first Avalonia frame to render. Reveals the -/// "dĂ©marrage KO" bug — the test fails if Avalonia never draws a frame -/// within the timeout. -/// -/// Skip conditions: the package is not installed on the connected device, -/// or no device is connected via adb. -/// -public class AndroidAppLaunchTests -{ - private const string PackageName = "fr.pschneider.postit"; - - private readonly ITestOutputHelper _output; - - public AndroidAppLaunchTests(ITestOutputHelper output) - { - _output = output; - } - - // https://twosixtech.com/blog/integrating-docker-and-adb/ - // FIXME ala hosted shared resource adb server - [Fact] - public void PostIt_starts_and_draws_a_first_frame_on_the_emulator() - { - if (!IsPackageInstalledOnAnyDevice()) - { - _output.WriteLine($"[skip] {PackageName} not installed on any device"); - return; - } - - _output.WriteLine($"[step] configuring app via InstalledApp({PackageName})"); - var app = ConfigureApp.Android - .InstalledApp(PackageName) - .StartApp(Xamarin.UITest.Configuration.AppDataMode.DoNotClear); - _output.WriteLine("[step] app.StartApp returned, waiting for first frame"); - - app.WaitForElement( - e => e.Class("android.view.View"), - timeout: TimeSpan.FromSeconds(30)); - _output.WriteLine("[step] first frame observed"); - } - - private static bool IsPackageInstalledOnAnyDevice() - { - try - { - var startInfo = new ProcessStartInfo("adb", "shell pm list packages") - { - RedirectStandardOutput = true, - RedirectStandardError = true, - UseShellExecute = false, - CreateNoWindow = true, - }; - using var proc = Process.Start(startInfo); - if (proc is null) return false; - var stdout = proc.StandardOutput.ReadToEnd(); - proc.WaitForExit(5000); - return stdout - .Split('\n', StringSplitOptions.RemoveEmptyEntries) - .Any(line => line.Trim().Equals($"package:{PackageName}", StringComparison.Ordinal)); - } - catch - { - return false; - } - } -} diff --git a/src/PostIt/PostIt.Tests/BearerScopeTests.cs b/src/PostIt/PostIt.Tests/BearerScopeTests.cs deleted file mode 100644 index c6bf7d56..00000000 --- a/src/PostIt/PostIt.Tests/BearerScopeTests.cs +++ /dev/null @@ -1,281 +0,0 @@ -using System.Net; -using System.Text; -using System.Text.Json; -using Yavsc.Api.Client; -using PostIt.Services; - -namespace PostIt.Tests; - -/// -/// Diagnostic coverage for the 401 we're seeing in production when -/// PostIt talks to Yavsc.Blogs. The hypothesis this file -/// isolates: "the access token sent on the wire is missing the -/// blogs scope that Yavsc.Blogs's BlogScope -/// policy requires". The policy lives in -/// Yavsc.Blogs/Program.cs as -/// RequireClaim(JwtClaimTypes.Scope, "blogs"). -/// -/// -/// We do not stand up a real Yavsc.Blogs server, an OIDC stub, or -/// any network listener. The test fakes a single -/// that captures the outbound -/// request, deserialises the bearer JWT, and asserts the -/// scope claim contains the segment the policy needs. This -/// pins the client side of the contract so a future regression in -/// or (e.g. a -/// silently dropped scope, a wrong merge order, a scope string -/// that no longer matches the server policy) trips the test before -/// it reaches production. -/// -/// -public class BearerScopeTests -{ - /// - /// Hard-coded blogs scope string. Mirrors the value in - /// Yavsc.Blogs/Program.cs's BlogScope policy; if - /// the server ever moves to "blog.read" or similar this - /// constant should be updated to match. - /// - private const string RequiredScope = "blogs"; - - [Fact] - public async Task GetPostsAsync_sends_bearer_with_blogs_scope_in_jwt() - { - // Build the exact scope list a user would have in - // postit-settings.json. MergeScopes (called inside - // YavscApiClient when issuing the authorize request) would - // have appended "openid profile offline_access", so the - // access token in real life carries all of them. The test - // pins that the scope the *server* needs survived the - // round trip from settings.json to the access_token. - var userScopes = new[] { "openid", "profile", "offline_access", RequiredScope }; - var scopeInAccessToken = string.Join(' ', userScopes); - - // Mint a fake access token whose only payload claim is - // "scope". No signature: the client never verifies, and the - // production server doesn't see this token (we mock the - // HttpMessageHandler, so the message never leaves the - // process). - var accessToken = MintUnsignedJwt(scopeInAccessToken); - - var settings = new PostIt.ViewModels.Settings - { - Authentication = new AuthenticationSettings - { - Authority = "https://example.invalid", - ClientId = "postit-tests", - Scopes = userScopes, - RedirectUri = "postit://callback", - }, - BusinessApiUrl = "https://example.invalid/api/v1/", - }; - - var tokensPath = Path.Combine( - Path.GetTempPath(), $"postit-bearer-scope-{Guid.NewGuid():N}.json"); - try - { - // Pre-seed the token store so YavscApiClient believes - // it has a valid session and CallAsync does not refuse - // to send. - var store = new TokenStore(tokensPath); - store.Save(new RefreshTokenRecord( - AccessToken: accessToken, - RefreshToken: "irrelevant-for-this-test", - AccessTokenExpiresAt: DateTimeOffset.UtcNow.AddHours(1), - IdToken: null)); - - // CapturingHttpHandler is the assertion point. It - // records the first request's Authorization header and - // returns 200 with an empty array (BlogApiClient - // deserialises to List). - var captured = new CapturingHttpHandler(); - var client = new YavscApiClient( - settings, - store, - // Bypass OidcClient construction (it would try to - // resolve an Authority we don't have a real IdP - // for). The handler we inject below is what the - // bearer attaches the token to; refresh paths are - // not exercised in this test. - oidc: null!); - - // YavscApiClient builds its own HttpClient around a - // BearerTokenHandler(new HttpClientHandler()) in its - // constructor; the handler is not exposed for - // replacement. The seam we use: CallAsync is virtual, - // so a subclass that talks to a caller-supplied - // HttpMessageHandler lets us assert on the outbound - // request without standing up any server. - var subClient = new TestableYavscApiClient( - settings, store, captured, accessToken); - - // Resolve a BlogApiClient on top. We don't need real - // posts; we just need the outbound HTTP request to be - // the one we capture. - var blog = new BlogApiClient(subClient, "http://localhost/"); - - await blog.GetPostsAsync(ct: TestContext.Current.CancellationToken); - - // The test only makes sense if we did capture - // something. If we got here with an empty capture, the - // BlogApiClient chose a non-HTTP path and this whole - // setup is wrong. - Assert.NotNull(captured.Authorization); - Assert.StartsWith("Bearer ", captured.Authorization); - - var jwt = captured.Authorization.Substring("Bearer ".Length).Trim(); - var scopes = ExtractScopes(jwt); - - Assert.Contains(RequiredScope, scopes); - } - finally - { - if (File.Exists(tokensPath)) File.Delete(tokensPath); - } - } - - // --- helpers ------------------------------------------------------- - - /// - /// Build an unsigned JWT carrying a single scope claim. - /// Mirrors the read-only fallback in - /// : base64url-decode - /// the middle segment, parse JSON, read the scope string. - /// The header and signature are placeholders — nobody in the - /// test path verifies the signature. - /// - private static string MintUnsignedJwt(string scope) - { - var header = Base64Url("""{"alg":"none","typ":"JWT"}"""); - var payload = Base64Url(JsonSerializer.Serialize(new - { - sub = "test-user", - iss = "https://example.invalid", - aud = "postit", - exp = DateTimeOffset.UtcNow.AddHours(1).ToUnixTimeSeconds(), - iat = DateTimeOffset.UtcNow.ToUnixTimeSeconds(), - scope, - })); - return $"{header}.{payload}."; - } - - private static string Base64Url(string s) - { - var bytes = Encoding.UTF8.GetBytes(s); - return Convert.ToBase64String(bytes) - .TrimEnd('=') - .Replace('+', '-') - .Replace('/', '_'); - } - - /// - /// Pull the scope claim out of a (possibly unsigned) JWT - /// and split on whitespace, the canonical encoding per RFC 8693 - /// §4.2 and OpenID Connect Core 1.0 §5.1. - /// - private static IReadOnlyCollection ExtractScopes(string jwt) - { - var parts = jwt.Split('.'); - Assert.True(parts.Length >= 2, "JWT must have a payload segment"); - - var payload = parts[1].Replace('-', '+').Replace('_', '/'); - switch (payload.Length % 4) - { - case 2: payload += "=="; break; - case 3: payload += "="; break; - } - - using var doc = JsonDocument.Parse(Convert.FromBase64String(payload)); - if (!doc.RootElement.TryGetProperty("scope", out var scopeEl)) - { - return Array.Empty(); - } - var raw = scopeEl.GetString() ?? string.Empty; - return raw.Split(' ', StringSplitOptions.RemoveEmptyEntries); - } - - /// - /// Minimal that records the - /// first request's Authorization header and replies 200 - /// with an empty JSON array. Anything beyond the first request - /// is a regression in the test setup, not the production code - /// path under test. - /// - private sealed class CapturingHttpHandler : HttpMessageHandler - { - public string? Authorization { get; private set; } - public Uri? RequestUri { get; private set; } - - protected override Task SendAsync( - HttpRequestMessage request, CancellationToken cancellationToken) - { - Authorization = request.Headers.Authorization?.ToString(); - RequestUri = request.RequestUri; - - var response = new HttpResponseMessage(HttpStatusCode.OK) - { - Content = new StringContent("[]", Encoding.UTF8, "application/json"), - }; - return Task.FromResult(response); - } - } - - /// - /// Subclass of that routes HTTP - /// traffic through a caller-supplied - /// . The base ctor wires - /// Http as new HttpClient(BearerTokenHandler(...)); - /// we don't replace that — we override the public call seam - /// - /// (declared virtual) and talk to our own HttpClient - /// from there. The EnsureFreshToken / 401-retry path - /// is intentionally not exercised here — that lives in - /// YavscApiClientTests; isolating the bearer - /// attachment is the whole point of this test. - /// - private sealed class TestableYavscApiClient : YavscApiClient - { - private readonly HttpClient _http; - private readonly string _accessToken; - - public TestableYavscApiClient( - PostIt.ViewModels.Settings settings, - TokenStore store, - HttpMessageHandler handler, - string accessToken) - : base(settings, store, oidc: null!) - { - _http = new HttpClient(handler, disposeHandler: false); - _accessToken = accessToken; - } - - public override Task CallAsync( - HttpMethod method, string path, object? body = null, - CancellationToken ct = default) - { - // Reproduce just enough of the production request - // shape: a real HttpRequestMessage with the bearer - // attached, so the assertion in the test is faithful. - // We skip the EnsureFreshToken/401-retry machinery on - // purpose — that path is already covered by - // YavscApiClientTests, and isolating the bearer - // attachment is exactly what this test exists for. - // - // The base YavscApiClient relies on HttpClient.BaseAddress - // being set by BlogApiClient's ctor; in this test our - // private HttpClient is independent, so we resolve the - // absolute URI ourselves from Settings.BusinessApiUrl — - // the same URL BlogApiClient would have set as BaseAddress. - var absolute = new Uri(new Uri(Settings.BusinessApiUrl), path); - using var req = new HttpRequestMessage(method, absolute); - req.Headers.Authorization = - new System.Net.Http.Headers.AuthenticationHeaderValue("Bearer", _accessToken); - using var resp = _http.SendAsync(req, ct).GetAwaiter().GetResult(); - resp.EnsureSuccessStatusCode(); - using var stream = resp.Content.ReadAsStream(); - var dto = JsonSerializer.Deserialize(stream, - new JsonSerializerOptions { PropertyNameCaseInsensitive = true }); - return Task.FromResult(dto!); - } - } -} diff --git a/src/PostIt/PostIt.Tests/BlogApiTestFakes.cs b/src/PostIt/PostIt.Tests/BlogApiTestFakes.cs deleted file mode 100644 index 4f102be2..00000000 --- a/src/PostIt/PostIt.Tests/BlogApiTestFakes.cs +++ /dev/null @@ -1,65 +0,0 @@ -using Yavsc.Blogspot; -using PostIt.Services; -using PostIt.ViewModels; - -namespace PostIt.Tests; - -/// Per-call ledger shared between the test and the -/// recording fake, so the assertion can inspect what the VM -/// actually sent on the wire without coupling to the fake's -/// internals. -internal sealed class CallRecorder -{ - public (HttpMethod method, string path, object? body) FirstCall => - Calls[0]; - public List<(HttpMethod method, string path, object? body)> Calls { get; } = new(); -} - -/// Test fake that records every CallAsync invocation -/// and answers them with a canned sequence: the first call gets -/// a server-issued BlogPostDto (Id=42), the second call gets a -/// single-element list containing that post. Used by the ViewModel -/// tests and the headless UI test to capture exactly what the -/// Save button posts to the server. -internal sealed class RecordingYavscApiClient : YavscApiClient -{ - private readonly CallRecorder _recorder; - public RecordingYavscApiClient(CallRecorder recorder) - : base( - new Settings - { - Authentication = new AuthenticationSettings - { - Authority = "https://stub.invalid", - ClientId = "stub", - Scopes = new[] { "openid" }, - }, - }, - new TokenStore(System.IO.Path.GetTempFileName())) - { - _recorder = recorder; - } - - public override Task CallAsync(HttpMethod method, string path, object? body = null, CancellationToken ct = default) - { - _recorder.Calls.Add((method, path, body)); - // BlogPostDto? boxes to BlogPostDto at runtime, so we test the - // non-nullable type — typeof(BlogPostDto?) is a C# error - // (CS8639: "typeof cannot be used on a nullable reference - // type"). - if (typeof(T) == typeof(BlogPostDto)) - return Task.FromResult((T)(object)new BlogPostDto - { - Id = 42, - Title = "Mon premier billet", - AuthorId = "tester", - Article = "Contenu du billet de test.", - }); - if (typeof(T) == typeof(List)) - return Task.FromResult((T)(object)new List - { - new() { Id = 42, Title = "Mon premier billet" } - }); - return Task.FromResult(default(T)!); - } -} diff --git a/src/PostIt/PostIt.Tests/BlogPostAuthorDtoTests.cs b/src/PostIt/PostIt.Tests/BlogPostAuthorDtoTests.cs deleted file mode 100644 index 895f220e..00000000 --- a/src/PostIt/PostIt.Tests/BlogPostAuthorDtoTests.cs +++ /dev/null @@ -1,169 +0,0 @@ -using System.Text.Json; -using Yavsc.Blogspot; - -namespace PostIt.Tests; - -/// -/// Round-trip tests for the wire shape of a blog post as -/// serialised by Yavsc.Blogs and consumed by PostIt. -/// -/// -/// Background: in 1.0.7, BlogPostDto.Author was typed as -/// the abstract interface IApplicationUser. System.Text.Json -/// cannot materialise an interface without a polymorphic -/// converter, so the "load posts" call from PostIt crashed when -/// the server returned a post with a populated Author -/// object. The fix replaced IApplicationUser with a thin -/// concrete DTO, BlogPostAuthorDto, embedded directly in -/// BlogPostDto.Author. -/// -/// -/// -/// These tests pin the wire shape: a JSON document with an -/// Author object must deserialise without throwing and -/// must round-trip the three fields PostIt exposes in the UI -/// (Id, UserName, Avatar). They are intentionally placed in -/// PostIt.Tests — the client-side assembly — so the -/// regression is caught at the deserialisation boundary, where -/// it actually manifested in production. -/// -/// -public class BlogPostAuthorDtoTests -{ - private static readonly JsonSerializerOptions CaseInsensitiveJson - = new() { PropertyNameCaseInsensitive = true }; - - [Fact] - public void BlogPostDto_deserialises_with_populated_author() - { - // A representative JSON shape the server would emit for - // GET /api/BlogApi. The Author object is fully populated - // — that's the shape that used to break deserialisation - // when Author was typed as the abstract IApplicationUser - // interface. - var json = """ - { - "id": 42, - "title": "Premier billet", - "article": "Contenu", - "photo": null, - "dateCreated": "2026-08-01T12:00:00Z", - "dateModified": "2026-08-02T12:00:00Z", - "userCreated": "alice", - "userModified": "alice", - "authorId": "u-alice", - "isPublished": true, - "author": { - "id": "u-alice", - "userName": "alice", - "avatar": "/avatars/alice.png" - } - } - """; - - var post = JsonSerializer.Deserialize(json, CaseInsensitiveJson); - - Assert.NotNull(post); - Assert.Equal(42, post!.Id); - Assert.Equal("Premier billet", post.Title); - Assert.Equal("u-alice", post.AuthorId); - Assert.True(post.IsPublished); - - // The actual regression coverage: Author must - // materialise as a concrete DTO, not be left null because - // of a JsonException on IApplicationUser. - Assert.NotNull(post.Author); - Assert.Equal("u-alice", post.Author!.Id); - Assert.Equal("alice", post.Author.UserName); - Assert.Equal("/avatars/alice.png", post.Author.Avatar); - } - - [Fact] - public void BlogPostDto_deserialises_when_author_is_null() - { - // The server is allowed to omit Author (the field is - // nullable on the wire — it maps to a navigation - // property that may not have been Included). The client - // must accept that shape without throwing. - var json = """ - { - "id": 7, - "title": "Sans auteur", - "article": null, - "photo": null, - "dateCreated": "2026-08-01T12:00:00Z", - "dateModified": "2026-08-01T12:00:00Z", - "userCreated": "system", - "userModified": "system", - "authorId": "system", - "isPublished": false, - "author": null - } - """; - - var post = JsonSerializer.Deserialize(json, CaseInsensitiveJson); - - Assert.NotNull(post); - Assert.Null(post!.Author); - Assert.Equal("system", post.AuthorId); - } - - [Fact] - public void BlogPostDto_deserialises_when_author_field_is_missing() - { - // Forward-compatibility: an older server that doesn't - // emit the Author field at all. Should not throw. - var json = """ - { - "id": 9, - "title": "Ancien format", - "article": "Pas d'auteur dans la charge utile", - "photo": null, - "dateCreated": "2026-07-01T12:00:00Z", - "dateModified": "2026-07-01T12:00:00Z", - "userCreated": "bob", - "userModified": "bob", - "authorId": "u-bob", - "isPublished": true - } - """; - - var post = JsonSerializer.Deserialize(json, CaseInsensitiveJson); - - Assert.NotNull(post); - Assert.Null(post!.Author); - } - - [Fact] - public void BlogPostAuthorDto_serialises_back_to_expected_json_shape() - { - // Pin the wire shape on the way out too. The server - // builds BlogPostAuthorDto from an ApplicationUser and - // PostIt receives it as JSON; if the field names - // change (e.g. case) the round-trip on the client side - // is what would silently break. - // - // The server emits camelCase (ASP.NET Core's Web - // defaults — PropertyNamingPolicy = CamelCase). We - // mirror that here so the test reflects what the wire - // actually looks like. PropertyNameCaseInsensitive on - // the client deserialiser means we don't have to - // hardcode the casing for the inbound assertions. - var author = new BlogPostAuthorDto - { - Id = "u-alice", - UserName = "alice", - Avatar = "/avatars/alice.png" - }; - - var json = JsonSerializer.Serialize(author, - new JsonSerializerOptions { PropertyNamingPolicy = JsonNamingPolicy.CamelCase }); - - using var doc = JsonDocument.Parse(json); - var root = doc.RootElement; - - Assert.True(root.TryGetProperty("id", out _)); - Assert.True(root.TryGetProperty("userName", out _)); - Assert.True(root.TryGetProperty("avatar", out _)); - } -} diff --git a/src/PostIt/PostIt.Tests/MainPageButtonsTests.cs b/src/PostIt/PostIt.Tests/MainPageButtonsTests.cs deleted file mode 100644 index d1d00532..00000000 --- a/src/PostIt/PostIt.Tests/MainPageButtonsTests.cs +++ /dev/null @@ -1,230 +0,0 @@ -using Avalonia; -using Avalonia.Controls; -using Avalonia.Headless.XUnit; -using CommunityToolkit.Mvvm.Input; -using Microsoft.Extensions.DependencyInjection; -using Yavsc.Api.Client; -using Yavsc.Blogspot; -using PostIt.Services; -using PostIt.ViewModels; -using PostIt.Views; - -namespace PostIt.Tests; - -/// -/// Regression coverage for the three toolbar buttons on -/// that the user reported as inoperative: -/// "ACL", "Mes cercles", and "[DEV] Signature". -/// -/// Pattern (per the Avalonia headless testing docs — -/// TestableApp.Headless.XUnit/CalculatorTests): name every -/// interactive control in the XAML with x:Name="...", then -/// in the test focus the named control and raise the click via -/// window.KeyPressQwerty(PhysicalKey.Enter, ...). This is -/// the supported path — searching the visual tree via -/// GetVisualDescendants().OfType<Button>() for a -/// button by Content text is brittle and was tried first; it does -/// not work reliably when the page is hosted inside an -/// , which wraps the -/// pushed page in an internal container that the visual-tree walk -/// does not always expose under headless. -/// -/// The assertion is on the post-click top of -/// : -/// the user's bug is "I click and the dialog / page never opens", -/// so the test fails when the click doesn't push anything onto the -/// stack. We pin Îł + sniff lĂ©ger — the new top must be a non-null -/// , but we do not yet assert the concrete type -/// (that would require a fully stubbed App.ServiceProvider, -/// which is the next iteration of this suite). -/// -/// Each test exercises the bit that would silently break if -/// the wiring was reverted: -/// -/// "ACL" — click with a selected post pushes a page onto -/// the stack. -/// "Mes cercles" — click pushes a page onto the stack. -/// "[DEV] Signature" — click pushes a page onto the -/// stack. -/// -/// -public class MainPageButtonsTests -{ - /// - /// Fake that throws on any - /// wire call. These tests never invoke a command that hits - /// the API — only the click → nav side of the pipeline is - /// asserted. - /// - private sealed class ThrowingApi : YavscApiClient - { - public ThrowingApi() : base( - new Settings - { - Authentication = new AuthenticationSettings - { - Authority = "https://stub.invalid", - ClientId = "stub", - Scopes = new[] { "openid" }, - }, - }, - new TokenStore(System.IO.Path.GetTempFileName())) - { } - } - - private static MainViewModel MakeViewModel(BlogPostDto? selectedPost = null) - { - var api = new ThrowingApi(); - var blog = new BlogApiClient(api, "http://localhost/"); - var circle = new CircleApiClient(api, "http://localhost/"); - var acl = new BlogAclApiClient(api, "http://localhost/"); - // Minimal DI graph: only what MainPageViewModel resolves - // when the user clicks a navigation button. Today that's - // SignaturePageViewModel / CirclesPageViewModel / ACL - // dependencies. The graph intentionally stays local to this - // suite to avoid side effects from App.BuildServices() (real - // token-store wiring). - var services = new ServiceCollection(); - services.AddSingleton(new Settings()); - services.AddSingleton(circle); - services.AddSingleton(acl); - services.AddTransient(); - services.AddTransient(); - services.AddTransient(); - services.AddTransient(); - services.AddTransient(); - var vm = new MainViewModel(blog, services: services.BuildServiceProvider()); - if (selectedPost is not null) vm.SelectedPost = selectedPost; - return vm; - } - - /// - /// Mount a real (as - /// SessionStatusBannerTests does), push a - /// with the given VM onto - /// NavRoot. PushAsync is awaited (via - /// GetAwaiter().GetResult()) so the page is on the - /// nav stack before the test tries to interact with its - /// named buttons. The window is shown so the visual tree is - /// realised and KeyPressQwerty has a real - /// to dispatch against. - /// - private static (MainView window, MainPage page) MountMainPage(MainViewModel vm) - { - var window = new MainView(); - var page = new MainPage { DataContext = vm }; - var app = (PostIt.App)Application.Current!; - app.AttachMainWindow(window); - window.NavRoot.PushAsync(page).GetAwaiter().GetResult(); - return (window, page); - } - - /// - /// Click a button by focusing it and pressing Enter — the - /// supported headless pattern (cf. CalculatorTests in the - /// Avalonia.Samples repo). Returns the nav-stack count - /// before the click so the caller can assert on the delta. - /// KeyPressQwerty is dispatched on the - /// itself — it is the that owns the - /// headless implementation, and routing the key through any - /// descendant TopLevel (e.g. one obtained via - /// TopLevel.GetTopLevel(button)) fails with a - /// NullReferenceException from the headless impl - /// because the descendant does not carry the - /// PlatformHandle the harness expects. - /// - private static int ClickAndCapture(MainView window, Button button) - { - var stackBefore = window.NavRoot.NavigationStack.Count; - button.Command?.Execute(button.CommandParameter); - if (button.Command is IAsyncRelayCommand asyncCommand) - { - asyncCommand.ExecutionTask?.GetAwaiter().GetResult(); - } - return stackBefore; - } - - [AvaloniaFact] - public void Acl_button_click_pushes_a_page_onto_nav_stack() - { - // Arrange: a VM whose SelectedPost is non-null so - // CanManageAcl evaluates to true and the button is - // armed. - var post = new BlogPostDto - { - Id = 42, - Title = "An existing post", - AuthorId = "u-alice" - }; - var vm = MakeViewModel(post); - var (window, page) = MountMainPage(vm); - - // Sanity: the button's command is bound and CanExecute - // is true. If this fails, the bug is upstream (XAML - // binding) and the rest of the test is moot. - var aclButton = page.ManageAclButton; - Assert.NotNull(aclButton.Command); - Assert.True(aclButton.Command.CanExecute(null)); - - // Act - var stackBefore = ClickAndCapture(window, aclButton); - - // Assert Îł + sniff lĂ©ger: stack grew, new top is a Page. - Assert.True(window.NavRoot.NavigationStack.Count > stackBefore, - $"Click on ACL must push a new page onto the nav stack. Stack size before: {stackBefore}, after: {window.NavRoot.NavigationStack.Count}."); - var pushed = window.NavRoot.NavigationStack.Last(); - Assert.NotNull(pushed); - Assert.IsAssignableFrom(pushed); - } - - [AvaloniaFact] - public void Circles_button_click_pushes_a_page_onto_nav_stack() - { - // Arrange: OpenCircles has no CanExecute guard today — - // any click should fire it and push the page. - var vm = MakeViewModel(); - var (window, page) = MountMainPage(vm); - - var circlesButton = page.OpenCirclesButton; - Assert.NotNull(circlesButton.Command); - - // Act - var stackBefore = ClickAndCapture(window, circlesButton); - - // Assert - Assert.True(window.NavRoot.NavigationStack.Count > stackBefore, - "Click on 'Mes cercles' must push a new page onto the nav stack."); - var pushed = window.NavRoot.NavigationStack.Last(); - Assert.NotNull(pushed); - Assert.IsAssignableFrom(pushed); - } - - [AvaloniaFact] - public void Signature_dev_button_click_pushes_a_page_onto_nav_stack() - { - // Arrange: the "[DEV] Signature" button is bound to the - // MainPageViewModel.OpenSignatureDevCommand [RelayCommand]. - // The click must push SignaturePage on top of NavRoot. - // The ServiceCollection registered in MakeViewModel provides - // SignaturePageViewModel so the command can resolve it via - // DI and call App.PushPage; the ViewLocator - // then maps SignaturePageViewModel -> SignaturePage and - // the binding pushes the page. - var vm = MakeViewModel(); - var (window, page) = MountMainPage(vm); - - var signatureButton = page.OpenSignatureDevButton; - Assert.NotNull(signatureButton.Command); - Assert.True(signatureButton.Command.CanExecute(null)); - - // Act - var stackBefore = ClickAndCapture(window, signatureButton); - - // Assert - Assert.True(window.NavRoot.NavigationStack.Count > stackBefore, - "Click on '[DEV] Signature' must push a new page onto the nav stack."); - var pushed = window.NavRoot.NavigationStack.Last(); - Assert.NotNull(pushed); - Assert.IsAssignableFrom(pushed); - } -} diff --git a/src/PostIt/PostIt.Tests/MainPageSaveTests.cs b/src/PostIt/PostIt.Tests/MainPageSaveTests.cs deleted file mode 100644 index 5baae658..00000000 --- a/src/PostIt/PostIt.Tests/MainPageSaveTests.cs +++ /dev/null @@ -1,88 +0,0 @@ -using Avalonia.Controls; -using Avalonia.Headless.XUnit; -using Avalonia.VisualTree; -using Yavsc.Blogspot; -using Yavsc.Api.Client; -using PostIt.ViewModels; -using PostIt.Views; -namespace PostIt.Tests; - -/// -/// Headless UI tests for the "Save" flow in . -/// The pattern is the one SessionStatusBannerTests -/// established: [AvaloniaFact], a -/// hosting the page (via a because -/// MainPage is a ContentPage), then drive the -/// controls through their public surface and assert on what -/// saw go on the wire. -/// -/// The bug we are pinning: the title TextBox is -/// currently {Binding SelectedPost.Title, Mode=TwoWay}. -/// When SelectedPost is null (i.e. the user has not yet -/// clicked an item in the posts list — which is the only state -/// in which a brand-new post can be created), the binding has -/// no target and the user's keystrokes are silently dropped. -/// Clicking "Save" then routes to the VM branch -/// if (SelectedPost is null) { new BlogPostDto { Title = string.Empty, ... } } -/// which the controller rejects with 400 "The Title field is -/// required." This test fails on that branch today and will -/// pass once the VM owns a dedicated Title/Article -/// buffer that the XAML binds to and the Save command consumes. -/// -public class MainPageSaveTests -{ - [AvaloniaFact] - public async Task Typing_a_title_then_clicking_Save_sends_that_title_in_the_post_body() - { - // Arrange: VM with a recording API client, mounted in a - // headless window via a Frame (MainPage is a ContentPage, - // not a Control, so it needs a navigation host). - var recorder = new CallRecorder(); - var api = new RecordingYavscApiClient(recorder); - var blog = new BlogApiClient(api, "http://localhost/"); - var viewModel = new MainViewModel(blog); - - var page = new MainPage { DataContext = viewModel }; - // MainPage is a ContentPage (a Page, not a Control), so it - // must be hosted in a navigation surface. The production - // MainWindow.axaml uses NavigationPage, and the API is the - // same one App.axaml.cs drives at boot (PushAsync, fire- - // and-forget in prod because the page is the top of the - // stack immediately). - var nav = new NavigationPage(); - _ = nav.PushAsync(page); - var window = new Window { Content = nav }; - window.Show(); - - // Act: type a title into the editor's TextBox without - // first selecting a post in the list — the only state in - // which a new post can be created. Then click Save. - var titleBox = window.GetVisualDescendants() - .OfType() - .First(t => t.PlaceholderText == "Title"); - const string typed = "Mon premier billet"; - titleBox.Text = typed; - - var saveButton = window.GetVisualDescendants() - .OfType -public enum OIDCLoginPhase +public enum OidcLoginPhase { /// No login in flight (or login has settled). Idle, diff --git a/src/PostIt/PostIt/Services/Platform.cs b/src/PostIt/PostIt/Services/Platform.cs index 8e5f7e25..258cd5b5 100644 --- a/src/PostIt/PostIt/Services/Platform.cs +++ b/src/PostIt/PostIt/Services/Platform.cs @@ -7,8 +7,8 @@ namespace PostIt.Services; /// Authorization Code + PKCE flow. The shared PostIt library does /// not reference any UI framework; platform projects (PostIt.Android, /// PostIt.Desktop, PostIt.Browser) populate this class once at startup so -/// the shared OIDC login path can drive a native browser without taking -/// a hard dependency on any specific UI toolkit. +/// the shared LoginPageViewModel can drive a native browser without +/// taking a hard dependency on any specific UI toolkit. /// public static class Platform { @@ -21,14 +21,14 @@ public static class Platform /// override this property at startup (e.g. PostIt.Android sets /// it to android://postit-signin). /// - public const string RedirectUri = "postit://callback"; + public static string DefaultRedirectUri { get; set; } = "postit://callback"; /// /// Scheme prefix the matches /// against BrowserOptions.EndUrl. Overridable for apps /// that want to register their own scheme. /// - public const string CustomScheme = "postit"; + public static string CustomScheme { get; set; } = "postit"; /// /// Constructs a fresh for the running platform. @@ -37,4 +37,4 @@ public static class Platform /// public static System.Func? CreateBrowser { get; set; } = () => new CustomSchemeBrowser(CustomScheme); -} +} \ No newline at end of file diff --git a/src/PostIt/PostIt/Services/UserDirectory.Desktop.cs b/src/PostIt/PostIt/Services/UserDirectory.Desktop.cs deleted file mode 100644 index c821bb87..00000000 --- a/src/PostIt/PostIt/Services/UserDirectory.Desktop.cs +++ /dev/null @@ -1,52 +0,0 @@ -#if !ANDROID && !IOS -using System; -using System.Collections.Generic; -using System.Linq; -using System.Threading; -using System.Threading.Tasks; -using Yavsc.Api.Client; - -namespace PostIt.Services; - -/// -/// Desktop implementation of . -/// Delegates to the central /api/user-search endpoint -/// via . -/// -/// The desktop has no device-local address book, so the -/// "add to a circle" flow on desktop is Yavsc-users-only. -/// Inviting someone who doesn't have a Yavsc account from -/// desktop is a separate feature (manual email entry + -/// invitation endpoint) and lives outside this interface. -/// -public sealed class UserDirectory : IUserDirectory -{ - private readonly UserSearchClient _client; - - public UserDirectory(UserSearchClient client) - { - _client = client ?? throw new ArgumentNullException(nameof(client)); - } - - public async Task> SearchAsync( - string query, CancellationToken ct = default) - { - // UserSearchClient already short-circuits on empty - // queries, but do it here too so the contract is - // obvious to anyone reading IUserDirectory alone - // without having to chase the client wrapper. - if (string.IsNullOrWhiteSpace(query)) - return Array.Empty(); - - var results = await _client.SearchAsync(query: query, ct: ct).ConfigureAwait(false); - if (results is null) return Array.Empty(); - - return results.Select(u => new UserSummary( - Id: u.Id, - UserName: u.UserName, - FullName: u.FullName, - Avatar: u.Avatar, - Email: u.Email)).ToList(); - } -} -#endif diff --git a/src/PostIt/PostIt/Services/UserDirectory.Mobile.cs b/src/PostIt/PostIt/Services/UserDirectory.Mobile.cs deleted file mode 100644 index 5cba6e4a..00000000 --- a/src/PostIt/PostIt/Services/UserDirectory.Mobile.cs +++ /dev/null @@ -1,49 +0,0 @@ -#if ANDROID || IOS -using System; -using System.Collections.Generic; -using System.Linq; -using System.Threading; -using System.Threading.Tasks; -using Yavsc.Api.Client; - -namespace PostIt.Services; - -/// -/// Mobile implementation of . -/// Same backing as the desktop provider (the central -/// /api/user-search endpoint via -/// ) — mobile devices have the -/// network too, and "add to a circle" needs the same directory -/// regardless of platform. -/// -/// The split exists so a future mobile-only provider -/// (offline cache, device-local mirror of the user's own -/// circles) can be plugged in without touching consumers. -/// -public sealed class UserDirectory : IUserDirectory -{ - private readonly UserSearchClient _client; - - public UserDirectory(UserSearchClient client) - { - _client = client ?? throw new ArgumentNullException(nameof(client)); - } - - public async Task> SearchAsync( - string query, CancellationToken ct = default) - { - if (string.IsNullOrWhiteSpace(query)) - return Array.Empty(); - - var results = await _client.SearchAsync(query: query, ct: ct).ConfigureAwait(false); - if (results is null) return Array.Empty(); - - return results.Select(u => new UserSummary( - Id: u.Id, - UserName: u.UserName, - FullName: u.FullName, - Avatar: u.Avatar, - Email: u.Email)).ToList(); - } -} -#endif diff --git a/src/PostIt/PostIt/Services/YavscApiClient.cs b/src/PostIt/PostIt/Services/YavscApiClient.cs index 726b3f4f..6710ebb8 100644 --- a/src/PostIt/PostIt/Services/YavscApiClient.cs +++ b/src/PostIt/PostIt/Services/YavscApiClient.cs @@ -3,12 +3,11 @@ using System.Net; using System.Net.Http; using System.Net.Http.Headers; using System.Net.Http.Json; +using System.Text; using System.Text.Json; using System.Threading; using System.Threading.Tasks; using IdentityModel.OidcClient; -using PostIt.ViewModels; -using Yavsc.Api.Client; namespace PostIt.Services; @@ -24,16 +23,16 @@ namespace PostIt.Services; /// only refreshes once even if many /// concurrent requests are in flight. /// -public class YavscApiClient : IYavscApiClient, IAsyncDisposable +public class YavscApiClient : IAsyncDisposable { // 60s of slack before the access_token's nominal expiry. Covers // network latency + JWT validation on the server side. private static readonly TimeSpan RefreshSkew = TimeSpan.FromSeconds(60); - public Settings Settings {  get; } + private readonly Settings _settings; private readonly OidcClient _oidc; private readonly TokenStore _store; - public HttpClient Http { get; } + private readonly HttpClient _http; private readonly BearerTokenHandler _bearer; private readonly SemaphoreSlim _refreshGate = new(1, 1); @@ -41,19 +40,24 @@ public class YavscApiClient : IYavscApiClient, IAsyncDisposable public YavscApiClient(Settings settings, TokenStore store, OidcClient? oidc = null) { - Settings = settings; + _settings = settings; _store = store; _oidc = oidc ?? new OidcClient(settings.GetOidcClientOptions()); _bearer = new BearerTokenHandler(this); - Http = new HttpClient(_bearer, disposeHandler: true); + _http = new HttpClient(_bearer, disposeHandler: true) + { + // ApiUrl is e.g. "https://blogs.pschneider.fr/api/v1/" — keep the + // trailing slash so relative paths ("posts") resolve correctly. + BaseAddress = new Uri(settings.ApiUrl) + }; _tokens = store.Load(); } /// /// True if a non-expired access token (or a refreshable bundle) is - /// already in memory. UI uses this to skip the login flow on warm + /// already in memory. UI uses this to skip the LoginPage on warm /// starts. /// public bool HasValidSession @@ -70,9 +74,9 @@ public class YavscApiClient : IYavscApiClient, IAsyncDisposable /// /// The current access token, or null if no session is active. - /// Surfaced so consumers (e.g. HomePage) can mirror it onto - /// their own observable properties and so the OIDC id_token / claims - /// can be shown in the UI. + /// Surfaced so the LoginPageViewModel can mirror it onto its own + /// observable property (and so the OIDC id_token / claims can be + /// shown in the UI). /// public string? CurrentAccessToken => _tokens?.AccessToken; @@ -83,21 +87,23 @@ public class YavscApiClient : IYavscApiClient, IAsyncDisposable /// Optional sink for the discrete phases of /// the flow; the UI uses this to render a debug-friendly status /// (Discovering → OpeningBrowser → AwaitingCallback → ExchangingCode - /// → Success / Error). + /// → Success / Error). The same caller can also rely on + /// for the human + /// text (URLs, error detail). public async Task LoginInteractiveAsync( - IProgress? progress = null, + IProgress? progress = null, CancellationToken ct = default) { - progress?.Report(OIDCLoginPhase.Discovering); + progress?.Report(OidcLoginPhase.Discovering); var browser = Platform.CreateBrowser?.Invoke(); if (browser is null) { - progress?.Report(OIDCLoginPhase.Error); + progress?.Report(OidcLoginPhase.Error); throw new InvalidOperationException("No browser is available on this platform."); } - var client = new OidcClient(Settings.GetOidcClientOptions(browser)); + var client = new OidcClient(_settings.GetOidcClientOptions(browser)); // OidcClient.LoginAsync builds the authorize URL, calls // IBrowser.InvokeAsync (which on desktop hands the user off @@ -108,20 +114,20 @@ public class YavscApiClient : IYavscApiClient, IAsyncDisposable // the moment we ask the browser to open (covers the entire // user-driven window including the AwaitingCallback wait), and // the moment we trade the code for tokens. - progress?.Report(OIDCLoginPhase.OpeningBrowser); + progress?.Report(OidcLoginPhase.OpeningBrowser); var result = await client.LoginAsync(new LoginRequest(), ct).ConfigureAwait(false); if (result.IsError) { - progress?.Report(OIDCLoginPhase.Error); + progress?.Report(OidcLoginPhase.Error); throw new InvalidOperationException($"OIDC login failed: {result.Error}"); } - progress?.Report(OIDCLoginPhase.ExchangingCode); + progress?.Report(OidcLoginPhase.ExchangingCode); if (string.IsNullOrEmpty(result.RefreshToken)) { - progress?.Report(OIDCLoginPhase.Error); + progress?.Report(OidcLoginPhase.Error); throw new InvalidOperationException( "Missing refresh_token — vĂ©rifie le scope 'offline_access'."); } @@ -133,7 +139,7 @@ public class YavscApiClient : IYavscApiClient, IAsyncDisposable IdToken: result.IdentityToken); _store.Save(_tokens); - progress?.Report(OIDCLoginPhase.Success); + progress?.Report(OidcLoginPhase.Success); } /// @@ -146,7 +152,7 @@ public class YavscApiClient : IYavscApiClient, IAsyncDisposable /// phase and returns false so the UI can keep going. /// public async Task TrySilentLoginAsync( - IProgress? progress = null, + IProgress? progress = null, CancellationToken ct = default) { if (!HasValidSession) return false; @@ -155,7 +161,7 @@ public class YavscApiClient : IYavscApiClient, IAsyncDisposable // Access token still has plenty of life — nothing to do. if (_tokens.AccessTokenExpiresAt - DateTimeOffset.UtcNow > RefreshSkew) { - progress?.Report(OIDCLoginPhase.Success); + progress?.Report(OidcLoginPhase.Success); return true; } @@ -166,19 +172,19 @@ public class YavscApiClient : IYavscApiClient, IAsyncDisposable // the user back to the login page. try { - progress?.Report(OIDCLoginPhase.ExchangingCode); + progress?.Report(OidcLoginPhase.ExchangingCode); await ForceRefreshAsync(ct).ConfigureAwait(false); - progress?.Report(OIDCLoginPhase.Success); + progress?.Report(OidcLoginPhase.Success); return true; } catch (RefreshFailedException) { - progress?.Report(OIDCLoginPhase.Idle); + progress?.Report(OidcLoginPhase.Idle); return false; } catch { - progress?.Report(OIDCLoginPhase.Idle); + progress?.Report(OidcLoginPhase.Idle); return false; } } @@ -191,7 +197,7 @@ public class YavscApiClient : IYavscApiClient, IAsyncDisposable CancellationToken ct = default) { using var response = await SendAsync(method, path, body, ct).ConfigureAwait(false); - await EnsureSuccessOrThrowAsync(response, ct).ConfigureAwait(false); + response.EnsureSuccessStatusCode(); var stream = await response.Content.ReadAsStreamAsync(ct).ConfigureAwait(false); var dto = await JsonSerializer.DeserializeAsync(stream, @@ -199,16 +205,6 @@ public class YavscApiClient : IYavscApiClient, IAsyncDisposable return dto!; } - /// - /// Call a JSON endpoint with no request body while still allowing a - /// positional cancellation token argument. - /// - public Task CallAsync( - HttpMethod method, - string path, - CancellationToken ct) - => CallAsync(method, path, body: null, ct); - /// Call an endpoint that returns no useful body (DELETE, etc.). public async Task CallAsync( HttpMethod method, @@ -217,19 +213,9 @@ public class YavscApiClient : IYavscApiClient, IAsyncDisposable CancellationToken ct = default) { using var response = await SendAsync(method, path, body, ct).ConfigureAwait(false); - await EnsureSuccessOrThrowAsync(response, ct).ConfigureAwait(false); + response.EnsureSuccessStatusCode(); } - /// - /// Call an endpoint with no request body while still allowing a - /// positional cancellation token argument. - /// - public Task CallAsync( - HttpMethod method, - string path, - CancellationToken ct) - => CallAsync(method, path, body: null, ct); - private async Task SendAsync( HttpMethod method, string path, object? body, CancellationToken ct) { @@ -241,7 +227,7 @@ public class YavscApiClient : IYavscApiClient, IAsyncDisposable using var req = new HttpRequestMessage(method, path); if (body is not null) req.Content = JsonContent.Create(body); - var response = await Http.SendAsync(req, ct).ConfigureAwait(false); + var response = await _http.SendAsync(req, ct).ConfigureAwait(false); if (response.StatusCode == HttpStatusCode.Unauthorized) { @@ -253,54 +239,12 @@ public class YavscApiClient : IYavscApiClient, IAsyncDisposable using var retry = new HttpRequestMessage(method, path); if (body is not null) retry.Content = JsonContent.Create(body); - response = await Http.SendAsync(retry, ct).ConfigureAwait(false); + response = await _http.SendAsync(retry, ct).ConfigureAwait(false); } return response; } - /// - /// Replaces the bare response.EnsureSuccessStatusCode() - /// call site with one that surfaces the response body in the - /// thrown exception. The default behaviour truncates the - /// diagnostic to "Response status code does not indicate - /// success: 400 (Bad Request)." — useless when the server is - /// an ASP.NET Core action returning a ProblemDetails - /// that names the field that failed ModelState validation. - /// The VM's catch (Exception ex) in - /// MainPageViewModel.ExecuteAsync shows - /// ex.Message on the status bar, so embedding the body - /// here is enough to make the next "click Save" self-explanatory - /// (e.g. "Error: 400 — The Title field is required."). - /// - private static async Task EnsureSuccessOrThrowAsync(HttpResponseMessage response, CancellationToken ct) - { - if (response.IsSuccessStatusCode) return; - - // Read the body before throwing; once the response is - // disposed, the stream is gone. We bound the read to a few - // KB so a hostile server can't make us buffer megabytes - // just to format an error message. - string body = string.Empty; - try - { - var raw = await response.Content.ReadAsStringAsync(ct).ConfigureAwait(false); - if (!string.IsNullOrWhiteSpace(raw)) - { - body = raw.Length > 1024 ? raw[..1024] + "
" : raw; - } - } - catch - { - // Body unreadable: fall back to the default message. - } - - var msg = body.Length > 0 - ? $"{(int)response.StatusCode} {response.ReasonPhrase}: {body}" - : $"{(int)response.StatusCode} {response.ReasonPhrase}"; - throw new HttpRequestException(msg, inner: null, statusCode: response.StatusCode); - } - /// /// Lock the refresh path so concurrent callers don't each rotate /// the refresh token (which Auth0 invalidates on first use). @@ -362,7 +306,7 @@ public class YavscApiClient : IYavscApiClient, IAsyncDisposable public ValueTask DisposeAsync() { - Http.Dispose(); + _http.Dispose(); _refreshGate.Dispose(); return ValueTask.CompletedTask; } diff --git a/src/PostIt/PostIt/Settings/AuthenticationSettings.cs b/src/PostIt/PostIt/Settings/AuthenticationSettings.cs index 9ebeaebd..4547c732 100644 --- a/src/PostIt/PostIt/Settings/AuthenticationSettings.cs +++ b/src/PostIt/PostIt/Settings/AuthenticationSettings.cs @@ -1,28 +1,8 @@ using CommunityToolkit.Mvvm.ComponentModel; using System; -using System.Text.Json.Serialization; public partial class AuthenticationSettings : ObservableObject { - /// - /// Default custom-scheme redirect URI on Desktop. The OS routes the - /// callback to the running PostIt instance via the named-pipe - /// hand-off in - /// (RFC 8252 §7.1). Production Desktop builds use this. - /// - public const string DesktopRedirectUri = "postit://callback"; - - /// - /// Redirect URI used by the Android app. The corresponding IntentFilter - /// in PostIt.Android/Properties/AndroidManifest.xml must match. - /// - public const string AndroidRedirectUri = "android://postit-signin"; - - public static string DefaultAuthority { get; internal set; } = "https://yavsc.pschneider.fr"; - - public static string DefaultClientId { get; internal set; } = "postit"; - - public static string[] DefaultScopes { get; set; } = { "blogs"} ; [ObservableProperty] public partial string Authority { get; set; } @@ -30,100 +10,4 @@ public partial class AuthenticationSettings : ObservableObject [ObservableProperty] public partial string ClientId { get; set; } - - [ObservableProperty] - public partial string[] Scopes { get; set; } - - /// - /// OAuth redirect URI. Defaults to - /// (custom URI scheme) which is the right answer for desktop - /// production builds. Mobile platforms must set this to - /// before calling LoginAsync. - /// - [ObservableProperty] - public partial string RedirectUri { get; set; } -#if ANDROID - = AndroidRedirectUri; -#else - = DesktopRedirectUri; -#endif - - /// - /// Space-separated view of . Exists for the - /// SettingsPage TextBox binding — a string[] does not - /// round-trip through XAML binding to TextBox.Text, so we - /// expose the array as a string here and re-parse on assignment. - /// - /// [JsonIgnore] on purpose: is the - /// persisted shape (matches the on-disk format in - /// postit-settings.json and the runtime contract in - /// ). - /// Writing this property back to disk would duplicate the - /// information and confuse the deserializer. - /// - /// - [JsonIgnore] - [ObservableProperty] - public partial string ScopeListText { get; set; } = string.Empty; - - /// - /// Refresh from so - /// the TextBox shows the current persisted state after a Load(). - /// Called from Settings.ApplyJson on each disk / embedded - /// hydration; the source generator's OnScopesChanged partial - /// below keeps the two in sync in the other direction (edits made - /// in the TextBox). - /// - public void RefreshScopeListText() - { - ScopeListText = Scopes is null ? string.Empty : string.Join(' ', Scopes); - } - - partial void OnScopeListTextChanged(string value) - { - if (Scopes is null) - { - Scopes = Array.Empty(); - } - // Split on any whitespace, drop empties. Matches what - // string.Join(' ', Scopes) produces when Scopes is null-free, - // so a round-trip (Display → Edit → Display) is lossless - // for sane inputs. - var parts = value?.Split( - new[] { ' ', '\t', '\n', '\r' }, - StringSplitOptions.RemoveEmptyEntries) ?? Array.Empty(); - - // Skip the write if the parsed array is equal to the current - // one — avoids a PropertyChanged loop between OnScopesChanged - // and OnScopeListTextChanged when RefreshScopeListText runs. - if (Scopes is not null && Scopes.Length == parts.Length) - { - var same = true; - for (var i = 0; i < parts.Length; i++) - { - if (!string.Equals(Scopes[i], parts[i], StringComparison.Ordinal)) - { - same = false; - break; - } - } - if (same) return; - } - Scopes = parts; - } - - partial void OnScopesChanged(string[] value) - { - // Keep ScopeListText in sync when Scopes is reassigned from - // outside (JSON hydration, MergeScopes, programmatic - // updates). Compute the new value and only fire if it - // differs from what's already shown, otherwise the TextBox - // would briefly flicker / re-set the caret on every load. - var newText = value is null ? string.Empty : string.Join(' ', value); - if (!string.Equals(ScopeListText, newText, StringComparison.Ordinal)) - { - ScopeListText = newText; - } - } - -} +} \ No newline at end of file diff --git a/src/PostIt/PostIt/Settings/Settings.cs b/src/PostIt/PostIt/Settings/Settings.cs new file mode 100644 index 00000000..d69188b6 --- /dev/null +++ b/src/PostIt/PostIt/Settings/Settings.cs @@ -0,0 +1,207 @@ +using System.Runtime.CompilerServices; +using Avalonia; +using Avalonia.Controls; +using Avalonia.Platform.Storage; +using CommunityToolkit.Mvvm.ComponentModel; +using IdentityModel.OidcClient; +using PostIt.Services; +using System; +using System.IO; +using System.Text.Json; + +[assembly: InternalsVisibleTo("PostIt.Tests")] + +namespace PostIt; + +public partial class Settings : ObservableObject +{ + const string SettingsFileName = "postit-settings.json"; + IStorageFolder? folder = null; + + /// + /// Legacy loopback redirect URI. The post-2026.6 production flow + /// uses the custom URI scheme ( + /// on desktop, on Android) so the + /// OS hands the callback to the running instance without a TCP + /// listener. The loopback constant stays here so test fixtures + /// (which spin up an in-process OidcStubAuthority) keep working, + /// but it is no longer used as a default anywhere in production. + /// If you are still pointing your production postit-settings.json + /// at this URI, switch to postit://callback and remove the + /// matching entry from the Yavsc.Org server's allowed redirect URIs. + /// + public const string DefaultLoopbackRedirectUri = "http://127.0.0.1:7890/"; + + /// + /// Redirect URI used by the Android app. The corresponding IntentFilter + /// in PostIt.Android/Properties/AndroidManifest.xml must match. + /// + public const string AndroidRedirectUri = "android://postit-signin"; + + /// + /// Default custom-scheme redirect URI on Desktop. The OS routes the + /// callback to the running PostIt instance via the named-pipe + /// hand-off in + /// (RFC 8252 §7.1). Production Desktop builds use this. + /// + public const string DefaultDesktopRedirectUri = "postit://callback"; + + [ObservableProperty] + public partial AuthenticationSettings Authentication { get; set; } = new(); + + [ObservableProperty] + public partial bool DarkMode { get; set; } = false; + + [ObservableProperty] + public partial string ApiUrl { get; set; } = "https://blogs.pschneider.fr/api/v1/"; + + /// + /// OAuth redirect URI. Defaults to + /// (custom URI scheme) which is the right answer for desktop + /// production builds. Mobile platforms must set this to + /// before calling LoginAsync. + /// + [ObservableProperty] + public partial string RedirectUri { get; set; } = DefaultDesktopRedirectUri; + + + [ObservableProperty] + public partial string[] Scopes { get; set; } + public bool Loaded { get; private set; } = false; + + /// + /// Build OidcClient options configured for Authorization Code + PKCE + /// (no client secret). The browser implementation should be supplied + /// per-platform by the caller. + /// + internal OidcClientOptions GetOidcClientOptions(IdentityModel.OidcClient.Browser.IBrowser? browser = null) + { + if (!Loaded) Load(); + var options = new OidcClientOptions + { + Authority = Authentication.Authority, + ClientId = Authentication.ClientId, + RedirectUri = RedirectUri, + Scope = string.Join(' ', this.Scopes), + TokenClientCredentialStyle = IdentityModel.Client.ClientCredentialStyle.PostBody, + PostLogoutRedirectUri = "https//yavsc.pschneider.fr", + // PKCE is enabled by default when no client_secret is provided. + }; + + if (browser is not null) + options.Browser = browser; + + return options; + } + + internal void Load() + { + if (Loaded) return; + + // Trust an already-populated Authority: tests pre-fill Settings + // with the OIDC stub's random loopback port, and programmatic + // callers (CLI flags, integration tests) wire their own. If we + // fall through to the disk / embedded read here we'd silently + // overwrite their value with the bundled default + // (yavsc.pschneider.fr), break the stubbed discovery URL, and + // turn a passing login into an invalid_grant. + if (!string.IsNullOrWhiteSpace(Authentication?.Authority)) + { + Loaded = true; + return; + } + + string configDir = Path.Combine( + Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), + "PostIt" +); + Directory.CreateDirectory(configDir); + + string configPath = Path.Combine(configDir, SettingsFileName); + + FileInfo configFileInfo = new FileInfo(configPath); + + if (!configFileInfo.Exists) + { + Console.Error.WriteLine($"đŸ©Ž Settings file not found at {configFileInfo.FullName}"); + // No user-level config: fall back to the embedded default. + // We only get here when Authentication.Authority is empty + // (the early-return above) so the redundant guard is gone. + if (!TryLoadEmbeddedFallback()) + { + Console.Error.WriteLine("đŸ©Ž No embedded default settings; running with empty configuration."); + } + return; + } + + Console.WriteLine($"🔎 Loading settings from {configFileInfo.FullName}"); + + try + { + // Synchronous read on purpose: Settings.Load() is called from + // synchronous startup paths (App.axaml.cs, ViewModel ctors, + // tests) and bridging to async here with .Wait() / .GetAwaiter() + // .GetResult() deadlocks the Avalonia UI thread because the + // continuation can't resume on the same thread. The settings + // file is a few KiB at most; async I/O gains nothing here. + using var stream = configFileInfo.OpenRead(); + using var reader = new StreamReader(stream); + var json = reader.ReadToEnd(); + ApplyJson(json, $"user file {configFileInfo.FullName}"); + Loaded = true; + } + catch (Exception ex) + { + Console.Error.WriteLine($"đŸ©Ž Error loading settings: {ex.Message}"); + } + } + + private bool TryLoadEmbeddedFallback() + { + const string ResourceName = "PostIt.postit-settings.json"; + var assembly = typeof(Settings).Assembly; + using var stream = assembly.GetManifestResourceStream(ResourceName); + if (stream is null) + { + Console.Error.WriteLine($"đŸ©Ž Embedded resource {ResourceName} not found."); + return false; + } + using var reader = new StreamReader(stream); + var json = reader.ReadToEnd(); + if (string.IsNullOrWhiteSpace(json)) + { + Console.Error.WriteLine("đŸ©Ž Embedded settings resource is empty."); + return false; + } + Console.WriteLine($"🔎 Loading embedded default settings ({ResourceName})."); + ApplyJson(json, $"embedded resource {ResourceName}"); + return true; + } + + private void ApplyJson(string json, string source) + { + if (string.IsNullOrWhiteSpace(json)) + { + Console.Error.WriteLine($"đŸ©Ž Settings payload is empty (source: {source})."); + return; + } + try + { + var settings = JsonSerializer.Deserialize(json); + if (settings is null) + { + Console.Error.WriteLine($"đŸ©Ž Settings payload is invalid (source: {source})."); + return; + } + this.Authentication = settings.Authentication; + this.DarkMode = settings.DarkMode; + this.ApiUrl = settings.ApiUrl; + this.RedirectUri = string.IsNullOrWhiteSpace(settings.RedirectUri) ? DefaultDesktopRedirectUri : settings.RedirectUri; + this.Scopes = settings.Scopes; + } + catch (Exception ex) + { + Console.Error.WriteLine($"đŸ©Ž Error applying settings from {source}: {ex.Message}"); + } + } +} diff --git a/src/PostIt/PostIt/ViewLocator.cs b/src/PostIt/PostIt/ViewLocator.cs index 3543a9c9..9a05aa84 100644 --- a/src/PostIt/PostIt/ViewLocator.cs +++ b/src/PostIt/PostIt/ViewLocator.cs @@ -11,42 +11,27 @@ namespace PostIt; /// /// Given a view model, returns the corresponding view if possible. /// -[RequiresUnreferencedCode( - "Default implementation of ViewLocator involves reflection which may be trimmed away.", - Url = "https://docs.avaloniaui.net/docs/concepts/view-locator")] + public class ViewLocator : IDataTemplate { + private readonly IServiceProvider _services; - public Control Build(object? data) + public ViewLocator(IServiceProvider services) { - try - { - return BuildCore(data); - } - catch (Exception ex) - { - return new TextBlock { Text = $"ViewLocator threw: {ex}" }; - } + _services = services; } - - private Control BuildCore(object? data) + public Control Build(object data) { - var app = App.Current as App; - var services = app!.ServiceProvider!; return data switch { - MainViewModel => services.GetRequiredService(), - Settings => services.GetRequiredService(), - HomePageViewModel => services.GetRequiredService(), - SignaturePageViewModel => services.GetRequiredService(), - AddCircleMemberDialogViewModel => services.GetRequiredService(), - CirclesPageViewModel => services.GetRequiredService(), - PostAclDialogViewModel => services.GetRequiredService(), - null => new TextBlock { Text = "No view for " }, - _ => new TextBlock { Text = $"No view for {data.GetType().Name}" } + MainPageViewModel => _services.GetRequiredService(), + SettingsPageViewModel => _services.GetRequiredService(), + LoginPageViewModel => _services.GetRequiredService(), + HomePageViewModel => _services.GetRequiredService(), + _ => new TextBlock { Text = $"No view for {data.GetType().Name}" } }; } - public bool Match(object? data) => data is ViewModelBase; + public bool Match(object data) => data is ViewModelBase; } diff --git a/src/PostIt/PostIt/ViewModels/AddCircleMemberDialogViewModel.cs b/src/PostIt/PostIt/ViewModels/AddCircleMemberDialogViewModel.cs deleted file mode 100644 index 88d01335..00000000 --- a/src/PostIt/PostIt/ViewModels/AddCircleMemberDialogViewModel.cs +++ /dev/null @@ -1,127 +0,0 @@ -using System; -using System.Collections.ObjectModel; -using System.Threading; -using System.Threading.Tasks; -using CommunityToolkit.Mvvm.ComponentModel; -using CommunityToolkit.Mvvm.Input; -using PostIt.Services; -using Yavsc.Api.Client; - -namespace PostIt.ViewModels; - -/// -/// View model for the "add a Yavsc user to a circle" modal. -/// -/// Resolves users through -/// (which delegates to /api/user-search); the caller -/// (CirclesPage) decides whether to add the picked user to -/// the circle by calling -/// -/// (which is bound to the dialog's "Ajouter" button). -/// -/// The dialog itself doesn't know the target -/// CircleId: that's set by the caller via the -/// constructor and the dialog only triggers -/// against the -/// string. The "Add" command -/// returns the picked via the -/// event, and the hosting -/// CirclesPage then calls -/// . -/// -public partial class AddCircleMemberDialogViewModel : ViewModelBase -{ - private readonly IUserDirectory _directory; - - [ObservableProperty] - public partial string SearchQuery { get; set; } = string.Empty; - - [ObservableProperty] - public partial ObservableCollection Results { get; set; } = new(); - - [ObservableProperty] - public partial UserSummary? Selected { get; set; } - - [ObservableProperty] - public partial bool IsBusy { get; set; } - - [ObservableProperty] - public partial string StatusMessage { get; set; } = string.Empty; - - /// - /// Raised when the user confirms a selection. The hosting - /// CirclesPage subscribes to this event and calls - /// CircleApiClient.AddMemberAsync with the target - /// circle id + the picked user's id. The dialog itself - /// does not know the circle id by design: separation of - /// concerns — the modal is a user picker, not a - /// "circle joiner" form. - /// - public event EventHandler? Confirmed; - - public AddCircleMemberDialogViewModel(IUserDirectory directory) - { - _directory = directory ?? throw new ArgumentNullException(nameof(directory)); - } - - public override bool CanNavigateNext { get => throw new NotImplementedException(); protected set => throw new NotImplementedException(); } - public override bool CanNavigatePrevious { get => throw new NotImplementedException(); protected set => throw new NotImplementedException(); } - - /// - /// Search the directory for users matching the current - /// . Triggered explicitly via the - /// "Rechercher" button — no debouncing, so the caller - /// stays in control of how often the network is hit. - /// - [RelayCommand] - public async Task SearchAsync() - { - if (string.IsNullOrWhiteSpace(SearchQuery)) - { - Results.Clear(); - StatusMessage = "Tapez un nom ou un email"; - return; - } - - IsBusy = true; - try - { - var hits = await _directory.SearchAsync(SearchQuery, CancellationToken.None).ConfigureAwait(true); - Results = new ObservableCollection(hits ?? Array.Empty()); - StatusMessage = $"{Results.Count} rĂ©sultat(s)"; - } - catch (Exception ex) - { - StatusMessage = $"Erreur: {ex.Message}"; - } - finally - { - IsBusy = false; - } - } - - /// - /// Raise for the currently selected - /// user. No-op when no selection has been made — keeps the - /// UI from firing an event with a null payload. - /// - [RelayCommand] - public async Task AddAsync() - { - if (Selected is null) - { - StatusMessage = "SĂ©lectionnez un utilisateur"; - return; - } - Confirmed?.Invoke(this, Selected); - var app = App.Current as App; - await app.GoBackAsync(); - } - - [RelayCommand] - public async Task CloseAsync() - { - var app = App.Current as App; - await app.GoBackAsync(); - } -} diff --git a/src/PostIt/PostIt/ViewModels/CirclesPageViewModel.cs b/src/PostIt/PostIt/ViewModels/CirclesPageViewModel.cs deleted file mode 100644 index 9cee3ea8..00000000 --- a/src/PostIt/PostIt/ViewModels/CirclesPageViewModel.cs +++ /dev/null @@ -1,311 +0,0 @@ -using System; -using System.Collections.ObjectModel; -using System.Threading.Tasks; -using Avalonia; -using CommunityToolkit.Mvvm.ComponentModel; -using CommunityToolkit.Mvvm.Input; -using Microsoft.Extensions.DependencyInjection; -using PostIt.Helpers; -using PostIt.Services; -using Yavsc.Api.Client; -using Yavsc.Api.Client.Dtos; - -namespace PostIt.ViewModels; - -/// -/// View model for the "Mes cercles" page. CRUD on the caller's own -/// circles (the server scopes every endpoint to the caller's uid -/// since the BlogAcl fix on this branch), plus membership -/// management on the currently selected circle. -/// -/// The view lists circles in , supports -/// create / edit via , and exposes -/// per-item Delete and per-item edit commands. -/// drives a progress overlay during API calls; -/// surfaces success / error feedback in the view footer. -/// -/// When the user selects a circle in the list, -/// fetches its members into -/// . The "Add a member" command -/// () is a UI event the view -/// raises to open AddCircleMemberDialog; the dialog -/// raises a Confirmed event back, which the page's -/// code-behind forwards here via -/// . The "remove" -/// command is per-row and runs inline. -/// -public partial class CirclesPageViewModel : ViewModelBase -{ - private readonly CircleApiClient _client; - - [ObservableProperty] - public partial ObservableCollection Circles { get; set; } = new(); - - [ObservableProperty] - public partial CircleDto? SelectedCircle { get; set; } - - /// Editor buffer for the new / edited circle's name. - [ObservableProperty] - public partial string DraftName { get; set; } = string.Empty; - - /// Editor buffer for the new / edited circle's visibility flag. - [ObservableProperty] - public partial bool DraftPublic { get; set; } - - /// Members of the currently selected circle. Empty - /// when no circle is selected or after a refresh that - /// produced an empty list. Updated by - /// . - [ObservableProperty] - public partial ObservableCollection Members { get; set; } = new(); - - [ObservableProperty] - public partial bool IsBusy { get; set; } - - [ObservableProperty] - public partial string StatusMessage { get; set; } = string.Empty; - - - public CirclesPageViewModel(CircleApiClient client) - { - _client = client ?? throw new ArgumentNullException(nameof(client)); - } - - public override bool CanNavigateNext { get => throw new NotImplementedException(); protected set => throw new NotImplementedException(); } - public override bool CanNavigatePrevious { get => throw new NotImplementedException(); protected set => throw new NotImplementedException(); } - - /// - /// Partial property setter: when the selected circle - /// changes, refresh the members list. The setter is - /// invoked by the [ObservableProperty] source generator - /// for both user selections and programmatic resets. - /// - partial void OnSelectedCircleChanged(CircleDto? value) - { - Members = new ObservableCollection(); - if (value is not null) - { - // Fire-and-forget: load members in the background. - // Errors are routed to StatusMessage inside - // LoadMembersAsync. - _ = LoadMembersAsync(value.Id); - } - } - - [RelayCommand] - public async Task RefreshAsync() - { - IsBusy = true; - try - { - var list = await _client.GetMyCirclesAsync(); - Circles = new ObservableCollection(list ?? new()); - StatusMessage = $"{Circles.Count} cercle(s)"; - } - catch (Exception ex) - { - StatusMessage = $"Erreur: {ex.Message}"; - } - finally - { - IsBusy = false; - } - } - - [RelayCommand] - internal async Task OpenAddMemberAsync() - { - var app = Application.Current as App; - var services = app?.ServiceProvider; - var directory = services.GetRequiredService(); - AddCircleMemberDialogViewModel model = - new AddCircleMemberDialogViewModel(directory); - // Wire the dialog's Confirmed event to OnAddMemberConfirmedAsync. - // Without this, the dialog's "Ajouter" button fires the event - // into the void: no subscriber, the picked user is silently - // dropped, and nothing is added to the circle. The dialog - // stays open until the user uses the back gesture — which is - // how the user noticed the button was a no-op. - // Async-void is intentional here: Confirmed is an - // EventHandler (returns void), and bridging to the - // async Task OnAddMemberConfirmedAsync requires it. - model.Confirmed += async (_, picked) => - await OnAddMemberConfirmedAsync(_, picked); - await app.PushPageAsync(model); - } - /// - /// Load the members of one of the caller's circles. The - /// server scopes the endpoint with a 404 when the circle - /// doesn't belong to the caller (mirroring the rest of the - /// circle API); that case flattens to an empty list here. - /// - [RelayCommand] - public async Task LoadMembersAsync(long circleId) - { - IsBusy = true; - try - { - var list = await _client.GetMembersAsync(circleId); - Members = new ObservableCollection(list ?? new()); - StatusMessage = $"{Members.Count} membre(s)"; - } - catch (Exception ex) - { - StatusMessage = $"Erreur: {ex.Message}"; - Members = new ObservableCollection(); - } - finally - { - IsBusy = false; - } - } - - [RelayCommand] - public void StartCreate() - { - SelectedCircle = null; - DraftName = string.Empty; - DraftPublic = false; - StatusMessage = "Nouveau cercle"; - } - - [RelayCommand] - public void StartEdit(CircleDto? circle) - { - if (circle is null) return; - SelectedCircle = circle; - DraftName = circle.Name; - DraftPublic = circle.Public; - StatusMessage = $"Édition de « {circle.Name} »"; - } - - [RelayCommand] - public async Task SaveAsync() - { - if (string.IsNullOrWhiteSpace(DraftName)) - { - StatusMessage = "Le nom est obligatoire"; - return; - } - - IsBusy = true; - try - { - if (SelectedCircle is null) - { - var created = await _client.CreateCircleAsync(new CircleDto - { - Name = DraftName.Trim(), - Public = DraftPublic, - }); - StatusMessage = created is null - ? "CrĂ©ation Ă©chouĂ©e" - : $"Cercle « {created.Name} » créé"; - } - else - { - SelectedCircle.Name = DraftName.Trim(); - SelectedCircle.Public = DraftPublic; - await _client.UpdateCircleAsync(SelectedCircle.Id, SelectedCircle); - StatusMessage = $"Cercle « {SelectedCircle.Name} » mis Ă  jour"; - } - await RefreshAsync(); - } - catch (Exception ex) - { - StatusMessage = $"Erreur: {ex.Message}"; - } - finally - { - IsBusy = false; - } - } - - [RelayCommand] - public async Task DeleteAsync(CircleDto? circle) - { - if (circle is null) return; - IsBusy = true; - try - { - await _client.DeleteCircleAsync(circle.Id); - StatusMessage = $"Cercle « {circle.Name} » supprimĂ©"; - // If the deleted circle was the selected one, - // clear the selection so the Members view goes - // empty too (the partial setter on - // SelectedCircle will reset Members). - if (SelectedCircle?.Id == circle.Id) - SelectedCircle = null; - await RefreshAsync(); - } - catch (Exception ex) - { - StatusMessage = $"Erreur: {ex.Message}"; - } - finally - { - IsBusy = false; - } - } - - - /// - /// Called by the view when the dialog confirms a - /// selection. Adds the picked user to the currently - /// selected circle and refreshes the members list. - /// - public async Task OnAddMemberConfirmedAsync(object? sender, UserSummary picked) - { - if (SelectedCircle is null || picked is null) return; - IsBusy = true; - try - { - await _client.AddMemberAsync(SelectedCircle.Id, picked.Id); - StatusMessage = $"« {picked.DisplayName} » ajoutĂ© au cercle"; - await LoadMembersAsync(SelectedCircle.Id); - } - catch (Exception ex) - { - // 409 (already a member) is a likely race — surface - // it as a friendly status, not an error. The - // server returns 409 for "already a member"; - // YavscApiClient surfaces that as an exception - // today; future refactors could route 409 into a - // typed result, but for now the message string is - // distinctive enough. - var msg = ex.Message.Contains("409") || ex.Message.Contains("Conflict") - ? "DĂ©jĂ  membre du cercle" - : $"Erreur: {ex.Message}"; - StatusMessage = msg; - } - finally - { - IsBusy = false; - } - } - - /// - /// Per-row "remove" command. Updates the local - /// collection in place so the UI doesn't flash. - /// - [RelayCommand] - public async Task RemoveMemberAsync(CircleMemberDto? member) - { - if (member is null || SelectedCircle is null) return; - IsBusy = true; - try - { - await _client.RemoveMemberAsync(SelectedCircle.Id, member.Id); - Members.Remove(member); - StatusMessage = $"« {member.UserName} » retirĂ© du cercle"; - } - catch (Exception ex) - { - StatusMessage = $"Erreur: {ex.Message}"; - } - finally - { - IsBusy = false; - } - } -} diff --git a/src/PostIt/PostIt/ViewModels/HomePageViewModel.cs b/src/PostIt/PostIt/ViewModels/HomePageViewModel.cs index 5d727729..e8e76a30 100644 --- a/src/PostIt/PostIt/ViewModels/HomePageViewModel.cs +++ b/src/PostIt/PostIt/ViewModels/HomePageViewModel.cs @@ -1,12 +1,11 @@ -using CommunityToolkit.Mvvm.Input; +using PostIt; using PostIt.Services; -namespace PostIt.ViewModels; +using PostIt.ViewModels; public class HomePageViewModel : ViewModelBase { public YavscApiClient Api { get; } public Settings Settings { get; } - public SessionStatusViewModel SessionStatus { get; } private string _welcomeText = "Welcome to PostIt!"; public string WelcomeText @@ -18,25 +17,12 @@ public class HomePageViewModel : ViewModelBase public override bool CanNavigateNext { get => true; protected set => throw new System.NotImplementedException(); } public override bool CanNavigatePrevious { get => false; protected set => throw new System.NotImplementedException(); } - public HomePageViewModel(YavscApiClient api, Settings settings, SessionStatusViewModel sessionStatus) + public HomePageViewModel(YavscApiClient api, Settings settings) { Api = api; Settings = settings; - SessionStatus = sessionStatus; - } - public RelayCommand OpenBlogs { get; set; } = new RelayCommand(() => App.PushMainPageAsync()); - /// - /// Avalonia designer constructor. Builds a self-contained VM - /// with a freshly-constructed Settings so the XAML preview can - /// render without a running App. Production paths always reach - /// the parameterised constructor (DI or direct injection), and - /// the postit://callback crash is fixed at the Settings layer - /// (thread-safe dispatcher marshalling on PropertyChanged) — a - /// designer-only duplicate instance is therefore harmless. - /// - public HomePageViewModel() : this(null!, new Settings(), new SessionStatusViewModel()) - { - } + // Constructeur sans arg pour le designer Avalonia + public HomePageViewModel() : this(null!, null!) { } } diff --git a/src/PostIt/PostIt/ViewModels/LoginPageViewModel.cs b/src/PostIt/PostIt/ViewModels/LoginPageViewModel.cs new file mode 100644 index 00000000..5c847beb --- /dev/null +++ b/src/PostIt/PostIt/ViewModels/LoginPageViewModel.cs @@ -0,0 +1,327 @@ +using System; +using System.IO; +using System.Threading.Tasks; +using CommunityToolkit.Mvvm.Input; +using IdentityModel.OidcClient.Browser; +using PostIt.Services; + +namespace PostIt.ViewModels; + +public partial class LoginPageViewModel : ViewModelBase +{ + private const string SettingsFileName = "postit-settings.json"; + + [Obsolete("Password grant is not used; IdentityModel.OidcClient performs PKCE.")] + public string Password { get; set; } = string.Empty; + + [Obsolete("User-entered email is not used; the IdP login UI collects it.")] + public string UserEmail { get; set; } = string.Empty; + + [Obsolete("No local credential persistence in the current build.")] + public bool RememberMe { get; set; } + + /// + /// URL of the Yavsc.Org account-registration page. + /// Derived from 's Authority. + /// Empty when the authority is not configured. + /// + public string RegisterUrl => + BuildExternalUrl("/Account/Register"); + + /// + /// URL of the Yavsc.Org password-reset page (open to anonymous users). + /// Derived from 's Authority. + /// Empty when the authority is not configured. + /// + public string ForgotPasswordUrl => + BuildExternalUrl("/Account/ForgotPassword"); + + public bool HasRegisterUrl => !string.IsNullOrEmpty(RegisterUrl); + public bool HasForgotPasswordUrl => !string.IsNullOrEmpty(ForgotPasswordUrl); + + /// + /// Canonical authority with any trailing + /// slash removed. Used as the base for both the OIDC discovery URL and the + /// human-facing Account URLs (Register / Forgot password). Empty when the + /// authority is not configured. + /// + public string ExternalUrl => BuildExternalUrl(string.Empty); + + /// + /// OIDC discovery URL the client actually calls during login: + /// ExternalUrl + "/.well-known/openid-configuration". Surfaced in + /// on failure so the operator can copy it + /// verbatim and verify reachability from a browser. + /// + public string DiscoveryUrl => + string.IsNullOrEmpty(ExternalUrl) ? string.Empty : ExternalUrl + "/.well-known/openid-configuration"; + + /// + /// True when the settings file is missing or Authentication.Authority + /// is empty. The LoginPage surfaces a banner in that case and disables + /// the Register / Forgot password buttons. + /// + public bool ConfigMissing => + string.IsNullOrWhiteSpace(Settings.Authentication?.Authority); + + /// + /// Localised banner shown when is true. + /// The path follows the XDG spec on Linux (where PostIt.Desktop runs): + /// the file is expected at ~/.config/PostIt/postit-settings.json. + /// + public string ConfigMissingMessage => + $"Configuration PostIt manquante — voir ~/.config/PostIt/postit-settings.json"; + + private string BuildExternalUrl(string path) + { + var authority = Settings.Authentication?.Authority?.TrimEnd('/'); + return string.IsNullOrEmpty(authority) + ? string.Empty + : authority + path; + } + + /// + /// The access token of the most recent successful login, or null. + /// Kept on the VM so views can show "logged in as 
" feedback; the + /// authoritative copy lives in the . + /// + private string? _accessToken; + public string? AccessToken + { + get => _accessToken; + private set => this.SetProperty(ref _accessToken, value); + } + + public override bool CanNavigateNext { get => false; protected set => throw new NotImplementedException(); } + public override bool CanNavigatePrevious { get => true; protected set => throw new NotImplementedException(); } + + public Settings Settings { get; } + + /// + /// Discrete phase of the OIDC flow the LoginPage is currently + /// showing. Surfaced in the UI as a one-line status (Discovering / + /// OpeningBrowser / AwaitingCallback / ExchangingCode / Success / + /// Error). Operators use this to debug the custom-scheme + /// callback hand-off: when AwaitingCallback never resolves, + /// the OS never re-launched PostIt with the postit:// URL. + /// + private OidcLoginPhase _phase = OidcLoginPhase.Idle; + public OidcLoginPhase Phase + { + get => _phase; + private set + { + if (this.SetProperty(ref _phase, value)) + OnPropertyChanged(nameof(PhaseLabel)); + } + } + + /// + /// Human-readable label for . French to match + /// the rest of the UI. Computed once per phase change. + /// + public string PhaseLabel => _phase switch + { + OidcLoginPhase.Idle => "En attente", + OidcLoginPhase.Discovering => "DĂ©couverte OIDC
", + OidcLoginPhase.OpeningBrowser => "Ouverture du navigateur
", + OidcLoginPhase.AwaitingCallback => "En attente du callback postit://
", + OidcLoginPhase.ExchangingCode => "Échange du code contre les jetons
", + OidcLoginPhase.Success => "ConnectĂ©", + OidcLoginPhase.Error => "Erreur", + _ => _phase.ToString(), + }; + + private string _statusMessage = "Ready"; + public string StatusMessage + { + get => _statusMessage; + private set => this.SetProperty(ref _statusMessage, value); + } + + private bool _isBusy; + public bool IsBusy + { + get => _isBusy; + private set => this.SetProperty(ref _isBusy, value); + } + + private bool _LoginSuccess; + public bool LoginSuccess { get => _isBusy; + private set => this.SetProperty(ref _LoginSuccess, value); } + + /// + /// Optional override used by tests. When set, this factory is called + /// instead of to obtain the + /// instance. + /// + public Func? BrowserFactoryOverride { get; set; } + + /// + /// Optional override used by tests. When set, this delegate replaces + /// the call to at the start of + /// , so tests can inject a Settings object + /// without it being overwritten by the user/embedded default. + /// + public Func? SettingsLoadOverride { get; set; } + + /// + /// Optional override used by tests. When set, the VM hands this + /// pre-built to itself instead of + /// constructing a fresh one. + /// + public YavscApiClient? ApiClientOverride { get; set; } + public Action LoginSucceeded { get; internal set; } + + private YavscApiClient? _api; + + public LoginPageViewModel() : this(new Settings(), apiClient: null, browserFactoryOverride: null) + { + // Load settings eagerly so RegisterUrl / ForgotPasswordUrl are + // populated as soon as the page renders (XAML bindings fire + // before the user clicks Login). Settings.Load is synchronous + // on purpose; calling .GetAwaiter().GetResult() on it would + // deadlock the UI thread on the await inside the file read. + try { Settings.Load(); } + catch { /* settings may be missing in tests/dev; LoginAsync will surface real errors */ } + } + + /// + /// Test-friendly constructor: caller supplies pre-loaded + /// , an optional + /// that bypasses the + /// static indirection, and an optional + /// pre-built for end-to-end + /// scenarios where the test owns the wiring. + /// + public LoginPageViewModel( + Settings settings, + Func? browserFactoryOverride = null, + YavscApiClient? apiClient = null) + { + Settings = settings; + BrowserFactoryOverride = browserFactoryOverride; + ApiClientOverride = apiClient; + StatusMessage = "Ready"; + } + + [RelayCommand] + public async Task LoginAsync() + { + try + { + IsBusy = true; + LoginSuccess = false; + if (SettingsLoadOverride is not null) + await SettingsLoadOverride().ConfigureAwait(false); + else + Settings.Load(); + + // Guard: refuse to call OidcClient when the authority is + // empty. IdentityModel would otherwise build a bogus + // authorize URL like "http://127.0.0.1:1/" from an empty + // Authority, which the browser refuses with a confusing + // "Cette adresse est interdite"-style message. Tell the + // operator exactly what to fix instead. + if (string.IsNullOrWhiteSpace(Settings.Authentication?.Authority)) + { + IsBusy = false; + StatusMessage = + $"Configuration manquante — Ă©dite {SettingsFileHint()} et renseigne Authentication.Authority"; + return; + } + + // The platform project picks the right redirect URI and + // browser implementation; we don't reference any UI + // toolkit from here. + Settings.RedirectUri = string.IsNullOrWhiteSpace(Settings.RedirectUri) + ? Platform.DefaultRedirectUri + : Settings.RedirectUri; + + // Surface the discovery URL the client is about to call, + // so a failure (DNS, TLS, 404) can be diagnosed by + // pasting the URL straight into a browser. OidcClient + // computes the discovery URL as + // `Authority + /.well-known/openid-configuration`; we + // normalise the trailing slash here so the printed URL is + // exactly what IdentityModel will fetch. + if (!string.IsNullOrEmpty(DiscoveryUrl)) + StatusMessage = $"Discovering {DiscoveryUrl}"; + + // Build (or reuse) the API client. The browser override + // takes precedence: tests want to inject a fake browser + // and the production path uses Platform.CreateBrowser. + _api ??= ApiClientOverride ?? new YavscApiClient(Settings, BuildTokenStore()); + + // Platform.CreateBrowser may still want to be customised + // per-call (e.g. between desktop and android), so route + // the interactive login through a callback that reuses + // BrowserFactoryOverride when present. + // + // The progress sink drives Phase / PhaseLabel; StatusMessage + // keeps the text detail (URLs, error messages). Same + // underlying flow, two views. + var progress = new Progress(p => Phase = p); + await LoginInteractiveCoreAsync(_api, progress).ConfigureAwait(false); + + IsBusy = false; + AccessToken = _api.CurrentAccessToken; + StatusMessage = "Interactive token acquired."; + LoginSuccess = true; + LoginSucceeded?.Invoke(); + } + catch (Exception ex) + { + IsBusy = false; + var suffix = !string.IsNullOrEmpty(DiscoveryUrl) ? $" (discovery: {DiscoveryUrl})" : string.Empty; + StatusMessage = $"Error: {ex.Message}{suffix}"; + } + } + + /// + /// Single entry point for the OIDC login: YavscApiClient owns the + /// browser choice, the OidcClient instance, the token persistence + /// and the refresh path. The VM is just a thin coordinator. + /// + private async Task LoginInteractiveCoreAsync( + YavscApiClient api, + IProgress? progress = null) + { + var original = Platform.CreateBrowser; + try + { + if (BrowserFactoryOverride is not null) + Platform.CreateBrowser = BrowserFactoryOverride; + + await api.LoginInteractiveAsync(progress).ConfigureAwait(false); + } + finally + { + Platform.CreateBrowser = original; + } + } + + /// + /// XDG-compliant path to the user settings file. Surfaced in the + /// "Configuration manquante" message so the operator knows exactly + /// which file to edit without having to dig through docs. + /// + private static string SettingsFileHint() + { + var appData = Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData); + return Path.Combine(appData, "PostIt", "postit-settings.json"); + } + + /// + /// Build the on-disk used by + /// . The token bundle lives in + /// ~/.config/PostIt/tokens.json on Linux; the same path + /// layout is used on every platform for predictability. + /// + private static TokenStore BuildTokenStore() + { + var appData = Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData); + var path = Path.Combine(appData, "PostIt", "tokens.json"); + return new TokenStore(path); + } +} diff --git a/src/PostIt/PostIt/ViewModels/MainViewModel.cs b/src/PostIt/PostIt/ViewModels/MainViewModel.cs index 1aa3eee0..e34d753c 100644 --- a/src/PostIt/PostIt/ViewModels/MainViewModel.cs +++ b/src/PostIt/PostIt/ViewModels/MainViewModel.cs @@ -2,54 +2,23 @@ using System; using System.Collections.ObjectModel; using System.Linq; using System.Threading.Tasks; -using Avalonia; +using Avalonia.Styling; using CommunityToolkit.Mvvm.ComponentModel; using CommunityToolkit.Mvvm.Input; -using Microsoft.Extensions.DependencyInjection; -using Yavsc.Blogspot; -using Yavsc.Api.Client; -using PostIt.Helpers; +using PostIt.Models; +using PostIt.Services; namespace PostIt.ViewModels; -public partial class MainViewModel : ViewModelBase +public partial class MainPageViewModel : ViewModelBase { - /// Window/tab title. Cosmetic — bound by - /// MainPage.axaml if at all. Not the post title. [ObservableProperty] - public partial string WindowTitle { get; set; } + public partial string Title { get; set; } - /// Editor buffer for the post title. Bound TwoWay to - /// the title TextBox in MainPage.axaml. The Save - /// command reads from this buffer (not from - /// ) so that typing into a freshly - /// mounted editor (no post selected yet) is captured. With the - /// previous "{Binding SelectedPost.Title}" binding, the user's - /// keystrokes were silently dropped whenever - /// SelectedPost was null, which made the editor a trap - /// and caused Save to POST a BlogPostDto with an empty - /// title — hence the 400 "The Title field is required". [ObservableProperty] - public partial string DraftTitle { get; set; } + public partial ViewModelBase? CurrentViewModel { get; set; } - /// Editor buffer for the post body. Same pattern as - /// . - [ObservableProperty] - public partial string DraftArticle { get; set; } - - /// Editor buffer for the post's publication state. - /// Reflects the server-side IsPublished flag (the - /// existence of a row in BlogSpotPublication) and - /// is pushed to the server via - /// on explicit - /// toggle — it is NOT included in the regular Save - /// payload, mirroring the wire contract where - /// BlogPostDto doesn't carry Publish as a - /// mutable field. Toggling is its own action. - [ObservableProperty] - public partial bool DraftIsPublished { get; set; } - - public Settings SettingsModel { get; } + public SettingsPageViewModel SettingsModel { get; } [ObservableProperty] public partial string StatusMessage { get; set; } @@ -58,17 +27,20 @@ public partial class MainViewModel : ViewModelBase public partial string SearchText { get; set; } [ObservableProperty] - public partial ObservableCollection Posts { get; set; } + public partial ObservableCollection Posts { get; set; } [ObservableProperty] - public partial ObservableCollection FilteredPosts { get; set; } + public partial ObservableCollection FilteredPosts { get; set; } [ObservableProperty] - public partial BlogPostDto? SelectedPost { get; set; } + public partial BlogPost? SelectedPost { get; set; } [ObservableProperty] public partial bool IsBusy { get; set; } + [ObservableProperty] + ThemeVariant themeVariant = ThemeVariant.Default; + [ObservableProperty] public partial Settings Settings { get; private set; } @@ -78,140 +50,43 @@ public partial class MainViewModel : ViewModelBase /// App.axaml.cs so the same client (and its token store) /// is shared with the login flow. /// - public BlogApiClient? BlogClient { get; } - - /// - /// DI container the VM uses to resolve navigation targets - /// (other ViewModels) when the user clicks a toolbar button - /// that opens a sub-screen. Owned by App.ServiceProvider - /// in production; injected directly in tests. The VM resolves - /// ViewModels via this provider, never Views — the - /// actual to push is decided by - /// at bind time, per CONTRIBUTING.md - /// §"Navigation (PostIt)". - /// - public IServiceProvider? Services { get; } - - private SignaturePageViewModel? _signatureModel; - - /// - /// Resolved on first access. Lazy so the test path (which - /// never pushes SignaturePage) does not require a - /// fully-built DI graph just to construct the VM. Mirrors the - /// pattern of for the Settings case. - /// - public SignaturePageViewModel SignatureModel => - _signatureModel ??= ResolveSignatureModel(); + public BlogApiClient BlogClient { get; } public override bool CanNavigateNext { get => throw new NotImplementedException(); protected set => throw new NotImplementedException(); } public override bool CanNavigatePrevious { get => throw new NotImplementedException(); protected set => throw new NotImplementedException(); } - private SignaturePageViewModel ResolveSignatureModel() - { - var sp = ResolveServices(); - return sp.GetRequiredService(); - } - - private IServiceProvider ResolveServices() - { - return Services ?? (Application.Current as App)?.ServiceProvider ?? - throw new InvalidOperationException( - "No IServiceProvider available for navigation. Inject one in tests " + - "or ensure App.ServiceProvider is initialized in production."); - } - - - public MainViewModel() - { - SettingsModel = new Settings(); - Init(SettingsModel); - BlogClient = null; - } - - private void Init(Settings? settings) - { - SearchText = string.Empty; - Posts = new ObservableCollection(); - FilteredPosts = new ObservableCollection(); - SelectedPost = null; - IsBusy = false; - StatusMessage = "Ready"; - Settings = settings ?? new Settings(); - WindowTitle = "PostIt"; - DraftTitle = string.Empty; - DraftArticle = string.Empty; - DraftIsPublished = false; - // Production path: DI injects the canonical Settings singleton - // and we use it as-is. Test path: tests call this constructor - // without a Settings argument; we fall back to a fresh - // instance so the fixture can build a self-contained VM. - // The previous "?? new Settings()" silently worked in prod - // too, which is what allowed a second Settings instance to - // race the singleton and crash the postit://callback binding - // sink; that crash is fixed in Settings.OnPropertyChanged - // (thread-safe dispatcher marshalling) so the duplicate - // instance is now merely wasteful, not dangerous. - - } - - /// Save is enabled as soon as the user has typed - /// a non-whitespace title in the editor, regardless of - /// whether a post is selected. The "no selection" case is - /// the create-new-post path; the "with selection" case is - /// the update path. Both read from the editor buffer. - /// Previously this also required SelectedPost is not null - /// — which contradicted the create-new-post intent and - /// forced the buggy "draft with empty title" branch. - private bool CanSave() => !IsBusy && !string.IsNullOrWhiteSpace(DraftTitle); - private bool CanDelete() => SelectedPost is not null && SelectedPost.Id != 0 && !IsBusy; - private bool CanManageAcl() => SelectedPost is not null && SelectedPost.Id != 0 && !IsBusy; - /// /// Test-friendly constructor: caller supplies a pre-built /// . Production code uses the /// (Settings, BlogApiClient) overload below. /// - public MainViewModel(BlogApiClient blogClient, Settings? settings = null, IServiceProvider? services = null) + public MainPageViewModel(BlogApiClient blogClient, Settings? settings = null) { - SettingsModel = new Settings(); - BlogClient = blogClient ?? throw new ArgumentNullException(nameof(blogClient)); ; - Services = services; - Init(settings); + SearchText = string.Empty; + Posts = new ObservableCollection(); + FilteredPosts = new ObservableCollection(); + SelectedPost = null; + IsBusy = false; + StatusMessage = "Ready"; + Settings = settings ?? new Settings(); + Title = "PostIt"; + CurrentViewModel = this; + SettingsModel = new SettingsPageViewModel(); + BlogClient = blogClient ?? throw new ArgumentNullException(nameof(blogClient)); } partial void OnSearchTextChanged(string value) => ApplyFilter(); - partial void OnSelectedPostChanged(BlogPostDto? value) - { - // Mirror the selection into the editor buffer so the - // XAML-bound TextBox/TextEditor show the right content - // when the user clicks a post in the list. When the - // selection is cleared (e.g. after a successful create - // rebinds to the server-issued record, or Delete - // nulls it out), the buffer is reset so the editor - // doesn't show stale content. - DraftTitle = value?.Title ?? string.Empty; - DraftArticle = value?.Article ?? string.Empty; - // Mirror publication state too. Defaults to false on - // null selection so a fresh draft starts unpublished. - DraftIsPublished = value?.IsPublished ?? false; - UpdateCommandStates(); - } + partial void OnSelectedPostChanged(BlogPost? value) => UpdateCommandStates(); partial void OnIsBusyChanged(bool value) => UpdateCommandStates(); - // Save's CanExecute depends on the buffer: the button must - // enable as soon as the user has typed a non-whitespace - // title, regardless of whether a post is selected. - partial void OnDraftTitleChanged(string value) => SaveCommand.NotifyCanExecuteChanged(); - partial void OnDraftArticleChanged(string value) => SaveCommand.NotifyCanExecuteChanged(); - [RelayCommand] internal async Task LoadPosts() { await ExecuteAsync(async () => { - var posts = await BlogClient!.GetPostsAsync(); + var posts = await BlogClient.GetPostsAsync(); Posts.Clear(); foreach (var post in posts.OrderByDescending(p => p.DateModified)) { @@ -228,39 +103,19 @@ public partial class MainViewModel : ViewModelBase [RelayCommand] internal async Task Save() { - // The button is already disabled when the title is empty - // (see CanSave), but the test path (and any programmatic - // ICommand.Execute) bypasses CanExecute, so we still - // guard here. Better to no-op with a status message - // than to send a request the server will reject. - if (string.IsNullOrWhiteSpace(DraftTitle)) + if (SelectedPost is null) { - StatusMessage = "Title is required."; + StatusMessage = "A post must be selected before saving."; return; } await ExecuteAsync(async () => { - // Build a fresh BlogPostDto from the editor buffer on - // every Save — we no longer mutate SelectedPost in - // place. The previous behaviour copied the buffer - // (which was a no-op when SelectedPost was null) - // back onto the model and relied on a - // [Required] violation to surface the missing - // input; the new shape keeps the editor buffer as - // the single source of truth for outgoing payloads - // and the selected post as a read-only hint for - // the update path. - if (SelectedPost is null || SelectedPost.Id == 0) + if (SelectedPost.Id == 0) { - var draft = new BlogPostDto - { - Title = DraftTitle, - Article = DraftArticle ?? string.Empty, - DateCreated = DateTime.UtcNow, - DateModified = DateTime.UtcNow, - }; - var created = await BlogClient!.CreatePostAsync(draft); + SelectedPost.DateCreated = DateTime.UtcNow; + SelectedPost.DateModified = DateTime.UtcNow; + var created = await BlogClient.CreatePostAsync(SelectedPost); if (created is not null) { SelectedPost = created; @@ -269,17 +124,8 @@ public partial class MainViewModel : ViewModelBase } else { - var update = new BlogPostDto - { - Id = SelectedPost.Id, - AuthorId = SelectedPost.AuthorId, - Photo = SelectedPost.Photo, - Title = DraftTitle, - Article = DraftArticle ?? string.Empty, - DateCreated = SelectedPost.DateCreated, - DateModified = DateTime.UtcNow, - }; - await BlogClient!.UpdatePostAsync(SelectedPost.Id, update); + SelectedPost.DateModified = DateTime.UtcNow; + await BlogClient.UpdatePostAsync(SelectedPost.Id, SelectedPost); StatusMessage = $"Saved post {SelectedPost.Id}."; } @@ -298,82 +144,35 @@ public partial class MainViewModel : ViewModelBase await ExecuteAsync(async () => { - await BlogClient!.DeletePostAsync(SelectedPost.Id); + await BlogClient.DeletePostAsync(SelectedPost.Id); StatusMessage = $"Deleted post {SelectedPost.Id}."; SelectedPost = null; await RefreshPostsAsync(); }); } - /// - /// Toggle the publication state of the currently selected - /// post. Pushes the new state to - /// PUT /api/BlogApi/{id}/publish and reflects it - /// locally in + the - /// selected post so the UI updates without a full - /// refresh. - /// - /// The toggle is its own action — separate from Save - /// — because Publish is not part of the - /// BlogPostDto payload. Bundling it into Save - /// would require a wire-shape change and a second server - /// overload; the dedicated endpoint keeps the wire - /// contract clean. - /// [RelayCommand] - internal async Task TogglePublish() + internal void New() { - if (SelectedPost is null || SelectedPost.Id == 0) + SelectedPost = new BlogPost { - StatusMessage = "SĂ©lectionnez un billet existant pour changer sa publication."; - return; - } - - await ExecuteAsync(async () => - { - var desired = !DraftIsPublished; - await BlogClient!.SetPublishAsync(SelectedPost.Id, desired); - DraftIsPublished = desired; - // Mirror into the selected post so a subsequent - // RefreshPostsAsync() doesn't blow away the - // locally flipped state until the round-trip - // re-hydrates it. - SelectedPost.IsPublished = desired; - StatusMessage = desired - ? $"Billet {SelectedPost.Id} publiĂ©." - : $"Billet {SelectedPost.Id} remis en brouillon."; - }); + Title = string.Empty, + Article = string.Empty, + DateCreated = DateTime.UtcNow, + DateModified = DateTime.UtcNow + }; + StatusMessage = "New blog post ready."; } - /// - /// DEV ONLY: open the signature capture page. The production - /// entry point is a SignalR push from Yavsc.Org ("devis - /// received, sign here"); this command is the dev-time - /// shortcut to reach the page without that infrastructure. - /// Aligned on the same VM-first navigation pattern as - /// : the VM resolves the target VM - /// through , the ViewLocator picks - /// the matching Control at bind time. No - /// Click handler, no App.ServiceProvider - /// access from the view layer. - /// [RelayCommand] - internal async Task OpenSignatureDev() + internal void OpenSettings() { - await ((App)App.Current!).PushPageAsync(SignatureModel).ConfigureAwait(true); - } - - private ViewModelBase GetACLViewModel(BlogPostDto selectedPost) - { - var sp = ResolveServices(); - var aclClient = sp.GetRequiredService(); - var circleClient = sp.GetRequiredService(); - return new PostAclDialogViewModel(selectedPost, aclClient, circleClient); + CurrentViewModel = SettingsModel; } private async Task RefreshPostsAsync() { - var posts = await BlogClient!.GetPostsAsync(); + var posts = await BlogClient.GetPostsAsync(); Posts.Clear(); foreach (var post in posts.OrderByDescending(p => p.DateModified)) { @@ -429,25 +228,9 @@ public partial class MainViewModel : ViewModelBase LoadPostsCommand.NotifyCanExecuteChanged(); SaveCommand.NotifyCanExecuteChanged(); DeleteCommand.NotifyCanExecuteChanged(); + NewCommand.NotifyCanExecuteChanged(); } - - - [RelayCommand(CanExecute = nameof(CanManageAcl))] - public async Task ManageAcl() - { - if (SelectedPost is null) - { - StatusMessage = "Select an existing post before managing ACL."; - return; - } - await ((App)App.Current!).PushPageAsync(GetACLViewModel(SelectedPost)).ConfigureAwait(true); - } - - [RelayCommand] - public async Task OpenCircles() - { - var circlesVm = ResolveServices().GetRequiredService(); - await ((App)App.Current!).PushPageAsync(circlesVm).ConfigureAwait(true); - } + private bool CanSave() => SelectedPost is not null && !IsBusy; + private bool CanDelete() => SelectedPost is not null && SelectedPost.Id != 0 && !IsBusy; } diff --git a/src/PostIt/PostIt/ViewModels/PostAclDialogViewModel.cs b/src/PostIt/PostIt/ViewModels/PostAclDialogViewModel.cs deleted file mode 100644 index ae9e71d5..00000000 --- a/src/PostIt/PostIt/ViewModels/PostAclDialogViewModel.cs +++ /dev/null @@ -1,174 +0,0 @@ -using System; -using System.Collections.Generic; -using System.Collections.ObjectModel; -using System.Threading.Tasks; -using CommunityToolkit.Mvvm.ComponentModel; -using CommunityToolkit.Mvvm.Input; -using Yavsc.Blogspot; -using Yavsc.Api.Client; -using Yavsc.Api.Client.Dtos; -using Yavsc.Abstract.BlogSpot; - -namespace PostIt.ViewModels; - -/// -/// View model for the "GĂ©rer l'ACL" modal of a single blog post. -/// -/// Loads the caller's circles once on construct (the dropdown -/// only shows circles the user owns), then keeps an in-memory list -/// of the ACL entries for the post. / -/// are the only mutating verbs; both -/// refresh the list afterwards so the UI stays in sync with the -/// server. -/// -/// The server is the source of truth: it scopes every -/// endpoint to the caller's uid and rejects ACL grants on posts -/// the caller doesn't own. This VM does not re-validate that — -/// any 403 / 404 will surface as an exception caught by the -/// command and routed to . -/// -public partial class PostAclDialogViewModel : ViewModelBase -{ - private readonly BlogAclApiClient _aclClient; - private readonly CircleApiClient _circleClient; - - /// The post whose ACL is being edited. Set by the - /// caller (MainPage) when opening the dialog. - public BlogPostDto Post { get; } - - [ObservableProperty] - public partial ObservableCollection - MyCircles { get; set; } = new(); - - [ObservableProperty] - public partial ObservableCollection - AclEntries { get; set; } = new(); - - [ObservableProperty] - public partial CircleDto? SelectedCircleToAdd { get; set; } - - [ObservableProperty] - public partial bool IsBusy { get; set; } - - [ObservableProperty] - public partial string StatusMessage { get; set; } = string.Empty; - - /// - /// Idempotency gate for : the dialog - /// attaches the load trigger in DataContextChanged, - /// which can fire more than once if the page is detached - /// and re-attached (dialog re-use, navigation edge cases) - /// with a different VM. Without this guard, the second load - /// would race against the first and could overwrite - /// mid-edit. Pattern copied from - /// Settings.Load. - /// - private bool _loaded; - - /// True once has run at least - /// once. Exposed for tests; do not bind from XAML. - public bool Loaded => _loaded; - - public PostAclDialogViewModel( - BlogPostDto post, - BlogAclApiClient aclClient, - CircleApiClient circleClient) - { - Post = post ?? throw new ArgumentNullException(nameof(post)); - _aclClient = aclClient ?? throw new ArgumentNullException(nameof(aclClient)); - _circleClient = circleClient ?? throw new ArgumentNullException(nameof(circleClient)); - } - - public override bool CanNavigateNext { get => throw new NotImplementedException(); protected set => throw new NotImplementedException(); } - public override bool CanNavigatePrevious { get => throw new NotImplementedException(); protected set => throw new NotImplementedException(); } - - [RelayCommand] - public async Task LoadAsync() - { - if (_loaded) return; - - IsBusy = true; - try - { - // Load circles and ACL entries in parallel — both are - // independent reads on the same host. The caller's uid - // is implicit in both endpoints. - var circlesTask = _circleClient.GetMyCirclesAsync(); - var aclTask = _aclClient.GetMyAclAsync(); - await Task.WhenAll(circlesTask, aclTask); - - var circles = circlesTask.Result ?? new List(); - MyCircles = new ObservableCollection(circles); - - - StatusMessage = $"{AclEntries.Count} autorisation(s)"; - _loaded = true; - } - catch (Exception ex) - { - StatusMessage = $"Erreur: {ex.Message}"; - } - finally - { - IsBusy = false; - } - } - - [RelayCommand] - public async Task AddAsync() - { - if (SelectedCircleToAdd is null) - { - StatusMessage = "SĂ©lectionnez un cercle Ă  ajouter"; - return; - } - - IsBusy = true; - try - { - var created = await _aclClient.GrantAsync(new Yavsc.Abstract.BlogSpot.PostAccessControlRulePayload - { - CircleId = SelectedCircleToAdd.Id, - BlogPostId = Post.Id - }); - if (created is not null) - { - AclEntries.Add(created); - StatusMessage = $"Cercle « {SelectedCircleToAdd.Name} » autorisĂ©"; - } - else - { - StatusMessage = "Autorisation refusĂ©e par le serveur"; - } - } - catch (Exception ex) - { - StatusMessage = $"Erreur: {ex.Message}"; - } - finally - { - IsBusy = false; - } - } - - [RelayCommand] - public async Task RevokeAsync(PostAccessControlRulePayload? acl) - { - if (acl is null) return; - IsBusy = true; - try - { - await _aclClient.RevokeAsync(acl.CircleId); - AclEntries.Remove(acl); - StatusMessage = "Autorisation rĂ©voquĂ©e"; - } - catch (Exception ex) - { - StatusMessage = $"Erreur: {ex.Message}"; - } - finally - { - IsBusy = false; - } - } -} diff --git a/src/PostIt/PostIt/ViewModels/SessionStatusViewModel.cs b/src/PostIt/PostIt/ViewModels/SessionStatusViewModel.cs index f2496b85..0ebe73a9 100644 --- a/src/PostIt/PostIt/ViewModels/SessionStatusViewModel.cs +++ b/src/PostIt/PostIt/ViewModels/SessionStatusViewModel.cs @@ -1,9 +1,5 @@ -using System; -using System.Threading.Tasks; using CommunityToolkit.Mvvm.ComponentModel; using CommunityToolkit.Mvvm.Input; -using Microsoft.Extensions.DependencyInjection; -using PostIt.Helpers; using PostIt.Services; namespace PostIt.ViewModels; @@ -13,11 +9,7 @@ namespace PostIt.ViewModels; /// MainWindow.axaml. Mirrors 's /// session state ("ConnectĂ©" / "DĂ©connectĂ©") and exposes a /// Logout command that purges the token store and asks the -/// navigation owner to route the user back to HomePage, plus -/// a Login command that drives the OIDC interactive flow -/// and raises a event on success so -/// MainWindow can push MainPage on top of -/// HomePage. +/// navigation owner to route the user back to HomePage. /// /// Construction is deferred until the API client exists; the /// App.axaml.cs wiring sets after building both, @@ -29,29 +21,12 @@ public partial class SessionStatusViewModel : ViewModelBase /// App.axaml.cs listens and swaps the navigation root. public event System.Action? LogoutCompleted; - /// Raised after acquired a valid session; - /// App.axaml.cs listens and pushes MainPage on top of - /// HomePage so the user lands on the blog editor. - public event System.Action? LoginSucceeded; - [ObservableProperty] public partial bool IsLoggedIn { get; private set; } - /// Inverse of , for XAML bindings - /// (the banner shows the Login button when the user is logged out). - /// Updated from . - [ObservableProperty] - public partial bool IsLoggedOut { get; private set; } = true; - [ObservableProperty] public partial string SessionLabel { get; private set; } = "DĂ©connectĂ©"; - /// True while a Login flow is in flight; the Login button - /// binds IsEnabled to !IsBusy via - /// 's CanExecute. - [ObservableProperty] - public partial bool IsBusy { get; private set; } - /// The API client backing the banner. Set once at startup; /// the banner polls HasValidSession on demand rather than /// subscribing to a stream — the session state only changes at @@ -75,58 +50,9 @@ public partial class SessionStatusViewModel : ViewModelBase { var has = Api?.HasValidSession ?? false; IsLoggedIn = has; - IsLoggedOut = !has; SessionLabel = has ? "ConnectĂ©" : "DĂ©connectĂ©"; } - /// - /// Override the banner label with an error message. Used when - /// an interactive login attempt fails so the operator sees - /// something on the persistent UI without us needing a - /// dedicated error page. The next call - /// reverts to "ConnectĂ©" / "DĂ©connectĂ©". - /// - public void SetError(string message) - { - IsLoggedIn = false; - IsLoggedOut = true; - SessionLabel = message; - } - - /// - /// Drive the OIDC interactive login. On success, refreshes - /// the banner state and raises so - /// the navigation owner can push MainPage. On failure, - /// surfaces the error in the banner via . - /// - [RelayCommand(CanExecute = nameof(CanLogin))] - public async Task LoginAsync() - { - if (Api is null) return; - IsBusy = true; - try - { - await Api.LoginInteractiveAsync().ConfigureAwait(true); - } - catch (Exception ex) - { - SetError($"Login failed: {ex.Message}"); - return; - } - finally - { - IsBusy = false; - } - - Refresh(); - if (Api.HasValidSession) - LoginSucceeded?.Invoke(); - } - - private bool CanLogin() => !IsBusy; - - partial void OnIsBusyChanged(bool value) => LoginCommand.NotifyCanExecuteChanged(); - [RelayCommand] public async System.Threading.Tasks.Task LogoutAsync() { @@ -135,12 +61,4 @@ public partial class SessionStatusViewModel : ViewModelBase Refresh(); LogoutCompleted?.Invoke(); } - - [RelayCommand] - internal async Task OpenSettings() - { - var app = (App)App.Current!; - await app.PushPageAsync(app.ServiceProvider!.GetRequiredService()).ConfigureAwait(true); - } - } diff --git a/src/PostIt/PostIt/ViewModels/Settings.cs b/src/PostIt/PostIt/ViewModels/Settings.cs deleted file mode 100644 index fd87d772..00000000 --- a/src/PostIt/PostIt/ViewModels/Settings.cs +++ /dev/null @@ -1,413 +0,0 @@ -using System.Runtime.CompilerServices; -using CommunityToolkit.Mvvm.ComponentModel; -using CommunityToolkit.Mvvm.Input; -using IdentityModel.OidcClient; -using System; -using System.Collections.Generic; -using System.IO; -using System.Net.Http; -using System.Text.Json; - -[assembly: InternalsVisibleTo("PostIt.Tests")] - -namespace PostIt.ViewModels; - -public partial class Settings : ViewModelBase -{ - const string SettingsFileName = "postit-settings.json"; - - [ObservableProperty] - public partial AuthenticationSettings Authentication { get; set; } = new(); - - [ObservableProperty] - public partial bool DarkMode { get; set; } = false; - - [ObservableProperty] - public partial string BlogsApiUrl { get; set; } = "https://blogs.pschneider.fr/api/v1/"; - - [ObservableProperty] - public partial string BusinessApiUrl { get; set; } = "https://business.pschneider.fr/api/v1/"; - - /// - /// Catch top-level mutations: the four ObservableProperty - /// setters above all funnel through here, and we flip - /// in lock-step. Sub-property mutations - /// (e.g. Authentication.Authority) are caught by the - /// subscription wired up in - /// below. disables the flag during bulk - /// hydration so the disk load itself does not count as a user - /// edit. - /// - private void MarkDirty() => IsDirty = true; - - partial void OnDarkModeChanged(bool value) => MarkDirty(); - partial void OnBlogsApiUrlChanged(string value) => MarkDirty(); - partial void OnBusinessApiUrlChanged(string value) => MarkDirty(); - - /// - /// Authentication can be reassigned wholesale by - /// ; on each reassignment we (re)wire a - /// PropertyChanged listener so sub-property edits - /// (Authority, ClientId, RedirectUri, Scopes) are picked up - /// by the dirty tracker. We don't filter on PropertyName: any - /// nested setter is treated as a user edit, which matches the - /// user's mental model ("I typed in a field, the page is now - /// dirty"). - /// - partial void OnAuthenticationChanged(AuthenticationSettings value) - { - if (value is not null) - { - value.PropertyChanged += (_, _) => MarkDirty(); - } - MarkDirty(); - } - - public bool Loaded { get; private set; } = false; - - /// - /// True when the in-memory state has drifted from the last - /// or snapshot. The - /// Settings page binds the Sauver button's IsEnabled to - /// this flag, so it only enables when the user has actually - /// touched something since the last load / save. Cleared by - /// (and by ), set by - /// every successful setter on the four top-level mutable - /// properties and on the sub-properties of - /// . - /// - [ObservableProperty] - public partial bool IsDirty { get; private set; } = false; - - /// - /// Guards every mutation of the observable state. [ObservableProperty] - /// generates setters that call SetProperty(...) which fires - /// PropertyChanged. Avalonia bindings consume that event on - /// the UI thread, and a stray background-thread update is exactly - /// what crashed DataValidationErrors.SetErrors on - /// postit://callback re-launches. The lock makes mutations - /// atomic; - /// then marshals the notification onto the UI thread so bindings - /// observe the change on the right thread. - /// - private readonly object _mutationGate = new(); - - /// - /// Build OidcClient options configured for Authorization Code + PKCE - /// (no client secret). The browser implementation should be supplied - /// per-platform by the caller. - /// - internal OidcClientOptions GetOidcClientOptions(IdentityModel.OidcClient.Browser.IBrowser? browser = null) - { - if (!Loaded) Load(); - // Snapshot under the gate so the caller observes a consistent - // view of all six properties; without this, a concurrent - // Load() could swap Authentication mid-method and we would - // build options from a torn read. - lock (_mutationGate) - { - var options = new OidcClientOptions - { - Authority = Authentication.Authority, - ClientId = Authentication.ClientId, - RedirectUri = Authentication.RedirectUri, - Scope = string.Join(' ', MergeScopes(this.Authentication.Scopes)), - TokenClientCredentialStyle = IdentityModel.Client.ClientCredentialStyle.PostBody, - PostLogoutRedirectUri = Authentication.Authority, - // PKCE is enabled by default when no client_secret is provided. - }; - - if (IsDevelopmentEnvironment()) - { - // Dev only: allow local/self-signed TLS for discovery/token - // endpoints when the machine does not trust a custom root. - options.BackchannelHandler = new HttpClientHandler - { - ServerCertificateCustomValidationCallback = (_, _, _, _) => true - }; - } - - if (browser is not null) - options.Browser = browser; - - return options; - } - } - - /// - /// Scopes the PostIt client always requires from the OIDC provider, - /// regardless of what the user has in their settings file. - /// - /// PostIt calls into the Blog API (and any other Yavsc API - /// gated by an [Authorize("
Scope")] policy) and is silent - /// about the contract: a missing scope here surfaces as a 401 - /// on the very first API call after login, with no obvious link - /// to the settings. The "feature" scopes the user must opt into - /// (e.g. blogs) are still their choice — we only force the - /// structural ones that OIDC itself needs. - /// - private static readonly string[] BuiltInScopes = new[] - { - "openid", // OIDC: required for the id_token - "profile", // OIDC: standard profile claims - "offline_access" // OIDC: required to receive a refresh_token - }; - - /// - /// Merge user-configured scopes with the built-in ones. User scopes - /// come first (preserves author intent), then the built-ins, with - /// duplicates removed case-sensitively. null or empty input - /// is fine — we still emit the built-ins. - /// - internal static IEnumerable MergeScopes(string[]? userScopes) - { - var seen = new HashSet(StringComparer.Ordinal); - if (userScopes is not null) - { - foreach (var s in userScopes) - { - if (string.IsNullOrWhiteSpace(s)) continue; - if (seen.Add(s)) yield return s; - } - } - foreach (var s in BuiltInScopes) - { - if (seen.Add(s)) yield return s; - } - } - - private static bool IsDevelopmentEnvironment() - { - return string.Equals( - Environment.GetEnvironmentVariable("ASPNETCORE_ENVIRONMENT"), - "Development", - StringComparison.OrdinalIgnoreCase); - } - - internal void Load() - { - if (Loaded) return; - - // Trust an already-populated Authority: tests pre-fill Settings - // with the OIDC stub's random loopback port, and programmatic - // callers (CLI flags, integration tests) wire their own. If we - // fall through to the disk / embedded read here we'd silently - // overwrite their value with the bundled default - // (yavsc.pschneider.fr), break the stubbed discovery URL, and - // turn a passing login into an invalid_grant. - lock (_mutationGate) - { - if (Loaded) return; // double-check after taking the gate - if (!string.IsNullOrWhiteSpace(Authentication?.Authority)) - { - Loaded = true; - return; - } - } - - string configDir = Path.Combine( - Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), - "PostIt" -); - Directory.CreateDirectory(configDir); - - string configPath = Path.Combine(configDir, SettingsFileName); - - FileInfo configFileInfo = new FileInfo(configPath); - - if (!configFileInfo.Exists) - { - Console.Error.WriteLine($"đŸ©Ž Settings file not found at {configFileInfo.FullName}"); - // No user-level config: fall back to the embedded default. - // We only get here when Authentication.Authority is empty - // (the early-return above) so the redundant guard is gone. - if (!TryLoadEmbeddedFallback()) - { - Console.Error.WriteLine("đŸ©Ž No embedded default settings; running with empty configuration."); - } - return; - } - - Console.WriteLine($"🔎 Loading settings from {configFileInfo.FullName}"); - - try - { - // Synchronous read on purpose: Settings.Load() is called from - // synchronous startup paths (App.axaml.cs, ViewModel ctors, - // tests) and bridging to async here with .Wait() / .GetAwaiter() - // .GetResult() deadlocks the Avalonia UI thread because the - // continuation can't resume on the same thread. The settings - // file is a few KiB at most; async I/O gains nothing here. - using var stream = configFileInfo.OpenRead(); - using var reader = new StreamReader(stream); - var json = reader.ReadToEnd(); - ApplyJson(json, $"user file {configFileInfo.FullName}"); - Loaded = true; - } - catch (Exception ex) - { - Console.Error.WriteLine($"đŸ©Ž Error loading settings: {ex.Message}"); - } - } - - private bool TryLoadEmbeddedFallback() - { - const string ResourceName = "PostIt.postit-settings.json"; - var assembly = typeof(Settings).Assembly; - using var stream = assembly.GetManifestResourceStream(ResourceName); - if (stream is null) - { - Console.Error.WriteLine($"đŸ©Ž Embedded resource {ResourceName} not found."); - return false; - } - using var reader = new StreamReader(stream); - var json = reader.ReadToEnd(); - if (string.IsNullOrWhiteSpace(json)) - { - Console.Error.WriteLine("đŸ©Ž Embedded settings resource is empty."); - return false; - } - Console.WriteLine($"🔎 Loading embedded default settings ({ResourceName})."); - ApplyJson(json, $"embedded resource {ResourceName}"); - return true; - } - - private void ApplyJson(string json, string source) - { - if (string.IsNullOrWhiteSpace(json)) - { - Console.Error.WriteLine($"đŸ©Ž Settings payload is empty (source: {source})."); - return; - } - try - { - var settings = JsonSerializer.Deserialize(json); - if (settings is null) - { - UseDefaultSettings(); - } - // Apply under the gate so concurrent Load() callers cannot - // see half the new values / half the old ones. The actual - // PropertyChanged fan-out is handled by [ObservableProperty]'s - // setters which we route through SetProperty → OnPropertyChanged - // → our overridden dispatcher-safe marshaller below. - else lock (_mutationGate) - { - this.Authentication = settings.Authentication; - this.DarkMode = settings.DarkMode; - if (!(settings.Authentication is null)) - { - this.Authentication = new AuthenticationSettings(); - this.Authentication.Authority = string.IsNullOrWhiteSpace(settings.Authentication.Authority) ? - AuthenticationSettings.DefaultAuthority : settings.Authentication.Authority; - this.Authentication.ClientId = string.IsNullOrWhiteSpace(settings.Authentication.ClientId) ? - AuthenticationSettings.DefaultClientId : settings.Authentication.ClientId; - this.Authentication.RedirectUri = string.IsNullOrWhiteSpace(settings.Authentication.RedirectUri) ? - AuthenticationSettings.DesktopRedirectUri : settings.Authentication.RedirectUri; - if (settings.Authentication.Scopes is null || settings.Authentication.Scopes.Length == 0) - { - settings.Authentication.Scopes = AuthenticationSettings.DefaultScopes; - } - else - this.Authentication.Scopes = settings.Authentication.Scopes; - } - } - // A disk load (or an embedded-resource fallback) is the - // baseline, not a user edit. Clear the dirty flag last - // so the OnAuthenticationChanged / sub-property fan-out - // triggered by the assignments above doesn't leave it - // stuck at true. - IsDirty = false; - // Refresh the space-separated ScopeListText view after - // hydration so the SettingsPage TextBox reflects the - // loaded scopes (and not the default empty string the - // ObservableProperty was constructed with). OnScopesChanged - // already tries to do this, but it skips when the new - // array parses to the same text — calling explicitly - // forces a re-sync and normalises any whitespace the - // JSON might have introduced. - this.Authentication?.RefreshScopeListText(); - // Re-notify the command in case the button was bound - // before Load finished and the CanExecute cache is - // stale. - SaveCommand.NotifyCanExecuteChanged(); - } - catch (Exception ex) - { - Console.Error.WriteLine($"đŸ©Ž Error applying settings from {source}: {ex.Message}"); - } - } - - private void UseDefaultSettings() - { - this.Authentication = new AuthenticationSettings - { - Authority = AuthenticationSettings.DefaultAuthority, - ClientId = AuthenticationSettings.DefaultClientId, - RedirectUri = AuthenticationSettings.DesktopRedirectUri, - Scopes = AuthenticationSettings.DefaultScopes - }; - this.DarkMode = false; - } - - /// - /// Persist the current in-memory state to - /// ~/.config/PostIt/postit-settings.json (Linux) / - /// equivalent %APPDATA%\PostIt\postit-settings.json - /// (Windows). Symmetrical to : same path, - /// same directory creation, same 0600 file mode (POSIX) - /// as TokenStore.Save. Clears - /// on success. - /// - /// Synchronous on purpose: matches 's - /// contract (the file is a few KiB at most, and the Avalonia - /// UI thread cannot await here without risking the same - /// deadlock 's docstring describes). - /// - /// - [RelayCommand(CanExecute = nameof(CanSave))] - public void Save() - { - var configDir = Path.Combine( - Environment.GetFolderPath(Environment.SpecialFolder.ApplicationData), - "PostIt"); - Directory.CreateDirectory(configDir); - var configPath = Path.Combine(configDir, SettingsFileName); - - lock (_mutationGate) - { - try - { - var json = JsonSerializer.Serialize(this, new JsonSerializerOptions - { - WriteIndented = true, - }); - File.WriteAllText(configPath, json); - if (OperatingSystem.IsLinux() || OperatingSystem.IsMacOS()) - File.SetUnixFileMode(configPath, - UnixFileMode.UserRead | UnixFileMode.UserWrite); - IsDirty = false; - Console.WriteLine($"đŸ’Ÿ Settings saved to {configPath}"); - } - catch (Exception ex) - { - Console.Error.WriteLine($"đŸ©Ž Error saving settings to {configPath}: {ex.Message}"); - throw; - } - } - } - - private bool CanSave() => IsDirty; - - /// - /// Re-notify the SaveCommand (generated by - /// [RelayCommand] on ) so XAML - /// re-evaluates CanExecute when the dirty flag flips - /// outside the scope of a direct save (e.g. on - /// / ). - /// - partial void OnIsDirtyChanged(bool value) => SaveCommand.NotifyCanExecuteChanged(); - - public override bool CanNavigateNext { get => false; protected set => throw new System.NotImplementedException(); } - public override bool CanNavigatePrevious { get => true; protected set => throw new System.NotImplementedException(); } -} diff --git a/src/PostIt/PostIt/ViewModels/SettingsViewModel.cs b/src/PostIt/PostIt/ViewModels/SettingsViewModel.cs new file mode 100644 index 00000000..67223d5f --- /dev/null +++ b/src/PostIt/PostIt/ViewModels/SettingsViewModel.cs @@ -0,0 +1,18 @@ +using CommunityToolkit.Mvvm.ComponentModel; + +namespace PostIt.ViewModels; + +public partial class SettingsPageViewModel : ViewModelBase +{ + [ObservableProperty] + public partial bool DarkMode { get; set; } + + [ObservableProperty] + public partial string Authority { get; set; } + + [ObservableProperty] + public partial string ClientId { get; set; } + + public override bool CanNavigateNext { get => false; protected set => throw new System.NotImplementedException(); } + public override bool CanNavigatePrevious { get => true; protected set => throw new System.NotImplementedException(); } +} diff --git a/src/PostIt/PostIt/ViewModels/SignaturePageViewModel.cs b/src/PostIt/PostIt/ViewModels/SignaturePageViewModel.cs deleted file mode 100644 index b4b37974..00000000 --- a/src/PostIt/PostIt/ViewModels/SignaturePageViewModel.cs +++ /dev/null @@ -1,185 +0,0 @@ -using System; -using System.IO; -using System.Text; -using System.Text.Json; -using System.Threading.Tasks; -using CommunityToolkit.Mvvm.ComponentModel; -using CommunityToolkit.Mvvm.Input; -using PostIt.Controls; -using PostIt.Models; - -namespace PostIt.ViewModels; - -/// -/// Backing state for . -/// -/// The page exists to produce a -/// (length-prefixed normalised int[]) from a human signature drawn -/// with the mouse (Desktop) or finger (touch / Android). The page -/// is a recipient of an external trigger — a SignalR push from -/// Yavsc.Org telling PostIt "a devis has been sent, sign here" — -/// so it intentionally has no first-class entry point in -/// . The only "open" affordance today is a -/// dev-only shortcut on the blog editor, marked for removal once -/// the SignalR handler lands. -/// -/// Output path is the platform-friendly per-user data directory -/// (XDG_DATA_HOME / AppData / NSDocumentDirectory on iOS). Files -/// are JSON, one per capture, named -/// signature-{yyyyMMdd-HHmmssfff}.json. This is a stop-gap -/// until the Yavsc.Org endpoint exists; the contract there will -/// be POST /api/signature/{devisId} with this same payload. -/// -public partial class SignaturePageViewModel : ViewModelBase -{ - /// - /// Default capture surface, in DIPs. 3:1 ratio matches a - /// signature line at the bottom of an A4 contract. - /// - public const double DefaultWidth = 600; - public const double DefaultHeight = 200; - - [ObservableProperty] - public partial string StatusMessage { get; set; } = "PrĂȘt."; - - [ObservableProperty] - public partial int StrokeCount { get; set; } - - [ObservableProperty] - public partial int PointCount { get; set; } - - [ObservableProperty] - public partial string? LastCapturedPath { get; set; } - - public double Width { get; } - public double Height { get; } - - private SignaturePadControl? _control; - - public override bool CanNavigateNext - { - get => false; - protected set { _ = value; } - } - - public override bool CanNavigatePrevious - { - get => true; - protected set { _ = value; } - } - - public SignaturePageViewModel() - : this(DefaultWidth, DefaultHeight) - { - } - - public SignaturePageViewModel(double width, double height) - { - if (width <= 0) throw new ArgumentOutOfRangeException(nameof(width)); - if (height <= 0) throw new ArgumentOutOfRangeException(nameof(height)); - Width = width; - Height = height; - } - - /// - /// Bind a freshly-constructed (or re-templated) control to this - /// VM. Called from the view's code-behind once the control has - /// been added to the visual tree and its template applied (so - /// is wired). - /// - public void Attach(SignaturePadControl control) - { - if (control is null) throw new ArgumentNullException(nameof(control)); - Detach(); - _control = control; - _control.RedrawRequested += OnRedraw; - _control.StrokeCompleted += OnStrokeCompleted; - RefreshCounts(); - } - - public void Detach() - { - if (_control is null) return; - _control.RedrawRequested -= OnRedraw; - _control.StrokeCompleted -= OnStrokeCompleted; - _control = null; - } - - private void OnStrokeCompleted(object? sender, SignaturePadData data) - { - StatusMessage = $"Trait terminĂ©. {data.StrokeCount} trait(s)."; - RefreshCounts(); - } - - private void OnRedraw(object? sender, EventArgs e) => RefreshCounts(); - - private void RefreshCounts() - { - if (_control is null) return; - var snap = _control.Snapshot(); - StrokeCount = snap.StrokeCount; - PointCount = snap.PointCount; - } - - [RelayCommand] - public void Clear() - { - _control?.Clear(); - StatusMessage = "EffacĂ©."; - RefreshCounts(); - } - - [RelayCommand] - public async Task CaptureAsync() - { - if (_control is null) - { - StatusMessage = "ContrĂŽle non attachĂ©."; - return; - } - - var data = _control.Snapshot(); - if (data.IsEmpty) - { - StatusMessage = "Rien Ă  capturer."; - return; - } - - try - { - var path = WriteCapture(data); - LastCapturedPath = path; - StatusMessage = $"Capture enregistrĂ©e: {path}"; - } - catch (Exception ex) - { - StatusMessage = $"Erreur: {ex.Message}"; - } - await Task.CompletedTask; - } - - private static string WriteCapture(SignaturePadData data) - { - var dir = Path.Combine( - Environment.GetFolderPath(Environment.SpecialFolder.LocalApplicationData), - "PostIt", "signatures"); - Directory.CreateDirectory(dir); - - var fileName = $"signature-{DateTime.UtcNow:yyyyMMdd-HHmmssfff}.json"; - var path = Path.Combine(dir, fileName); - - var payload = new - { - format = "yavsc.signature/v1", - coordinateMax = SignaturePadData.CoordinateMax, - capturedAtUtc = DateTime.UtcNow, - strokes = data.Strokes, - strokeCount = data.StrokeCount, - }; - File.WriteAllText( - path, - JsonSerializer.Serialize(payload, new JsonSerializerOptions { WriteIndented = true }), - Encoding.UTF8); - return path; - } -} diff --git a/src/PostIt/PostIt/ViewModels/ViewModelBase.cs b/src/PostIt/PostIt/ViewModels/ViewModelBase.cs index 4ca69eea..93019360 100644 --- a/src/PostIt/PostIt/ViewModels/ViewModelBase.cs +++ b/src/PostIt/PostIt/ViewModels/ViewModelBase.cs @@ -1,10 +1,12 @@ -ï»żusing CommunityToolkit.Mvvm.ComponentModel; +ï»żusing Avalonia.Styling; +using CommunityToolkit.Mvvm.ComponentModel; namespace PostIt.ViewModels; public abstract partial class ViewModelBase : ObservableObject { - /// + + /// /// Gets if the user can navigate to the next page /// public abstract bool CanNavigateNext { get; protected set; } diff --git a/src/PostIt/PostIt/Views/AddCircleMemberDialog.axaml b/src/PostIt/PostIt/Views/AddCircleMemberDialog.axaml deleted file mode 100644 index 8b232988..00000000 --- a/src/PostIt/PostIt/Views/AddCircleMemberDialog.axaml +++ /dev/null @@ -1,62 +0,0 @@ - - - - - - - - - \ No newline at end of file + diff --git a/src/Yavsc.Org/Views/Account/ForgotPasswordConfirmation.cshtml b/src/Yavsc.Org/Views/Account/ForgotPasswordConfirmation.cshtml index 4faaf2d0..d1e50615 100644 --- a/src/Yavsc.Org/Views/Account/ForgotPasswordConfirmation.cshtml +++ b/src/Yavsc.Org/Views/Account/ForgotPasswordConfirmation.cshtml @@ -1,7 +1,5 @@ @model string -@{ - ViewBag.Title = Localizer["Account"]; -}

Check your mail box!

+ diff --git a/src/Yavsc.Org/Views/Account/LoggedOut.cshtml b/src/Yavsc.Org/Views/Account/LoggedOut.cshtml index 82c653c7..dc9fbf7a 100644 --- a/src/Yavsc.Org/Views/Account/LoggedOut.cshtml +++ b/src/Yavsc.Org/Views/Account/LoggedOut.cshtml @@ -1,8 +1,4 @@ -@{ - ViewBag.Title = Localizer["Account"]; -} - -@model LoggedOutViewModel +ï»ż@model LoggedOutViewModel @{ // set this so the layout rendering sees an anonymous user diff --git a/src/Yavsc.Org/Views/Account/Login.cshtml b/src/Yavsc.Org/Views/Account/Login.cshtml index 54df2e3e..b0ee8e88 100644 --- a/src/Yavsc.Org/Views/Account/Login.cshtml +++ b/src/Yavsc.Org/Views/Account/Login.cshtml @@ -1,7 +1,4 @@ @model LoginViewModel -@{ - ViewBag.Title = Localizer["Account"]; -} - \ No newline at end of file + diff --git a/src/Yavsc.Org/Views/Account/Logout.cshtml b/src/Yavsc.Org/Views/Account/Logout.cshtml index 893807f7..b49dee09 100644 --- a/src/Yavsc.Org/Views/Account/Logout.cshtml +++ b/src/Yavsc.Org/Views/Account/Logout.cshtml @@ -1,8 +1,4 @@ -@{ - ViewBag.Title = Localizer["Account"]; -} - -@model LogoutViewModel +ï»ż@model LogoutViewModel
diff --git a/src/Yavsc.Org/Views/Account/Register.cshtml b/src/Yavsc.Org/Views/Account/Register.cshtml index 92a7f34e..388b2ecd 100644 --- a/src/Yavsc.Org/Views/Account/Register.cshtml +++ b/src/Yavsc.Org/Views/Account/Register.cshtml @@ -1,11 +1,8 @@ @model RegisterModel -@{ - ViewBag.Title = Localizer["Account"]; -}
@Html.EditorForModel() -
\ No newline at end of file + diff --git a/src/Yavsc.Org/Views/Account/ResetPassword.cshtml b/src/Yavsc.Org/Views/Account/ResetPassword.cshtml index 0cdbb2e3..5f64c727 100644 --- a/src/Yavsc.Org/Views/Account/ResetPassword.cshtml +++ b/src/Yavsc.Org/Views/Account/ResetPassword.cshtml @@ -1,7 +1,4 @@ @model ResetPasswordViewModel -@{ - ViewBag.Title = Localizer["Account"]; -}

Your email : @Model.Email

@@ -18,4 +15,4 @@ -
\ No newline at end of file + diff --git a/src/Yavsc.Org/Views/Account/Signin.cshtml b/src/Yavsc.Org/Views/Account/Signin.cshtml index 871c0c74..079882b3 100644 --- a/src/Yavsc.Org/Views/Account/Signin.cshtml +++ b/src/Yavsc.Org/Views/Account/Signin.cshtml @@ -1,7 +1,4 @@ @model SignInModel -@{ - ViewBag.Title = Localizer["Account"]; -} -
\ No newline at end of file +
diff --git a/src/Yavsc.Org/Views/Activity/Create.cshtml b/src/Yavsc.Org/Views/Activity/Create.cshtml index 0fe9938a..cc305557 100644 --- a/src/Yavsc.Org/Views/Activity/Create.cshtml +++ b/src/Yavsc.Org/Views/Activity/Create.cshtml @@ -20,7 +20,7 @@
+ Name"]
@@ -28,7 +28,7 @@
+ Parent"]
@@ -37,7 +37,7 @@
+ Description"]
@@ -45,7 +45,7 @@
@@ -54,7 +54,7 @@
+
diff --git a/src/Yavsc.Org/Views/Activity/Edit.cshtml b/src/Yavsc.Org/Views/Activity/Edit.cshtml index 0f4e591a..ea77d956 100644 --- a/src/Yavsc.Org/Views/Activity/Edit.cshtml +++ b/src/Yavsc.Org/Views/Activity/Edit.cshtml @@ -19,7 +19,7 @@
- +
@@ -54,14 +54,13 @@
- -
- - +
+ +
+ + +
-
diff --git a/src/Yavsc.Org/Views/Administration/Enroll.cshtml b/src/Yavsc.Org/Views/Administration/Enroll.cshtml index 155e0e6b..78125398 100644 --- a/src/Yavsc.Org/Views/Administration/Enroll.cshtml +++ b/src/Yavsc.Org/Views/Administration/Enroll.cshtml @@ -21,7 +21,7 @@
- +
diff --git a/src/Yavsc.Org/Views/Administration/Haircut.cshtml b/src/Yavsc.Org/Views/Administration/Haircut.cshtml index 0165665c..a59ab801 100644 --- a/src/Yavsc.Org/Views/Administration/Haircut.cshtml +++ b/src/Yavsc.Org/Views/Administration/Haircut.cshtml @@ -1,7 +1,4 @@ @model HaircutAdminViewModel -@{ - ViewBag.Title = Localizer["Administration"]; -} Gestion des couleurs diff --git a/src/Yavsc.Org/Views/Administration/Role.cshtml b/src/Yavsc.Org/Views/Administration/Role.cshtml index e541f75a..68a5710f 100644 --- a/src/Yavsc.Org/Views/Administration/Role.cshtml +++ b/src/Yavsc.Org/Views/Administration/Role.cshtml @@ -21,19 +21,7 @@ @foreach (var user in Model.Users) { - @if (user.UserId==User.GetUserId()) { - You - } - @if (SiteSettings.Value.Admin.EMail == user.Email) { - Admin - } - @if (SiteSettings.Value.Owner.EMail == user.Email) { - Owner - } - @if (!String.IsNullOrWhiteSpace(user.Avatar)) - { - avatar - } + avatar @user.UserName <@(user.Email)> diff --git a/src/Yavsc.Org/Views/ApiScope/Create.cshtml b/src/Yavsc.Org/Views/ApiScope/Create.cshtml index 8297251d..5d3b9b8b 100644 --- a/src/Yavsc.Org/Views/ApiScope/Create.cshtml +++ b/src/Yavsc.Org/Views/ApiScope/Create.cshtml @@ -1,9 +1,20 @@ @model IdentityServer8.EntityFramework.Entities.ApiScope + @{ - ViewBag.Title = Localizer["ApiScope"]; + Layout = null; } + + + + + + Create + + +

ApiScope

+
@@ -53,3 +64,6 @@ + + + diff --git a/src/Yavsc.Org/Views/ApiScope/Delete.cshtml b/src/Yavsc.Org/Views/ApiScope/Delete.cshtml index abb3d26b..166e6110 100644 --- a/src/Yavsc.Org/Views/ApiScope/Delete.cshtml +++ b/src/Yavsc.Org/Views/ApiScope/Delete.cshtml @@ -1,8 +1,18 @@ @model Yavsc.Models.YavscApiScope + @{ - ViewBag.Title = Localizer["ApiScope"]; + Layout = null; } + + + + + + Delete + + +

Are you sure you want to delete this?

YavscApiScope

@@ -51,9 +61,12 @@ @Html.DisplayFor(model => model.ShowInDiscoveryDocument) - + | Back to List +
+ + diff --git a/src/Yavsc.Org/Views/ApiScope/Details.cshtml b/src/Yavsc.Org/Views/ApiScope/Details.cshtml index 9275a114..6c904ce3 100644 --- a/src/Yavsc.Org/Views/ApiScope/Details.cshtml +++ b/src/Yavsc.Org/Views/ApiScope/Details.cshtml @@ -1,8 +1,17 @@ @model Yavsc.Models.YavscApiScope + @{ - ViewBag.Title = Localizer["ApiScope"]; + Layout = null; } + + + + + + Details + +

YavscApiScope

@@ -56,3 +65,5 @@ Edit | Back to List
+ + diff --git a/src/Yavsc.Org/Views/ApiScope/Edit.cshtml b/src/Yavsc.Org/Views/ApiScope/Edit.cshtml index 1466435b..34b111d4 100644 --- a/src/Yavsc.Org/Views/ApiScope/Edit.cshtml +++ b/src/Yavsc.Org/Views/ApiScope/Edit.cshtml @@ -1,8 +1,17 @@ @model Yavsc.Models.YavscApiScope + @{ - ViewBag.Title = Localizer["ApiScope"]; + Layout = null; } + + + + + + Edit + +

YavscApiScope


@@ -56,3 +65,6 @@ + + + diff --git a/src/Yavsc.Org/Views/ApiScope/Index.cshtml b/src/Yavsc.Org/Views/ApiScope/Index.cshtml index 2c64b5c1..2d3bd6c7 100644 --- a/src/Yavsc.Org/Views/ApiScope/Index.cshtml +++ b/src/Yavsc.Org/Views/ApiScope/Index.cshtml @@ -1,10 +1,17 @@ @model IEnumerable @{ - ViewBag.Title = Localizer["ApiScope"]; - + Layout = null; } + + + + + + Index + +

Create New

@@ -68,3 +75,5 @@ } + + diff --git a/src/Yavsc.Org/Views/Blogspot/Details.cshtml b/src/Yavsc.Org/Views/Blogspot/Details.cshtml index dc0bea8a..d7d5a791 100644 --- a/src/Yavsc.Org/Views/Blogspot/Details.cshtml +++ b/src/Yavsc.Org/Views/Blogspot/Details.cshtml @@ -7,7 +7,7 @@ \ No newline at end of file + diff --git a/src/Yavsc.Org/Views/HairCutCommand/CommandConfirmation.cshtml b/src/Yavsc.Org/Views/HairCutCommand/CommandConfirmation.cshtml index 4031b7f0..ecdd8876 100644 --- a/src/Yavsc.Org/Views/HairCutCommand/CommandConfirmation.cshtml +++ b/src/Yavsc.Org/Views/HairCutCommand/CommandConfirmation.cshtml @@ -54,7 +54,7 @@
@Html.DisplayNameFor(m => m.Location)
@if (Model.Location == null) { -

Pas de lieu convenu ...

+

Pas de lieu convenu ...

} else { @Html.DisplayFor(m => m.Location) @@ -62,7 +62,7 @@
Notification
-
@if (ViewBag.GooglePayload !=null) +
@if (ViewBag.GooglePayload !=null) { @if (ViewBag.GooglePayload.success>0) {

GCM Notifications sent

@@ -85,10 +85,10 @@
@await Component.InvokeAsync("Bill", Model)
- -
@Html.DisplayNameFor(m=>m.Regularization)
+ +
@Html.DisplayNameFor(m=>m.Regularisation)
@await Component.InvokeAsync("PayPalButton", Model)
- +
diff --git a/src/Yavsc.Org/Views/Home/About.cshtml b/src/Yavsc.Org/Views/Home/About.cshtml index 39062cb2..dbde9bc5 100755 --- a/src/Yavsc.Org/Views/Home/About.cshtml +++ b/src/Yavsc.Org/Views/Home/About.cshtml @@ -1,7 +1,4 @@ @using System.Diagnostics -@{ - ViewBag.Title = Localizer["Home"]; -}

@SiteSettings.Value.Title - À Propos

@@ -70,4 +67,4 @@ Il a accÚs à la connaissance des journées connues comme libres des artistes p De plus, le droit de retrait est permanent et sa mise en oeuvre immédiate. Les artistes comme les clients peuvent demander leur désinscription, qui désactive immédiatement les publications associées à leurs informations, et programme la suppression complÚte de ces dites informations dans les quinze jours à compter de la demande, sauf demande contradictoire. L'opération est annulable, jusqu'à deux semaines aprÚs sa programmation. - \ No newline at end of file + diff --git a/src/Yavsc.Org/Views/Home/About.pt.cshtml b/src/Yavsc.Org/Views/Home/About.pt.cshtml index 487a1ab3..85b4d291 100755 --- a/src/Yavsc.Org/Views/Home/About.pt.cshtml +++ b/src/Yavsc.Org/Views/Home/About.pt.cshtml @@ -1,7 +1,3 @@ -@{ - ViewBag.Title = Localizer["Home"]; -} -

@SiteSettings.Value.Title - objetivo

@@ -93,8 +89,8 @@ A operação é anulåvel até duas semanas após a sua programação. Este é o meu site perso, uma configuração de _Yavsc_ (outro negócio muito pequeno). -* [README](https://forgejo.pschneider.fr/notazof/yavsc/blob/vnext/README.md) -* [licença: GNU GPL v3](https://forgejo.pschneider.fr/notazof/yavsc/blob/vnext/LICENSE) +* [README](https://github.com/pazof/yavsc/blob/vnext/README.md) +* [licença: GNU GPL v3](https://github.com/pazof/yavsc/blob/vnext/LICENSE) Outras instalaçÔes: @@ -109,8 +105,8 @@ Outras instalaçÔes: Yet Another Very Small Company ... -* [README](https://forgejo.pschneider.fr/notazof/yavsc/blob/vnext/README.md) -* [license: GNU FPL v3](https://forgejo.pschneider.fr/notazof/yavsc/blob/vnext/LICENSE) +* [README](https://github.com/pazof/yavsc/blob/vnext/README.md) +* [license: GNU FPL v3](https://github.com/pazof/yavsc/blob/vnext/LICENSE) @@ -118,8 +114,8 @@ Outras instalaçÔes: ## Yet Another Very Small Company : -* [README](https://forgejo.pschneider.fr/notazof/yavsc/blob/vnext/README.md) -* [license: GNU FPL v3](https://forgejo.pschneider.fr/notazof/yavsc/blob/vnext/LICENSE) +* [README](https://github.com/pazof/yavsc/blob/vnext/README.md) +* [license: GNU FPL v3](https://github.com/pazof/yavsc/blob/vnext/LICENSE) En production: diff --git a/src/Yavsc.Org/Views/Home/AboutIdentityServer.cshtml b/src/Yavsc.Org/Views/Home/AboutIdentityServer.cshtml index b77f2032..b34a19c8 100644 --- a/src/Yavsc.Org/Views/Home/AboutIdentityServer.cshtml +++ b/src/Yavsc.Org/Views/Home/AboutIdentityServer.cshtml @@ -1,7 +1,4 @@ @using System.Diagnostics -@{ - ViewBag.Title = Localizer["Home"]; -} @{ var version = FileVersionInfo.GetVersionInfo(typeof(IdentityServer8.Hosting.IdentityServerMiddleware).Assembly.Location).ProductVersion.Split('+').First(); @@ -32,4 +29,4 @@ and ready to use samples. -
\ No newline at end of file +
diff --git a/src/Yavsc.Org/Views/Home/Basket.cshtml b/src/Yavsc.Org/Views/Home/Basket.cshtml index 120b96d3..d9882ae3 100644 --- a/src/Yavsc.Org/Views/Home/Basket.cshtml +++ b/src/Yavsc.Org/Views/Home/Basket.cshtml @@ -1,7 +1,3 @@ -@{ - ViewBag.Title = Localizer["Home"]; -} - @Model BasketView
    diff --git a/src/Yavsc.Org/Views/Home/Contact.cshtml b/src/Yavsc.Org/Views/Home/Contact.cshtml index 2488e2a0..d7ae2fa7 100755 --- a/src/Yavsc.Org/Views/Home/Contact.cshtml +++ b/src/Yavsc.Org/Views/Home/Contact.cshtml @@ -1,9 +1,5 @@ @using Microsoft.IdentityModel.Protocols.Configuration @model SiteSettings -@{ - ViewBag.Title = Localizer["Home"]; -} -

    Contact

    @Model.Owner.Name

    @@ -13,4 +9,4 @@
    Support: @(Model.Admin.Name)<@(Model.Admin.EMail)>
    Marketing: @(Model.Owner.Name)<@(Model.Owner.EMail)> -
    \ No newline at end of file + diff --git a/src/Yavsc.Org/Views/Home/Privacy.cshtml b/src/Yavsc.Org/Views/Home/Privacy.cshtml index 34ae1803..2f76522b 100644 --- a/src/Yavsc.Org/Views/Home/Privacy.cshtml +++ b/src/Yavsc.Org/Views/Home/Privacy.cshtml @@ -1,6 +1,3 @@ -@{ - ViewBag.Title = Localizer["Home"]; -} = La confidentialité @@ -13,4 +10,4 @@ ne sont transmis à personne. Seul le systÚme et son link:Contact[possesseur] o De plus, le droit de retrait est permanent et sa mise en oeuvre link:/Account/Delete[immédiate]. - \ No newline at end of file + diff --git a/src/Yavsc.Org/Views/Manage/DoDirectCredit.cshtml b/src/Yavsc.Org/Views/Manage/DoDirectCredit.cshtml index b6a21b88..c51ad586 100644 --- a/src/Yavsc.Org/Views/Manage/DoDirectCredit.cshtml +++ b/src/Yavsc.Org/Views/Manage/DoDirectCredit.cshtml @@ -1,9 +1,5 @@ @model DoDirectCreditViewModel -@{ - ViewBag.Title = Localizer["Manage"]; -} -
    @@ -128,4 +124,4 @@
- \ No newline at end of file + diff --git a/src/Yavsc.Org/Views/Manage/ProfileEMailUsage.cshtml b/src/Yavsc.Org/Views/Manage/ProfileEMailUsage.cshtml index 95e70fb0..008897fe 100644 --- a/src/Yavsc.Org/Views/Manage/ProfileEMailUsage.cshtml +++ b/src/Yavsc.Org/Views/Manage/ProfileEMailUsage.cshtml @@ -1,7 +1,4 @@ @model Yavsc.ViewModels.Manage.ProfileEMailUsageViewModel -@{ - ViewBag.Title = Localizer["Manage"]; -}
@@ -20,4 +17,4 @@ -
\ No newline at end of file + diff --git a/src/Yavsc.Org/Views/Manage/SetActivity.cshtml b/src/Yavsc.Org/Views/Manage/SetActivity.cshtml index 48690359..41866484 100644 --- a/src/Yavsc.Org/Views/Manage/SetActivity.cshtml +++ b/src/Yavsc.Org/Views/Manage/SetActivity.cshtml @@ -1,5 +1,5 @@ -@model PerformerProfile -@{ ViewBag.Title = "Your performer profile"; } +@model PerformerProfile +@{ ViewBag.Title = "Your performer profile"; } @section header {