Compare commits

..
Author SHA1 Message Date
HampusandGitHub f00c6ee47a docs(http-api): name the endpoint a third-party client reads (#2564) 2026-09-06 23:50:52 +02:00
HampusandGitHub 82859dc2f6 fix(api): keep a deferral while the phone gate state is unknown (#2554) 2026-09-06 23:41:29 +02:00
HampusandGitHub 328dc06ab0 feat(installer): drive podman as well as docker (#2563) 2026-09-06 23:28:40 +02:00
HampusandGitHub ea6e4a75db fix(markdown): let a backslash escape a code fence (#2562) 2026-09-06 22:45:29 +02:00
HampusandGitHub 69ca462930 fix(app): keep popouts in the window they were opened in (#2561) 2026-09-06 22:42:32 +02:00
HampusandGitHub f38619d974 fix(app): isolate bidi usernames from message timestamps (#2560) 2026-09-06 22:41:57 +02:00
HampusandGitHub 6c0ce9369b fix(app): refresh mutual communities on membership change (#2559) 2026-09-06 22:38:31 +02:00
HampusandGitHub 00c1b19809 fix(app): inherit category mute when hiding muted channels (#2558) 2026-09-06 22:10:09 +02:00
HampusandGitHub 2fd5daf104 fix(app): keep the client active while the user is typing (#2557) 2026-09-06 21:29:06 +02:00
HampusandGitHub fbf0f6adfe fix(app): load more bookmarks as the list scrolls (#2556) 2026-09-06 21:05:57 +02:00
HampusandGitHub d91b5bec66 fix(app): show unread channels in muted collapsed categories (#2555) 2026-09-06 20:45:11 +02:00
HampusandGitHub 0f24cfb6ef ci(docs): check the installer upgrade key lists for drift (#2553) 2026-09-06 20:43:50 +02:00
HampusandGitHub 7a6691cdbe fix(installer): make the record and rollback paths trustworthy (#2552) 2026-09-06 20:36:59 +02:00
HampusandGitHub 73d3a4f843 fix(app): widen the custom status modal (#2551) 2026-09-06 20:19:28 +02:00
51 changed files with 1211 additions and 267 deletions
+10 -10
View File
@@ -157,6 +157,16 @@ LIVEKIT_API_SECRET=CHANGE_ME
#FLUXER_LIVEKIT_TCP_PORT=7881
#FLUXER_LIVEKIT_UDP_PORT=7882
# LiveKit finds the address browsers dial by asking a STUN server. A host that
# cannot reach one over UDP stops with "could not resolve external IP", and the
# address is then set by hand: put it in FLUXER_LIVEKIT_NODE_IP and set
# FLUXER_LIVEKIT_USE_EXTERNAL_IP to false. Point the two STUN entries at another
# server to keep the lookup and leave Google out of it.
#FLUXER_LIVEKIT_USE_EXTERNAL_IP=false
#FLUXER_LIVEKIT_NODE_IP=203.0.113.10
#FLUXER_LIVEKIT_STUN_PRIMARY=stun.l.google.com:19302
#FLUXER_LIVEKIT_STUN_SECONDARY=stun1.l.google.com:19302
FLUXER_KLIPY_API_KEY=
FLUXER_EMAIL_ENABLED=false
@@ -189,16 +199,6 @@ FLUXER_DISCOVERY_ENABLED=true
#FLUXER_VALKEY_MEMORY_LIMIT=256mb
#FLUXER_NATS_MEMORY_LIMIT=256mb
#FLUXER_MEILISEARCH_MEMORY_LIMIT=768mb
# LiveKit finds the address browsers dial by asking a STUN server. A host that
# cannot reach one over UDP stops with "could not resolve external IP", and the
# address is then set by hand: put it in FLUXER_LIVEKIT_NODE_IP and turn the
# lookup off. Point the two STUN entries at another server to keep the lookup
# and leave Google out of it.
#FLUXER_LIVEKIT_USE_EXTERNAL_IP=true
#FLUXER_LIVEKIT_NODE_IP=203.0.113.10
#FLUXER_LIVEKIT_STUN_PRIMARY=stun.l.google.com:19302
#FLUXER_LIVEKIT_STUN_SECONDARY=stun1.l.google.com:19302
#FLUXER_SEAWEEDFS_MEMORY_LIMIT=512mb
#FLUXER_SEAWEEDFS_INIT_MEMORY_LIMIT=128mb
#FLUXER_LIVEKIT_MEMORY_LIMIT=512mb
@@ -632,6 +632,8 @@ describe('Deferred phone verification gate', () => {
await configurePhoneGate({deferred_phone_gate_window_hours: 0.0001});
const outsideWindow = await createGuildWithInvite(harness);
await addFillerMember(outsideWindow.inviteCode);
const beforeJoin = await readFlags(subject.userId);
expect(beforeJoin & DEFERRED_PHONE_ON_COMMUNITY_JOIN).not.toBe(0);
await createBuilder(harness, subject.token).post(`/invites/${outsideWindow.inviteCode}`).expect(200).execute();
const flags = await readFlags(subject.userId);
+2 -1
View File
@@ -22705,7 +22705,8 @@
"type": "string",
"description": "Maximum number of saved messages to return (1-100, default 25)"
}
}
},
{"name": "before", "in": "query", "required": false, "schema": {"$ref": "#/components/schemas/SnowflakeType"}}
]
},
"post": {
@@ -1,6 +1,10 @@
// SPDX-License-Identifier: AGPL-3.0-or-later
let cachedEnabled = false;
// Null until a policy has actually been read. A deferral is only ever granted
// while the gate is on, so reading "not known yet" as "off" revokes it from every
// account holding one and answers their next request with the phone requirement
// the deferral exists to hold back.
let cachedEnabled: boolean | null = null;
export function resolveDeferredPhoneGateEnabled(policy: {
deferred_phone_gate_enabled: boolean;
@@ -9,7 +13,7 @@ export function resolveDeferredPhoneGateEnabled(policy: {
return policy.deferred_phone_gate_enabled && !policy.single_community_enabled;
}
export function getCachedDeferredPhoneGateEnabled(): boolean {
export function getCachedDeferredPhoneGateEnabled(): boolean | null {
return cachedEnabled;
}
+1 -1
View File
@@ -134,7 +134,7 @@ function suppressDeferredPhoneFlags(rawFlags: number): number {
if ((rawFlags & DEFERRED_PHONE_ON_COMMUNITY_JOIN) === 0) {
return rawFlags;
}
if (!getCachedDeferredPhoneGateEnabled()) {
if (getCachedDeferredPhoneGateEnabled() === false) {
return rawFlags & ~DEFERRED_PHONE_ON_COMMUNITY_JOIN;
}
return rawFlags & ~DEFERRABLE_PHONE_FLAGS;
@@ -123,9 +123,11 @@ export function UserContentController(app: HonoApp) {
'Retrieves all messages saved by the current user. Messages are saved privately for easy reference. Returns paginated list of saved messages with metadata.',
}),
async (ctx) => {
const {limit, before} = ctx.req.valid('query');
const response = await ctx.get('userContentRequestService').listSavedMessages({
userId: ctx.get('user').id,
limit: ctx.req.valid('query').limit,
limit,
before: before ? createMessageID(before) : undefined,
requestCache: ctx.get('requestCache'),
});
return ctx.json(response, 200);
@@ -46,6 +46,7 @@ interface UserMentionsReadParams {
interface SavedMessagesParams {
userId: UserID;
limit: number;
before?: MessageID;
requestCache: RequestCache;
}
@@ -108,7 +109,11 @@ export class UserContentRequestService {
}
async listSavedMessages(params: SavedMessagesParams): Promise<SavedMessageEntryListResponse> {
const entries = await this.userContentService.getSavedMessages({userId: params.userId, limit: params.limit});
const entries = await this.userContentService.getSavedMessages({
userId: params.userId,
limit: params.limit,
before: params.before,
});
const messages = entries.map((entry) => entry.message).filter((message): message is Message => message != null);
const responses = await this.userContentService.buildMessageResponsesForUser(params.userId, messages);
const responseByMessageId = new Map(responses.map((response) => [response.id, response] as const));
@@ -100,6 +100,7 @@ function createUserContentService({
}) {
const batchCalls: Array<ChannelBatchCall> = [];
const deletedSavedMessageIds: Array<string> = [];
const savedMessageListCalls: Array<{limit?: number; before?: MessageID}> = [];
const readableByChannel = new Map<string, Map<string, Message>>();
for (const entry of readable) {
const key = entry.channelId.toString();
@@ -109,7 +110,10 @@ function createUserContentService({
}
const userRepository = {
listRecentMentions: async () => entries,
listSavedMessages: async () => entries,
listSavedMessages: async (_userId: UserID, limit?: number, before?: MessageID) => {
savedMessageListCalls.push({limit, before});
return entries;
},
deleteSavedMessage: async (_userId: UserID, messageId: MessageID) => {
deletedSavedMessageIds.push(messageId.toString());
},
@@ -146,7 +150,7 @@ function createUserContentService({
{} as unknown as KVBulkMessageDeletionQueueService,
{} as unknown as LimitConfigService,
);
return {service, batchCalls, deletedSavedMessageIds};
return {service, batchCalls, deletedSavedMessageIds, savedMessageListCalls};
}
const CHANNEL_A = createChannelID(100n);
@@ -238,6 +242,15 @@ describe('getRecentMentions', () => {
});
describe('getSavedMessages', () => {
it('passes the page cursor to the repository', async () => {
const entries = [{channelId: CHANNEL_A, messageId: createMessageID(11n)}];
const {service, savedMessageListCalls} = createUserContentService({entries, readable: entries});
await service.getSavedMessages({userId: VIEWER_ID, limit: 50, before: createMessageID(20n)});
expect(savedMessageListCalls).toEqual([{limit: 50, before: createMessageID(20n)}]);
});
it('marks every entry of an unreachable channel as missing permissions without deleting it', async () => {
const entries = [
{channelId: CHANNEL_A, messageId: createMessageID(11n)},
@@ -229,8 +229,16 @@ export class UserContentService {
);
}
async getSavedMessages({userId, limit}: {userId: UserID; limit: number}): Promise<Array<SavedMessageEntry>> {
const savedMessages = await this.userRepository.listSavedMessages(userId, limit);
async getSavedMessages({
userId,
limit,
before,
}: {
userId: UserID;
limit: number;
before?: MessageID;
}): Promise<Array<SavedMessageEntry>> {
const savedMessages = await this.userRepository.listSavedMessages(userId, limit, before);
const messagesByChannel = await this.readMessagesByChannel(userId, savedMessages);
const results: Array<SavedMessageEntry> = [];
const staleMessageIds: Array<MessageID> = [];
@@ -338,9 +338,7 @@ export const ChannelListContent = observer(({guild, scrollY}: {guild: Guild; scr
const unreadCount = ReadStates.getUnreadCount(channelId);
const hasUnread = ReadStates.hasUnread(channelId);
const mentionCount = ReadStates.getMentionCount(channelId);
const isMuted =
UserGuildSettings.isParentCategoryMuted(guild.id, channelId) ||
UserGuildSettings.isChannelDirectlyMuted(guild.id, channelId);
const isMuted = UserGuildSettings.isChannelDirectlyMuted(guild.id, channelId);
const channel = Channels.getChannel(channelId);
const unreadBadgesLevel = channel
? UserGuildSettings.resolvedUnreadBadgesLevel({
@@ -364,18 +362,21 @@ export const ChannelListContent = observer(({guild, scrollY}: {guild: Guild; scr
for (const group of channelGroups) {
const isCollapsed = group.category ? (collapsedCategories?.has(group.category.id) ?? false) : false;
const isNullSpace = !group.category;
const isCategoryMuted = group.category
? UserGuildSettings.isChannelDirectlyMuted(guild.id, group.category.id)
: false;
const isCategoryMuted =
hideMutedChannels && group.category
? UserGuildSettings.isChannelDirectlyMuted(guild.id, group.category.id)
: false;
let filteredTextChannels: Array<Channel>;
let filteredVoiceChannels: Array<Channel>;
if (hideMutedChannels) {
filteredTextChannels = [];
for (const ch of group.textChannels) {
const isMuted = UserGuildSettings.isChannelDirectlyMuted(guild.id, ch.id);
const isChannelMuted = UserGuildSettings.isChannelDirectlyMuted(guild.id, ch.id);
const isMuted = isCategoryMuted || isChannelMuted;
if (
shouldShowChannelWhenHidingMutedChannels({
isMuted,
isCategoryMuted,
isChannelMuted,
isSelected: ch.id === selectedChannelInGuildId,
isConnected: false,
hasVisibleUnread: isMuted && hasVisibleUnreadInChannel(ch.id),
@@ -386,10 +387,12 @@ export const ChannelListContent = observer(({guild, scrollY}: {guild: Guild; scr
}
filteredVoiceChannels = [];
for (const ch of group.voiceChannels) {
const isMuted = UserGuildSettings.isChannelDirectlyMuted(guild.id, ch.id);
const isChannelMuted = UserGuildSettings.isChannelDirectlyMuted(guild.id, ch.id);
const isMuted = isCategoryMuted || isChannelMuted;
if (
shouldShowChannelWhenHidingMutedChannels({
isMuted,
isCategoryMuted,
isChannelMuted,
isSelected: ch.id === selectedChannelInGuildId,
isConnected: ch.id === connectedChannelId,
hasVisibleUnread: isMuted && hasVisibleUnreadInChannel(ch.id),
@@ -411,8 +414,8 @@ export const ChannelListContent = observer(({guild, scrollY}: {guild: Guild; scr
for (const ch of filteredTextChannels) {
if (
shouldShowChannelInCollapsedCategory({
isCategoryMuted,
isSelected: ch.id === showTextSelected,
isConnected: false,
hasVisibleUnread: hasVisibleUnreadInChannel(ch.id),
})
) {
@@ -442,8 +445,8 @@ export const ChannelListContent = observer(({guild, scrollY}: {guild: Guild; scr
for (const ch of filteredVoiceChannels) {
if (
shouldShowChannelInCollapsedCategory({
isCategoryMuted,
isSelected: ch.id === selectedChannelInGuildId,
isConnected: ch.id === connectedChannelId,
hasVisibleUnread: hasVisibleUnreadInChannel(ch.id),
})
) {
@@ -11,7 +11,8 @@ describe('shouldShowChannelWhenHidingMutedChannels', () => {
it('keeps muted channels with visible unread state so mentions are findable', () => {
expect(
shouldShowChannelWhenHidingMutedChannels({
isMuted: true,
isCategoryMuted: false,
isChannelMuted: true,
isSelected: false,
isConnected: false,
hasVisibleUnread: true,
@@ -22,7 +23,8 @@ describe('shouldShowChannelWhenHidingMutedChannels', () => {
it('hides muted channels without visible unread state', () => {
expect(
shouldShowChannelWhenHidingMutedChannels({
isMuted: true,
isCategoryMuted: false,
isChannelMuted: true,
isSelected: false,
isConnected: false,
hasVisibleUnread: false,
@@ -30,10 +32,35 @@ describe('shouldShowChannelWhenHidingMutedChannels', () => {
).toBe(false);
});
it('inherits the mute from a muted category', () => {
expect(
shouldShowChannelWhenHidingMutedChannels({
isCategoryMuted: true,
isChannelMuted: false,
isSelected: false,
isConnected: false,
hasVisibleUnread: false,
}),
).toBe(false);
});
it('keeps channels of a muted category that have visible unread state', () => {
expect(
shouldShowChannelWhenHidingMutedChannels({
isCategoryMuted: true,
isChannelMuted: false,
isSelected: false,
isConnected: false,
hasVisibleUnread: true,
}),
).toBe(true);
});
it('keeps selected and connected muted channels visible', () => {
expect(
shouldShowChannelWhenHidingMutedChannels({
isMuted: true,
isCategoryMuted: true,
isChannelMuted: true,
isSelected: true,
isConnected: false,
hasVisibleUnread: false,
@@ -41,7 +68,8 @@ describe('shouldShowChannelWhenHidingMutedChannels', () => {
).toBe(true);
expect(
shouldShowChannelWhenHidingMutedChannels({
isMuted: true,
isCategoryMuted: true,
isChannelMuted: false,
isSelected: false,
isConnected: true,
hasVisibleUnread: false,
@@ -52,7 +80,8 @@ describe('shouldShowChannelWhenHidingMutedChannels', () => {
it('keeps unmuted channels visible', () => {
expect(
shouldShowChannelWhenHidingMutedChannels({
isMuted: false,
isCategoryMuted: false,
isChannelMuted: false,
isSelected: false,
isConnected: false,
hasVisibleUnread: false,
@@ -94,27 +123,37 @@ describe('shouldShowChannelInCollapsedCategory', () => {
it('keeps visible unread channels reachable in collapsed categories', () => {
expect(
shouldShowChannelInCollapsedCategory({
isCategoryMuted: false,
isSelected: false,
isConnected: false,
hasVisibleUnread: true,
}),
).toBe(true);
});
it('does not reveal unread channels from muted collapsed categories unless selected', () => {
it('keeps selected and connected channels visible without unread state', () => {
expect(
shouldShowChannelInCollapsedCategory({
isCategoryMuted: true,
isSelected: false,
hasVisibleUnread: true,
}),
).toBe(false);
expect(
shouldShowChannelInCollapsedCategory({
isCategoryMuted: true,
isSelected: true,
isConnected: false,
hasVisibleUnread: false,
}),
).toBe(true);
expect(
shouldShowChannelInCollapsedCategory({
isSelected: false,
isConnected: true,
hasVisibleUnread: false,
}),
).toBe(true);
});
it('hides read channels in collapsed categories', () => {
expect(
shouldShowChannelInCollapsedCategory({
isSelected: false,
isConnected: false,
hasVisibleUnread: false,
}),
).toBe(false);
});
});
@@ -1,19 +1,21 @@
// SPDX-License-Identifier: AGPL-3.0-or-later
export interface HiddenMutedChannelVisibilityInput {
isMuted: boolean;
isCategoryMuted: boolean;
isChannelMuted: boolean;
isSelected: boolean;
isConnected: boolean;
hasVisibleUnread: boolean;
}
export function shouldShowChannelWhenHidingMutedChannels({
isMuted,
isCategoryMuted,
isChannelMuted,
isSelected,
isConnected,
hasVisibleUnread,
}: HiddenMutedChannelVisibilityInput): boolean {
return isSelected || isConnected || !isMuted || hasVisibleUnread;
return isSelected || isConnected || !(isCategoryMuted || isChannelMuted) || hasVisibleUnread;
}
export interface HiddenMutedCategoryVisibilityInput {
@@ -29,15 +31,15 @@ export function shouldShowCategoryWhenHidingMutedChannels({
}
export interface CollapsedCategoryChannelVisibilityInput {
isCategoryMuted: boolean;
isSelected: boolean;
isConnected: boolean;
hasVisibleUnread: boolean;
}
export function shouldShowChannelInCollapsedCategory({
isCategoryMuted,
isSelected,
isConnected,
hasVisibleUnread,
}: CollapsedCategoryChannelVisibilityInput): boolean {
return isSelected || (!isCategoryMuted && hasVisibleUnread);
return isSelected || isConnected || hasVisibleUnread;
}
@@ -41,6 +41,13 @@
padding: 0 1rem 1rem;
}
.loadingState {
display: flex;
height: 5rem;
align-items: center;
justify-content: center;
}
.messagePreviewCard {
position: relative;
cursor: pointer;
@@ -17,6 +17,7 @@ import {focusChannelTextareaAfterNavigation} from '@app/features/messaging/utils
import {goToMessage} from '@app/features/messaging/utils/MessageNavigator';
import {BottomSheet} from '@app/features/ui/bottom_sheet/BottomSheet';
import {Scroller, type ScrollerHandle} from '@app/features/ui/components/Scroller';
import {Spinner} from '@app/features/ui/components/Spinner';
import type {MenuGroupType} from '@app/features/ui/menu_bottom_sheet/MenuBottomSheet';
import {MenuBottomSheet} from '@app/features/ui/menu_bottom_sheet/MenuBottomSheet';
import {MessagePreviewContext} from '@fluxer/constants/src/ChannelConstants';
@@ -44,6 +45,8 @@ export const BookmarksBottomSheet = observer(({isOpen, onClose}: BookmarksBottom
const {i18n} = useLingui();
const {savedMessages, missingSavedMessages, fetched} = SavedMessages;
const hasBookmarks = savedMessages.length > 0 || missingSavedMessages.length > 0;
const hasMore = SavedMessages.getHasMore();
const isLoadingMore = SavedMessages.getIsLoadingMore();
const scrollerRef = useRef<ScrollerHandle | null>(null);
const resolveBookmarksScrollSurface = useMemo(() => () => scrollerRef.current?.getViewportElement() ?? null, []);
const [selectedMessage, setSelectedMessage] = useState<Message | null>(null);
@@ -61,6 +64,13 @@ export const BookmarksBottomSheet = observer(({isOpen, onClose}: BookmarksBottom
useMessageListKeyboardNavigation({
containerRef: scrollerRef,
});
const handleScroll = (event: React.UIEvent<HTMLDivElement>) => {
const target = event.currentTarget;
const scrollPercentage = (target.scrollTop + target.offsetHeight) / target.scrollHeight;
if (scrollPercentage > 0.8 && hasMore && !isLoadingMore) {
SavedMessageCommands.loadMore();
}
};
const handleLongPress = (message: Message) => {
setSelectedMessage(message);
setMenuOpen(true);
@@ -127,6 +137,7 @@ export const BookmarksBottomSheet = observer(({isOpen, onClose}: BookmarksBottom
<NearViewportSurfaceContext.Provider value={resolveBookmarksScrollSurface}>
<Scroller
className={styles.messageList}
onScroll={handleScroll}
key="bookmarks-bottom-sheet-scroller"
ref={scrollerRef}
onCopy={onCopySelectedMessages}
@@ -157,6 +168,11 @@ export const BookmarksBottomSheet = observer(({isOpen, onClose}: BookmarksBottom
/>
))}
</div>
{isLoadingMore && (
<div className={styles.loadingState} data-flx="channel.bookmarks-bottom-sheet.loading-state">
<Spinner data-flx="channel.bookmarks-bottom-sheet.spinner" />
</div>
)}
</Scroller>
</NearViewportSurfaceContext.Provider>
) : (
@@ -23,6 +23,7 @@ import ReadStates from '@app/features/read_state/state/ReadStates';
import QuickSwitcher from '@app/features/search/state/QuickSwitcher';
import Nagbar from '@app/features/ui/state/Nagbar';
import UserGuildSettings from '@app/features/user/state/UserGuildSettings';
import UserProfile from '@app/features/user/state/UserProfile';
import MediaEngine from '@app/features/voice/engine/MediaEngineFacade';
import {FAVORITES_GUILD_ID} from '@fluxer/constants/src/AppConstants';
@@ -51,6 +52,7 @@ export function handleGuildCreate(data: GuildReadyData, _context: GatewayHandler
GuildCount.handleGuildCreate(data);
if (!isSync) {
MemberSidebar.handleGuildCreate(data.id);
UserProfile.handleGuildCreate();
}
if (!data.unavailable) {
Channels.handleGuildCreate(data);
@@ -20,6 +20,7 @@ import MentionFeed from '@app/features/notification/state/MentionFeed';
import Permission from '@app/features/permissions/state/Permission';
import Presence from '@app/features/presence/state/Presence';
import QuickSwitcher from '@app/features/search/state/QuickSwitcher';
import UserProfile from '@app/features/user/state/UserProfile';
import MediaEngine from '@app/features/voice/engine/MediaEngineFacade';
import Webhooks from '@app/features/webhook/state/Webhooks';
import type {Guild} from '@fluxer/schema/src/domains/guild/GuildResponseSchemas';
@@ -52,5 +53,6 @@ export function handleGuildDelete(data: GuildDeletePayload, _context: GatewayHan
Messages.handleGuildUnavailable(data.id, data.unavailable ?? false);
Messages.handleCleanup();
MentionFeed.handleGuildDelete(data.id);
UserProfile.handleGuildDelete(data.unavailable);
QuickSwitcher.recomputeIfOpen();
}
@@ -6,6 +6,7 @@ import GuildMembers from '@app/features/member/state/GuildMembers';
import MemberSearch from '@app/features/member/state/MemberSearch';
import Permission from '@app/features/permissions/state/Permission';
import Presence from '@app/features/presence/state/Presence';
import UserProfile from '@app/features/user/state/UserProfile';
import Users from '@app/features/user/state/Users';
import type {GuildMemberData} from '@fluxer/schema/src/domains/guild/GuildMemberSchemas';
import type {User} from '@fluxer/schema/src/domains/user/UserResponseSchemas';
@@ -21,4 +22,5 @@ export function handleGuildMemberAdd(data: GuildMemberAddPayload, _context: Gate
GuildVerification.handleGuildMemberUpdate(data.guild_id);
Presence.handleGuildMemberAdd(data.guild_id, data.user.id);
MemberSearch.handleMemberAdd(data.guild_id, data.user.id);
UserProfile.handleGuildMemberAdd(data.user.id);
}
@@ -5,6 +5,7 @@ import GuildMembers from '@app/features/member/state/GuildMembers';
import MemberSearch from '@app/features/member/state/MemberSearch';
import Permission from '@app/features/permissions/state/Permission';
import Presence from '@app/features/presence/state/Presence';
import UserProfile from '@app/features/user/state/UserProfile';
import Users from '@app/features/user/state/Users';
import type {UserPartial} from '@fluxer/schema/src/domains/user/UserResponseSchemas';
@@ -19,4 +20,5 @@ export function handleGuildMemberRemove(data: GuildMemberRemovePayload, _context
GuildMembers.handleMemberRemove(data.guild_id, data.user.id);
Permission.handleGuildMemberUpdate(data.user.id);
Presence.handleGuildMemberRemove(data.guild_id, data.user.id);
UserProfile.handleGuildMemberRemove(data.user.id);
}
@@ -13,6 +13,7 @@ import {modal} from '@app/features/ui/commands/ModalCommands';
import * as ToastCommands from '@app/features/ui/commands/ToastCommands';
import Users from '@app/features/user/state/Users';
import {APIErrorCodes} from '@fluxer/constants/src/ApiErrorCodes';
import {SAVED_MESSAGES_PAGE_SIZE} from '@fluxer/constants/src/LimitConstants';
import type {I18n} from '@lingui/core';
import {msg} from '@lingui/core/macro';
@@ -31,8 +32,14 @@ interface SaveMessageRequest {
message_id: string;
}
async function requestSavedMessages(): Promise<Array<SavedMessageEntryWire>> {
const response = await http.get<Array<SavedMessageEntryWire>>(Endpoints.USER_SAVED_MESSAGES);
interface SavedMessagesFetchOptions {
before?: string;
}
async function requestSavedMessages(options: SavedMessagesFetchOptions = {}): Promise<Array<SavedMessageEntryWire>> {
const response = await http.get<Array<SavedMessageEntryWire>>(Endpoints.USER_SAVED_MESSAGES, {
query: {limit: SAVED_MESSAGES_PAGE_SIZE, ...options},
});
return response.body ?? [];
}
@@ -78,20 +85,37 @@ function showMaxBookmarksModal(): boolean {
return true;
}
export async function fetch(): Promise<Array<SavedMessageEntry>> {
async function runSavedMessagesFetch(
label: string,
append: boolean,
options: SavedMessagesFetchOptions = {},
): Promise<Array<SavedMessageEntry>> {
const requestId = SavedMessages.handleFetchPending();
try {
logger.debug('Fetching saved messages');
const entries = savedMessageEntries(await requestSavedMessages());
SavedMessages.fetchSuccess(entries);
logger.debug(label);
const entries = savedMessageEntries(await requestSavedMessages(options));
SavedMessages.fetchSuccess(requestId, entries, append);
logger.debug(`Successfully fetched ${entries.length} saved messages`);
return entries;
} catch (error) {
SavedMessages.fetchError();
logger.error('Failed to fetch saved messages:', error);
SavedMessages.fetchError(requestId, append);
logger.error(`${label} failed:`, error);
throw error;
}
}
export async function fetch(): Promise<Array<SavedMessageEntry>> {
return runSavedMessagesFetch('Fetching saved messages', false);
}
export async function loadMore(): Promise<Array<SavedMessageEntry>> {
const before = SavedMessages.getCursor();
if (!before || !SavedMessages.getHasMore() || SavedMessages.getIsLoadingMore()) {
return [];
}
return runSavedMessagesFetch(`Loading more saved messages before ${before}`, true, {before});
}
export async function create(i18n: I18n, channelId: string, messageId: string): Promise<void> {
try {
logger.debug(`Saving message ${messageId} from channel ${channelId}`);
@@ -15,13 +15,14 @@ import {focusChannelTextareaAfterNavigation} from '@app/features/messaging/utils
import {goToMessage} from '@app/features/messaging/utils/MessageNavigator';
import * as RouterUtils from '@app/features/navigation/utils/RouterUtils';
import {Scroller, type ScrollerHandle} from '@app/features/ui/components/Scroller';
import {Spinner} from '@app/features/ui/components/Spinner';
import {MessagePreviewContext} from '@fluxer/constants/src/ChannelConstants';
import {msg} from '@lingui/core/macro';
import {useLingui} from '@lingui/react/macro';
import {FlagCheckeredIcon, SparkleIcon} from '@phosphor-icons/react';
import {observer} from 'mobx-react-lite';
import type React from 'react';
import {useMemo, useRef} from 'react';
import {useCallback, useMemo, useRef} from 'react';
const YOU_VE_REACHED_THE_END_DESCRIPTOR = msg({
message: "You've reached the end",
@@ -37,6 +38,9 @@ interface MessageListPageProps {
endStateDescription: string;
renderActionButtons: (message: Message) => React.ReactNode;
renderMissingMessage?: (message: Message) => React.ReactNode;
hasMore?: boolean;
isLoadingMore?: boolean;
onLoadMore?: () => void;
}
export const MessageListPage = observer(
@@ -49,6 +53,9 @@ export const MessageListPage = observer(
endStateDescription,
renderActionButtons,
renderMissingMessage,
hasMore = false,
isLoadingMore = false,
onLoadMore,
}: MessageListPageProps) => {
const {i18n} = useLingui();
const scrollerRef = useRef<ScrollerHandle | null>(null);
@@ -66,6 +73,16 @@ export const MessageListPage = observer(
containerRef: scrollerRef,
allowWhenInactive: true,
});
const handleScroll = useCallback(
(event: React.UIEvent<HTMLDivElement>) => {
const target = event.currentTarget;
const scrollPercentage = (target.scrollTop + target.offsetHeight) / target.scrollHeight;
if (scrollPercentage > 0.8 && hasMore && !isLoadingMore) {
onLoadMore?.();
}
},
[hasMore, isLoadingMore, onLoadMore],
);
return (
<div className={styles.container} data-flx="messaging.message-list-page.container">
<ChannelHeader
@@ -78,6 +95,7 @@ export const MessageListPage = observer(
<NearViewportSurfaceContext.Provider value={resolveListPageScrollSurface}>
<Scroller
className={styles.scroller}
onScroll={handleScroll}
key="message-list-page-scroller"
ref={scrollerRef}
onCopy={onCopySelectedMessages}
@@ -127,25 +145,32 @@ export const MessageListPage = observer(
</div>
);
})}
<div className={styles.endState} data-flx="messaging.message-list-page.end-state">
<div className={styles.endStateContent} data-flx="messaging.message-list-page.end-state-content">
<FlagCheckeredIcon
className={styles.endStateIcon}
data-flx="messaging.message-list-page.end-state-icon"
/>
<div className={styles.endStateText} data-flx="messaging.message-list-page.end-state-text">
<h3 className={styles.endStateTitle} data-flx="messaging.message-list-page.end-state-title">
{i18n._(YOU_VE_REACHED_THE_END_DESCRIPTOR)}
</h3>
<p
className={styles.endStateDescription}
data-flx="messaging.message-list-page.end-state-description"
>
{endStateDescription}
</p>
{isLoadingMore && (
<div className={previewStyles.loadingState} data-flx="messaging.message-list-page.loading-state">
<Spinner data-flx="messaging.message-list-page.spinner" />
</div>
)}
{!hasMore && !isLoadingMore && (
<div className={styles.endState} data-flx="messaging.message-list-page.end-state">
<div className={styles.endStateContent} data-flx="messaging.message-list-page.end-state-content">
<FlagCheckeredIcon
className={styles.endStateIcon}
data-flx="messaging.message-list-page.end-state-icon"
/>
<div className={styles.endStateText} data-flx="messaging.message-list-page.end-state-text">
<h3 className={styles.endStateTitle} data-flx="messaging.message-list-page.end-state-title">
{i18n._(YOU_VE_REACHED_THE_END_DESCRIPTOR)}
</h3>
<p
className={styles.endStateDescription}
data-flx="messaging.message-list-page.end-state-description"
>
{endStateDescription}
</p>
</div>
</div>
</div>
</div>
)}
</Scroller>
</NearViewportSurfaceContext.Provider>
) : (
@@ -39,6 +39,8 @@ const THERE_S_NOTHING_MORE_TO_SEE_HERE_DESCRIPTOR = msg({
export const SavedMessagesPage = observer(() => {
const {i18n} = useLingui();
const {savedMessages, missingSavedMessages, fetched} = SavedMessages;
const hasMore = SavedMessages.getHasMore();
const isLoadingMore = SavedMessages.getIsLoadingMore();
useEffect(() => {
if (!fetched) {
SavedMessageCommands.fetch();
@@ -91,6 +93,9 @@ export const SavedMessagesPage = observer(() => {
emptyStateDescription={i18n._(BOOKMARK_MESSAGES_TO_SAVE_THEM_FOR_LATER_DESCRIPTOR)}
endStateDescription={i18n._(THERE_S_NOTHING_MORE_TO_SEE_HERE_DESCRIPTOR)}
renderActionButtons={renderActionButtons}
hasMore={hasMore}
isLoadingMore={isLoadingMore}
onLoadMore={SavedMessageCommands.loadMore}
data-flx="messaging.saved-messages-page.message-list-page"
/>
</div>
@@ -49,6 +49,8 @@ const readonlyBehaviorOverrides = {
export const SavedMessagesContent = observer(() => {
const {i18n} = useLingui();
const {savedMessages, missingSavedMessages, fetched} = SavedMessages;
const hasMore = SavedMessages.getHasMore();
const isLoadingMore = SavedMessages.getIsLoadingMore();
const scrollerRef = useRef<ScrollerHandle | null>(null);
const resolveSavedScrollSurface = useMemo(() => () => scrollerRef.current?.getViewportElement() ?? null, []);
const onCopySelectedMessages = useMessageSelectionCopyForMessages<HTMLDivElement>(savedMessages);
@@ -79,6 +81,16 @@ export const SavedMessagesContent = observer(() => {
goToMessage(channelId, messageId);
InboxCommands.closeInboxAndFocusChannelTextarea(channelId);
}, []);
const handleScroll = useCallback(
(event: React.UIEvent<HTMLDivElement>) => {
const target = event.currentTarget;
const scrollPercentage = (target.scrollTop + target.offsetHeight) / target.scrollHeight;
if (scrollPercentage > 0.8 && hasMore && !isLoadingMore) {
SavedMessageCommands.loadMore();
}
},
[hasMore, isLoadingMore],
);
if (!fetched) {
return (
<div className={previewStyles.emptyState} data-flx="messaging.saved-messages-content.div">
@@ -110,6 +122,7 @@ export const SavedMessagesContent = observer(() => {
<NearViewportSurfaceContext.Provider value={resolveSavedScrollSurface}>
<Scroller
className={styles.scroller}
onScroll={handleScroll}
key="saved-messages-scroller"
ref={scrollerRef}
onCopy={onCopySelectedMessages}
@@ -189,22 +202,29 @@ export const SavedMessagesContent = observer(() => {
</div>
);
})}
<div className={previewStyles.endState} data-flx="messaging.saved-messages-content.div--7">
<div className={previewStyles.endStateContent} data-flx="messaging.saved-messages-content.div--8">
<FlagCheckeredIcon
className={previewStyles.endStateIcon}
data-flx="messaging.saved-messages-content.flag-checkered-icon"
/>
<div className={previewStyles.endStateTextContainer} data-flx="messaging.saved-messages-content.div--9">
<h3 className={previewStyles.endStateTitle} data-flx="messaging.saved-messages-content.h3--2">
{i18n._(YOU_VE_REACHED_THE_END_DESCRIPTOR)}
</h3>
<p className={previewStyles.endStateDescription} data-flx="messaging.saved-messages-content.p--2">
{i18n._(THERE_S_NOTHING_MORE_TO_SEE_HERE_DESCRIPTOR)}
</p>
{isLoadingMore && (
<div className={previewStyles.loadingState} data-flx="messaging.saved-messages-content.div--10">
<Spinner data-flx="messaging.saved-messages-content.spinner--2" />
</div>
)}
{!hasMore && !isLoadingMore && (
<div className={previewStyles.endState} data-flx="messaging.saved-messages-content.div--7">
<div className={previewStyles.endStateContent} data-flx="messaging.saved-messages-content.div--8">
<FlagCheckeredIcon
className={previewStyles.endStateIcon}
data-flx="messaging.saved-messages-content.flag-checkered-icon"
/>
<div className={previewStyles.endStateTextContainer} data-flx="messaging.saved-messages-content.div--9">
<h3 className={previewStyles.endStateTitle} data-flx="messaging.saved-messages-content.h3--2">
{i18n._(YOU_VE_REACHED_THE_END_DESCRIPTOR)}
</h3>
<p className={previewStyles.endStateDescription} data-flx="messaging.saved-messages-content.p--2">
{i18n._(THERE_S_NOTHING_MORE_TO_SEE_HERE_DESCRIPTOR)}
</p>
</div>
</div>
</div>
</div>
)}
</Scroller>
</NearViewportSurfaceContext.Provider>
);
@@ -0,0 +1,80 @@
// SPDX-License-Identifier: AGPL-3.0-or-later
import {SavedMessageEntry} from '@app/features/messaging/models/SavedMessageEntry';
import SavedMessages from '@app/features/messaging/state/SavedMessages';
import {SAVED_MESSAGES_PAGE_SIZE} from '@fluxer/constants/src/LimitConstants';
import {beforeEach, describe, expect, it, vi} from 'vitest';
vi.mock('@app/features/messaging/models/MessagingMessage', () => ({
Message: class {
readonly id: string;
constructor(data: {id: string}) {
this.id = data.id;
}
},
}));
function entryPage(startId: number, count: number): Array<SavedMessageEntry> {
return Array.from({length: count}, (_unused, index) =>
SavedMessageEntry.fromResponse({
id: String(startId - index),
channel_id: '10',
message_id: String(startId - index),
status: 'missing_permissions',
message: null,
}),
);
}
describe('SavedMessages pagination', () => {
beforeEach(() => {
SavedMessages.handleGatewayReady();
});
it('reports more pages while a full page comes back and tracks the oldest entry', () => {
const requestId = SavedMessages.handleFetchPending();
SavedMessages.fetchSuccess(requestId, entryPage(1000, SAVED_MESSAGES_PAGE_SIZE), false);
expect(SavedMessages.getHasMore()).toBe(true);
expect(SavedMessages.getIsLoadingMore()).toBe(false);
expect(SavedMessages.getCursor()).toBe(String(1000 - (SAVED_MESSAGES_PAGE_SIZE - 1)));
});
it('appends the next page instead of replacing the loaded one', () => {
const first = SavedMessages.handleFetchPending();
SavedMessages.fetchSuccess(first, entryPage(1000, SAVED_MESSAGES_PAGE_SIZE), false);
const second = SavedMessages.handleFetchPending();
SavedMessages.fetchSuccess(second, entryPage(900, 10), true);
expect(SavedMessages.getMissingEntries()).toHaveLength(SAVED_MESSAGES_PAGE_SIZE + 10);
expect(SavedMessages.getHasMore()).toBe(false);
expect(SavedMessages.getCursor()).toBe('891');
});
it('ignores a page that a newer request has superseded', () => {
const stale = SavedMessages.handleFetchPending();
SavedMessages.handleFetchPending();
SavedMessages.fetchSuccess(stale, entryPage(1000, 5), false);
expect(SavedMessages.fetched).toBe(false);
expect(SavedMessages.getMissingEntries()).toHaveLength(0);
});
it('keeps the loaded pages when loading more fails', () => {
const first = SavedMessages.handleFetchPending();
SavedMessages.fetchSuccess(first, entryPage(1000, SAVED_MESSAGES_PAGE_SIZE), false);
const second = SavedMessages.handleFetchPending();
SavedMessages.fetchError(second, true);
expect(SavedMessages.getMissingEntries()).toHaveLength(SAVED_MESSAGES_PAGE_SIZE);
expect(SavedMessages.getIsLoadingMore()).toBe(false);
expect(SavedMessages.fetched).toBe(true);
});
it('clears everything when the first page fails', () => {
const first = SavedMessages.handleFetchPending();
SavedMessages.fetchSuccess(first, entryPage(1000, 5), false);
const retry = SavedMessages.handleFetchPending();
SavedMessages.fetchError(retry, false);
expect(SavedMessages.getMissingEntries()).toHaveLength(0);
expect(SavedMessages.fetched).toBe(false);
expect(SavedMessages.getCursor()).toBeNull();
expect(SavedMessages.getHasMore()).toBe(true);
});
});
@@ -2,14 +2,23 @@
import {Message} from '@app/features/messaging/models/MessagingMessage';
import type {SavedMessageEntry, SavedMessageMissingEntry} from '@app/features/messaging/models/SavedMessageEntry';
import {SAVED_MESSAGES_PAGE_SIZE} from '@fluxer/constants/src/LimitConstants';
import type {Channel} from '@fluxer/schema/src/domains/channel/ChannelSchemas';
import type {Message as WireMessage} from '@fluxer/schema/src/domains/message/MessageResponseSchemas';
import {makeAutoObservable} from 'mobx';
function byIdDescending(a: {id: string}, b: {id: string}): number {
return b.id > a.id ? 1 : a.id > b.id ? -1 : 0;
}
class SavedMessages {
savedMessages: Array<Message> = [];
missingSavedMessages: Array<SavedMessageMissingEntry> = [];
fetched = false;
hasMore = true;
isLoadingMore = false;
cursor: string | null = null;
private fetchGeneration = 0;
constructor() {
makeAutoObservable(this, {}, {autoBind: true});
@@ -26,27 +35,74 @@ class SavedMessages {
return this.missingSavedMessages.slice();
}
fetchSuccess(entries: ReadonlyArray<SavedMessageEntry>): void {
this.savedMessages = entries
getHasMore(): boolean {
return this.hasMore;
}
getIsLoadingMore(): boolean {
return this.isLoadingMore;
}
getCursor(): string | null {
return this.cursor;
}
handleFetchPending(): number {
this.isLoadingMore = true;
this.fetchGeneration++;
return this.fetchGeneration;
}
fetchSuccess(requestId: number, entries: ReadonlyArray<SavedMessageEntry>, append: boolean): void {
if (requestId !== this.fetchGeneration) return;
const available = entries
.filter((entry) => entry.status === 'available' && entry.message)
.map((entry) => entry.message!)
.sort((a, b) => (b.id > a.id ? 1 : a.id > b.id ? -1 : 0));
this.missingSavedMessages = entries
.map((entry) => entry.message!);
const missing = entries
.filter((entry) => entry.status === 'missing_permissions' || entry.message === null)
.map((entry) => entry.toMissingEntry());
if (append) {
const knownMessageIds = new Set(this.savedMessages.map((message) => message.id));
const knownMissingIds = new Set(this.missingSavedMessages.map((entry) => entry.id));
this.savedMessages = [
...this.savedMessages,
...available.filter((message) => !knownMessageIds.has(message.id)),
].sort(byIdDescending);
this.missingSavedMessages = [
...this.missingSavedMessages,
...missing.filter((entry) => !knownMissingIds.has(entry.id)),
];
} else {
this.savedMessages = available.sort(byIdDescending);
this.missingSavedMessages = missing;
}
if (entries.length > 0) {
this.cursor = entries[entries.length - 1].messageId;
}
this.hasMore = entries.length === SAVED_MESSAGES_PAGE_SIZE;
this.isLoadingMore = false;
this.fetched = true;
}
fetchError(): void {
fetchError(requestId: number, append: boolean): void {
if (requestId !== this.fetchGeneration) return;
this.isLoadingMore = false;
if (append) return;
this.reset();
}
private reset(): void {
this.savedMessages = [];
this.missingSavedMessages = [];
this.fetched = false;
this.hasMore = true;
this.isLoadingMore = false;
this.cursor = null;
}
handleGatewayReady(): void {
this.savedMessages = [];
this.missingSavedMessages = [];
this.fetched = false;
this.reset();
this.fetchGeneration++;
}
handleChannelDelete(channel: Channel): void {
@@ -428,6 +428,7 @@
max-inline-size: none;
overflow: visible;
white-space: nowrap;
unicode-bidi: plaintext;
user-select: text;
-webkit-user-select: text;
}
@@ -505,6 +506,7 @@
font-weight: 400;
color: var(--message-timestamp-color);
line-height: var(--message-line-height);
unicode-bidi: isolate;
}
.messageTimestamp {
@@ -557,6 +559,7 @@
font-size: var(--message-timestamp-compact-font-size);
font-weight: 500;
line-height: var(--message-line-height);
unicode-bidi: isolate;
}
.messageTimestampHover {
@@ -948,6 +951,7 @@
white-space: nowrap;
max-width: 30%;
vertical-align: baseline;
unicode-bidi: plaintext;
font-weight: 500;
color: color-mix(
in srgb,
@@ -0,0 +1,58 @@
// SPDX-License-Identifier: AGPL-3.0-or-later
import {readFileSync} from 'node:fs';
import {fileURLToPath} from 'node:url';
import {describe, expect, it} from 'vitest';
const MESSAGE_CSS = readFileSync(fileURLToPath(new URL('./Message.module.css', import.meta.url)), 'utf8');
const ISOLATED_NAMES = ['.messageUsername', '.repliedUsername'];
const ISOLATED_TIMESTAMPS = [
'.messageTimestamp',
'.messageTimestampCompact',
'.messageTimestampHover',
'.messageTimestampCompactHover',
];
function rules(css: string): Array<{selector: string; declarations: string}> {
const source = css.replace(/\/\*[\s\S]*?\*\//g, '');
const out: Array<{selector: string; declarations: string}> = [];
const chain: Array<string> = [];
let buffer = '';
for (const char of source) {
if (char === '{') {
chain.push(buffer.split(/[;}]/).pop()?.trim().replace(/\s+/g, ' ') ?? '');
buffer = '';
} else if (char === '}') {
if (chain.length > 0) {
out.push({selector: chain.join(' '), declarations: buffer});
chain.pop();
}
buffer = '';
} else {
buffer += char;
}
}
return out;
}
function declaredBidi(className: string): Array<string> {
const selectorPattern = new RegExp(`\\${className}(?![\\w-])`);
const out: Array<string> = [];
for (const rule of rules(MESSAGE_CSS)) {
if (!rule.selector.split(',').some((selector) => selectorPattern.test(selector))) continue;
const match = rule.declarations.match(/unicode-bidi\s*:\s*([^;]+)/);
if (match) out.push(match[1].trim());
}
return out;
}
describe('message bidi isolation', () => {
it.each(ISOLATED_NAMES)('resolves %s in its own bidi paragraph', (className) => {
expect(declaredBidi(className)).toContain('plaintext');
});
it.each(ISOLATED_TIMESTAMPS)('keeps %s out of a neighbouring right-to-left run', (className) => {
expect(declaredBidi(className)).toContain('isolate');
});
});
@@ -0,0 +1,23 @@
// @vitest-environment happy-dom
// SPDX-License-Identifier: AGPL-3.0-or-later
import {scopePortalHostToDocument} from '@app/features/ui/overlay/PortalHostContext';
import {describe, expect, it} from 'vitest';
describe('scopePortalHostToDocument', () => {
it('keeps a host that belongs to the scoped document', () => {
const host = document.createElement('div');
expect(scopePortalHostToDocument(host, document)).toBe(host);
});
it('drops a host owned by another document', () => {
const popoutDocument = document.implementation.createHTMLDocument('popout');
const popoutHost = popoutDocument.createElement('div');
expect(scopePortalHostToDocument(popoutHost, document)).toBeNull();
expect(scopePortalHostToDocument(popoutHost, popoutDocument)).toBe(popoutHost);
});
it('passes a missing host through', () => {
expect(scopePortalHostToDocument(null, document)).toBeNull();
});
});
@@ -39,3 +39,8 @@ export function usePortalHost(): PortalHostElement {
export function resolvePortalHost(host: PortalHostElement): HTMLElement {
return host ?? document.body;
}
export function scopePortalHostToDocument(host: PortalHostElement, scopeDocument: Document): PortalHostElement {
if (host == null) return null;
return host.ownerDocument === scopeDocument ? host : null;
}
@@ -4,7 +4,7 @@ import Accessibility from '@app/features/accessibility/state/Accessibility';
import {useAntiShiftFloating} from '@app/features/app/hooks/useAntiShiftFloating';
import {shouldDisableAutofocusOnMobile} from '@app/features/platform/utils/AutofocusUtils';
import * as PopoutCommands from '@app/features/ui/commands/PopoutCommands';
import {usePortalHost} from '@app/features/ui/overlay/PortalHostContext';
import {scopePortalHostToDocument, usePortalHost} from '@app/features/ui/overlay/PortalHostContext';
import {type Popout, PopoutKeyContext, type PopoutReferenceRect} from '@app/features/ui/popover';
import {PopoutResizePositionContext} from '@app/features/ui/popover/PopoutResizePositionContext';
import {getPopoutFocusManagerInsideElements} from '@app/features/ui/popover/PopoverFocusManagerUtils';
@@ -426,10 +426,11 @@ interface PopoutsProps {
export const Popouts: React.FC<PopoutsProps> = observer(({ownerDocument}) => {
const prevPopoutKeysRef = useRef<Set<string>>(new Set());
const portalHost = usePortalHost();
const activePortalHost = usePortalHost();
let scopeDocument = document;
if (portalHost != null) scopeDocument = portalHost.ownerDocument;
if (activePortalHost != null) scopeDocument = activePortalHost.ownerDocument;
if (ownerDocument != null) scopeDocument = ownerDocument;
const portalHost = scopePortalHostToDocument(activePortalHost, scopeDocument);
const popouts = PopoutState.getPopouts(scopeDocument);
const topPopout = popouts.length ? popouts[popouts.length - 1] : null;
const needsBackdrop = Boolean(topPopout && !topPopout.disableBackdrop);
@@ -0,0 +1,99 @@
// @vitest-environment happy-dom
// SPDX-License-Identifier: AGPL-3.0-or-later
import {afterEach, beforeEach, describe, expect, it, vi} from 'vitest';
const IDLE_DURATION_MS = 600_000;
const IDLE_CHECK_INTERVAL_MS = 30_000;
vi.mock('@app/features/platform/types/Env', () => ({
IS_DEV: false,
IS_PROD: true,
MODE: 'test',
}));
vi.mock('@app/features/presence/state/LocalPresence', () => ({
default: {updatePresence: vi.fn()},
}));
async function loadIdle(getSystemIdleTimeMs?: () => Promise<number>) {
vi.resetModules();
if (getSystemIdleTimeMs) {
Object.defineProperty(window, 'electron', {value: {getSystemIdleTimeMs}, configurable: true, writable: true});
} else {
Reflect.deleteProperty(window as unknown as Record<string, unknown>, 'electron');
}
const {default: Idle} = await import('@app/features/ui/state/Idle');
return Idle;
}
describe('Idle', () => {
beforeEach(() => {
vi.useFakeTimers();
});
afterEach(() => {
Reflect.deleteProperty(window as unknown as Record<string, unknown>, 'electron');
vi.useRealTimers();
});
it('goes idle once nothing has reported activity for the idle duration', async () => {
const Idle = await loadIdle();
await vi.advanceTimersByTimeAsync(IDLE_DURATION_MS - IDLE_CHECK_INTERVAL_MS);
expect(Idle.isIdle()).toBe(false);
await vi.advanceTimersByTimeAsync(IDLE_CHECK_INTERVAL_MS);
expect(Idle.isIdle()).toBe(true);
});
it('stays active while the app keeps seeing input', async () => {
const Idle = await loadIdle();
for (let elapsed = 0; elapsed < IDLE_DURATION_MS * 2; elapsed += IDLE_CHECK_INTERVAL_MS) {
Idle.recordActivity();
await vi.advanceTimersByTimeAsync(IDLE_CHECK_INTERVAL_MS);
}
expect(Idle.isIdle()).toBe(false);
});
it('stays active while the app sees input even when the system idle clock keeps climbing', async () => {
const startedAt = Date.now();
const Idle = await loadIdle(async () => Date.now() - startedAt);
for (let elapsed = 0; elapsed < IDLE_DURATION_MS * 2; elapsed += IDLE_CHECK_INTERVAL_MS) {
Idle.recordActivity();
await vi.advanceTimersByTimeAsync(IDLE_CHECK_INTERVAL_MS);
}
expect(Idle.isIdle()).toBe(false);
});
it('leaves idle as soon as the app sees input again', async () => {
const startedAt = Date.now();
const Idle = await loadIdle(async () => Date.now() - startedAt);
await vi.advanceTimersByTimeAsync(IDLE_DURATION_MS);
expect(Idle.isIdle()).toBe(true);
Idle.recordActivity();
expect(Idle.isIdle()).toBe(false);
await vi.advanceTimersByTimeAsync(IDLE_CHECK_INTERVAL_MS);
expect(Idle.isIdle()).toBe(false);
});
it('stays active while the system reports input the app never sees', async () => {
const Idle = await loadIdle(async () => 0);
await vi.advanceTimersByTimeAsync(IDLE_DURATION_MS * 2);
expect(Idle.isIdle()).toBe(false);
});
it('goes idle when neither the app nor the system reports activity', async () => {
const startedAt = Date.now();
const Idle = await loadIdle(async () => Date.now() - startedAt);
await vi.advanceTimersByTimeAsync(IDLE_DURATION_MS);
expect(Idle.isIdle()).toBe(true);
});
it('falls back to app activity when the system idle clock is unreadable', async () => {
const Idle = await loadIdle(async () => Number.NaN);
await vi.advanceTimersByTimeAsync(IDLE_DURATION_MS);
expect(Idle.isIdle()).toBe(true);
Idle.recordActivity();
await vi.advanceTimersByTimeAsync(IDLE_CHECK_INTERVAL_MS);
expect(Idle.isIdle()).toBe(false);
});
});
+19 -21
View File
@@ -30,11 +30,11 @@ function normalizeIdleTimeMs(value: number): number | null {
class Idle {
idle = false;
private lastActivityTime = Date.now();
private lastLocalActivityTime = Date.now();
private lastSystemActivityTime = 0;
private checkInterval: NodeJS.Timeout | null = null;
private systemIdleCheckInFlight = false;
private lastSystemIdleFailureAt = 0;
private activityVersion = 0;
constructor() {
makeAutoObservable(this, {}, {autoBind: true});
@@ -56,16 +56,15 @@ class Idle {
}
recordActivity(): void {
this.lastActivityTime = Date.now();
this.activityVersion++;
this.lastLocalActivityTime = Date.now();
if (this.idle) {
this.applyIdleState(false);
}
}
markBackground(): void {
this.lastActivityTime = 0;
this.activityVersion++;
this.lastLocalActivityTime = 0;
this.lastSystemActivityTime = 0;
this.applyIdleState(true);
}
@@ -74,16 +73,24 @@ class Idle {
}
getIdleSince(): number {
return this.idle ? this.lastActivityTime : 0;
return this.idle ? this.getLastActivityTime() : 0;
}
getInactiveDurationMs(now = Date.now()): number {
return Math.max(0, now - this.lastActivityTime);
return Math.max(0, now - this.getLastActivityTime());
}
private getLastActivityTime(): number {
return Math.max(this.lastLocalActivityTime, this.lastSystemActivityTime);
}
private updateIdleState(): void {
const desktopIdleApi = getDesktopIdleApi();
if (desktopIdleApi && Date.now() - this.lastSystemIdleFailureAt >= SYSTEM_IDLE_RETRY_DELAY_MS) {
if (
desktopIdleApi &&
!this.systemIdleCheckInFlight &&
Date.now() - this.lastSystemIdleFailureAt >= SYSTEM_IDLE_RETRY_DELAY_MS
) {
void this.updateIdleStateFromSystem(desktopIdleApi);
return;
}
@@ -96,29 +103,20 @@ class Idle {
}
private async updateIdleStateFromSystem(desktopIdleApi: Required<DesktopIdleApi>): Promise<void> {
if (this.systemIdleCheckInFlight) return;
this.systemIdleCheckInFlight = true;
const activityVersion = this.activityVersion;
const requestedAt = Date.now();
try {
const idleTimeMs = normalizeIdleTimeMs(await desktopIdleApi.getSystemIdleTimeMs());
if (idleTimeMs === null) {
this.lastSystemIdleFailureAt = Date.now();
this.updateIdleStateFromLocalActivity();
return;
} else {
this.lastSystemActivityTime = Math.max(this.lastSystemActivityTime, Date.now() - idleTimeMs);
}
if (activityVersion !== this.activityVersion && this.lastActivityTime >= requestedAt) {
return;
}
const now = Date.now();
this.lastActivityTime = Math.max(0, now - idleTimeMs);
this.applyIdleState(idleTimeMs >= IDLE_DURATION_MS);
} catch {
this.lastSystemIdleFailureAt = Date.now();
this.updateIdleStateFromLocalActivity();
} finally {
this.systemIdleCheckInFlight = false;
}
this.updateIdleStateFromLocalActivity();
}
private applyIdleState(idle: boolean): void {
@@ -1,6 +1,6 @@
/* SPDX-License-Identifier: AGPL-3.0-or-later */
.modalRoot {
.modalRoot.modalRoot {
--profile-popout-content-width: 18.75rem;
--profile-popout-border-width: 0.15625rem;
--profile-card-width: calc(
@@ -9,9 +9,16 @@
var(--profile-popout-border-width)
);
--custom-status-modal-padding-inline: 2rem;
--custom-status-modal-card-gutter: 3.75rem;
--custom-status-modal-width: calc(
var(--profile-card-width) +
var(--custom-status-modal-padding-inline) +
var(--custom-status-modal-card-gutter) +
var(--custom-status-modal-card-gutter)
);
width: min(calc(var(--profile-card-width) + var(--custom-status-modal-padding-inline)), 90vw);
max-width: calc(var(--profile-card-width) + var(--custom-status-modal-padding-inline));
width: min(var(--custom-status-modal-width), 90vw);
max-width: var(--custom-status-modal-width);
}
.previewSection {
@@ -31,8 +38,6 @@
.statusInputWrapper {
width: 100%;
max-width: var(--profile-card-width);
margin-inline: auto;
display: flex;
flex-direction: column;
gap: 0.35rem;
@@ -24,26 +24,30 @@ class UserProfile {
}
handleGatewayReady(): void {
Object.values(this.profileTimeouts).forEach(clearTimeout);
this.profiles = {};
this.profileTimeouts = {};
this.clearAllProfiles();
}
handleProfileInvalidate(userId: string, guildId?: string): void {
const targetGuildId = guildId ?? ME;
this.clearProfileTimeout(userId, targetGuildId);
const userProfiles = this.profiles[userId];
if (!userProfiles) return;
const {[targetGuildId]: _, ...remainingGuildProfiles} = userProfiles;
if (Object.keys(remainingGuildProfiles).length === 0) {
const {[userId]: __, ...remainingProfiles} = this.profiles;
this.profiles = remainingProfiles;
} else {
this.profiles = {
...this.profiles,
[userId]: remainingGuildProfiles,
};
}
this.removeProfile(userId, targetGuildId);
}
handleGuildMemberAdd(userId: string): void {
this.clearUserProfiles(userId);
}
handleGuildMemberRemove(userId: string): void {
this.clearUserProfiles(userId);
}
handleGuildCreate(): void {
this.clearAllProfiles();
}
handleGuildDelete(unavailable?: boolean): void {
if (unavailable) return;
this.clearAllProfiles();
}
handleProfileCreate(profile: Profile): void {
@@ -82,6 +86,37 @@ class UserProfile {
this.profileTimeouts = updatedTimeouts;
}
private clearAllProfiles(): void {
Object.values(this.profileTimeouts).forEach(clearTimeout);
this.profiles = {};
this.profileTimeouts = {};
}
private clearUserProfiles(userId: string): void {
const userProfiles = this.profiles[userId];
if (!userProfiles) return;
for (const guildId of Object.keys(userProfiles)) {
this.clearProfileTimeout(userId, guildId);
}
const {[userId]: _, ...remainingProfiles} = this.profiles;
this.profiles = remainingProfiles;
}
private removeProfile(userId: string, guildId: string): void {
const userProfiles = this.profiles[userId];
if (!userProfiles) return;
const {[guildId]: _, ...remainingGuildProfiles} = userProfiles;
if (Object.keys(remainingGuildProfiles).length === 0) {
const {[userId]: __, ...remainingProfiles} = this.profiles;
this.profiles = remainingProfiles;
} else {
this.profiles = {
...this.profiles,
[userId]: remainingGuildProfiles,
};
}
}
private createTimeoutKey(userId: string, guildId: string): string {
return `${userId}:${guildId}`;
}
@@ -101,23 +136,8 @@ class UserProfile {
this.clearProfileTimeout(userId, guildId);
const timeout = setTimeout(() => {
runInAction(() => {
const userProfiles = this.profiles[userId];
if (!userProfiles) {
const {[timeoutKey]: _, ...remainingTimeouts} = this.profileTimeouts;
this.profileTimeouts = remainingTimeouts;
return;
}
const {[guildId]: _, ...remainingGuildProfiles} = userProfiles;
if (Object.keys(remainingGuildProfiles).length === 0) {
const {[userId]: __, ...remainingProfiles} = this.profiles;
this.profiles = remainingProfiles;
} else {
this.profiles = {
...this.profiles,
[userId]: remainingGuildProfiles,
};
}
const {[timeoutKey]: ___, ...remainingTimeouts} = this.profileTimeouts;
this.removeProfile(userId, guildId);
const {[timeoutKey]: _, ...remainingTimeouts} = this.profileTimeouts;
this.profileTimeouts = remainingTimeouts;
});
}, PROFILE_TIMEOUT_MS);
@@ -0,0 +1,66 @@
// SPDX-License-Identifier: AGPL-3.0-or-later
import type {Profile} from '@app/features/user/models/Profile';
import {afterEach, describe, expect, it, vi} from 'vitest';
vi.mock('@app/features/auth/state/Authentication', () => ({default: {currentUserId: null}}));
const {default: UserProfile} = await import('@app/features/user/state/UserProfile');
const GUILD_ID = '1000';
const TARGET_ID = '2000';
function cache(userId: string = TARGET_ID, guildId?: string): void {
UserProfile.handleProfileCreate({
userId,
guildId: guildId ?? null,
mutualGuilds: [{id: GUILD_ID, nick: null}],
} as unknown as Profile);
}
describe('UserProfile cache invalidation', () => {
afterEach(() => {
UserProfile.handleGatewayReady();
});
it('drops every cached scope for a member removed from a community', () => {
cache();
cache(TARGET_ID, GUILD_ID);
expect(UserProfile.getProfile(TARGET_ID)?.mutualGuilds).toHaveLength(1);
UserProfile.handleGuildMemberRemove(TARGET_ID);
expect(UserProfile.getProfile(TARGET_ID)).toBeNull();
expect(UserProfile.getProfile(TARGET_ID, GUILD_ID)).toBeNull();
});
it('drops every cached scope for a member who joined a community', () => {
cache();
UserProfile.handleGuildMemberAdd(TARGET_ID);
expect(UserProfile.getProfile(TARGET_ID)).toBeNull();
});
it('keeps other users cached when one member is removed', () => {
cache();
cache('3000');
UserProfile.handleGuildMemberRemove(TARGET_ID);
expect(UserProfile.getProfile(TARGET_ID)).toBeNull();
expect(UserProfile.getProfile('3000')).not.toBeNull();
});
it('drops cached profiles when the viewer leaves a community', () => {
cache();
UserProfile.handleGuildDelete(false);
expect(UserProfile.getProfile(TARGET_ID)).toBeNull();
});
it('keeps cached profiles when a community only goes unavailable', () => {
cache();
UserProfile.handleGuildDelete(true);
expect(UserProfile.getProfile(TARGET_ID)).not.toBeNull();
});
it('drops cached profiles when the viewer joins a community', () => {
cache();
UserProfile.handleGuildCreate();
expect(UserProfile.getProfile(TARGET_ID)).toBeNull();
});
});
@@ -43,6 +43,7 @@ export function useWindowEventListeners({preventDocumentScroll}: WindowEventList
document.addEventListener('visibilitychange', handleVisibilityChange);
window.addEventListener('mousedown', handleImmediateActivity);
window.addEventListener('keydown', handleUserActivity);
window.addEventListener('input', handleUserActivity);
window.addEventListener('resize', handleResize);
window.addEventListener('touchstart', handleImmediateActivity);
document.addEventListener('touchstart', preventPinchZoom, {passive: false});
@@ -58,6 +59,7 @@ export function useWindowEventListeners({preventDocumentScroll}: WindowEventList
document.removeEventListener('visibilitychange', handleVisibilityChange);
window.removeEventListener('mousedown', handleImmediateActivity);
window.removeEventListener('keydown', handleUserActivity);
window.removeEventListener('input', handleUserActivity);
window.removeEventListener('resize', handleResize);
window.removeEventListener('touchstart', handleImmediateActivity);
document.removeEventListener('touchstart', preventPinchZoom);
+23
View File
@@ -1242,6 +1242,29 @@ console.log('self-hosting guide against deploy/self-hosting');
compareKeyLists('secret', shellSecrets, powershellSecrets);
compareKeyLists('non-secret value', shellNonSecrets, powershellNonSecrets);
const shellUpgrade = parseShellKeys('fluxer_upgrade_secret_keys', 'the install.sh upgrade secret list');
const powershellUpgrade = parsePowerShellKeys('FluxerUpgradeSecretKeys', 'the install.ps1 upgrade secret list');
compareKeyLists('upgrade secret', shellUpgrade, powershellUpgrade);
for (const [script, upgrade, secrets] of [
['install.sh', shellUpgrade, shellSecrets],
['install.ps1', powershellUpgrade, powershellSecrets],
] as const) {
if (upgrade.size === 0) {
problems.push(`${script} declares no upgrade secret keys, so an upgrade mints nothing`);
}
for (const [name, kind] of upgrade) {
const asInstalled = secrets.get(name);
if (asInstalled == null) {
problems.push(`${script} mints ${name} on an upgrade and never writes it on an install`);
continue;
}
if (asInstalled !== kind) {
problems.push(`${name} is ${kind} on an upgrade and ${asInstalled} on an install in ${script}`);
}
}
}
const expectedSecretKind = (name: string): string => {
if (name === 'FLUXER_VAPID_PUBLIC_KEY') {
return 'vapid_public';
@@ -4,7 +4,7 @@ title: HTTP API
description: Request format, body representations, shared headers, cross-origin policy, and the error objects.
---
The Fluxer HTTP API is the set of routes a client calls to read and change data. Every route is published under `/v1`, and `/v1` is the only version. The base URL comes from `endpoints.api` in the [instance discovery document](/http-api/instance/#get-instance-discovery), which is served unversioned at `/.well-known/fluxer`.
The Fluxer HTTP API is the set of routes a client calls to read and change data. Every route is published under `/v1`, and `/v1` is the only version. The base URL comes from the [instance discovery document](/http-api/instance/#get-instance-discovery), which is served unversioned at `/.well-known/fluxer`. A third-party client reads `endpoints.api_public` there, and the first-party web application reads `endpoints.api_client`.
Every route is also mounted at the root, so a path resolves with or without the prefix. A client MUST use the `/v1` form. [Download stored object](/http-api/downloads/#download-stored-object) is the one exception, and it resolves at the root alone.
@@ -57,7 +57,7 @@ Each value is an absolute URL supplied by the operator. A value can be a bare or
| gift | string | Gift link base URL |
| webapp | string | Web application base URL |
<sup>1</sup> Both fields are the same configured client API endpoint, while `api_public` is the separately configured public API endpoint
<sup>1</sup> Both fields are the same configured client API endpoint, which the first-party web application reads. `api_public` is the separately configured public API endpoint, which a bot, a library, or any other third-party client reads. A deployment can point the two at one origin, and the instance Fluxer hosts does not
<sup>2</sup> The value is the configured Gateway endpoint and its scheme is `ws` or `wss` as the operator configured it
@@ -178,13 +178,14 @@ A matching entry is deleted and [Recent Mention Delete](/gateway/events/#recent-
Lists the caller's saved message collection. Returns an array of [saved message](#saved-message-object) objects in descending message ID order.
The response is a bare array with no cursor metadata, so `limit` is the only control and an account holding more than 100 entries cannot page past the first 100. An entry whose channel the caller can no longer reach, or whose message the caller can no longer read, comes back with status `missing_permissions` and a null message. An entry whose message no longer exists is deleted and omitted. The array can hold fewer entries than `limit`.
The response is a bare array with no cursor metadata, so `before` and `limit` are the only pagination controls. An entry whose channel the caller can no longer reach, or whose message the caller can no longer read, comes back with status `missing_permissions` and a null message. An entry whose message no longer exists is deleted and omitted. The array can hold fewer entries than `limit`.
### Query parameters
| Field | Type | Description |
| --- | --- | --- |
| limit?<sup>1</sup> <sup>2</sup> | integer | The maximum number of entries read from the collection (1-100, default 25) |
| before?<sup>2</sup> | snowflake | The upper bound on entry message ID, exclusive |
<sup>1</sup> A value outside the range fails with `VALUE_MUST_BE_INTEGER_IN_RANGE` at the `limit` path
+3 -1
View File
@@ -43,9 +43,11 @@ A client that knows only a Fluxer origin reads endpoint discovery first. `GET /.
GET https://example.com/.well-known/fluxer
```
The instance Fluxer hosts answers discovery at `https://fluxer.app/.well-known/fluxer`. That origin is the one thing a client is given. Every base URL below it still comes from the response.
It returns the [instance discovery object](/http-api/instance/#instance-discovery-object). Every base URL a client uses comes from the [instance endpoints object](/http-api/instance/#instance-endpoints-object) inside it. A client MUST read every base URL from that response, and it MUST NOT derive one from the origin it was given or assume an official Fluxer domain.
Take `endpoints.api` from that response, then send a credential in the `Authorization` header.
Take the base URL for the kind of client being built, then send a credential in the `Authorization` header. A bot, a library, or any other third-party client takes `endpoints.api_public`. `endpoints.api_client` is the endpoint the first-party web application uses, and `endpoints.api` repeats it.
```text
GET https://api.example.com/v1/users/@me
@@ -647,6 +647,22 @@ Default empty. The LiveKit secret. Compose fills it from `LIVEKIT_API_SECRET`.
Default empty. The client-facing LiveKit URL. When empty the API derives it from the public API origin as `wss://host/livekit`, or `ws://` under `http`, and keeps a non-default port. Set it only when LiveKit is served from another host. Compose forwards the `.env` value, empty by default.
#### `FLUXER_LIVEKIT_USE_EXTERNAL_IP`
Default `true`. Whether LiveKit discovers the address browsers dial by asking a STUN server. A host that cannot reach one over UDP fails to start with `could not resolve external IP: context deadline exceeded`. Set it to `false` and give `FLUXER_LIVEKIT_NODE_IP` the address instead. Read only by the `livekit` service.
#### `FLUXER_LIVEKIT_NODE_IP`
Default empty. The address LiveKit publishes in its ICE candidates. Empty leaves the choice to the discovery above, and with that discovery off LiveKit falls back to the container's own address, which no browser can reach. Set both together. `docker compose logs livekit` names the address in use as `nodeIP` on the starting line.
#### `FLUXER_LIVEKIT_STUN_PRIMARY`
Default `stun.l.google.com:19302`. The first STUN server the discovery asks. Point it at another server to keep the discovery without reaching Google.
#### `FLUXER_LIVEKIT_STUN_SECONDARY`
Default `stun1.l.google.com:19302`. The second STUN server, used the same way.
#### `FLUXER_LIVEKIT_INTERNAL_URL`
Default empty. The server-side LiveKit control API. Compose sets `http://livekit:7880`.
@@ -17,7 +17,7 @@ By the end you have a Fluxer instance on a hostname you own, with the web app, H
| Requirement | Value |
| --- | --- |
| Host | Any machine that runs Docker with Linux containers. A Linux server, or a Mac or Windows PC with Docker Desktop |
| Runtime | Docker Engine 24 or newer with the Compose plugin v2.20.2 or newer. Docker Desktop ships both |
| Runtime | Docker Engine 24 or newer, or Podman 5 or newer, with the Compose plugin v2.20.2 or newer |
| Processor | Intel, AMD and Apple Silicon all work. Every image ships for `amd64` and `arm64`, and Docker pulls the matching one |
| CPU | 2 vCPU minimum, 4 vCPU for a small active community. No service sets a CPU limit, so every container sees all of them |
| RAM | 8 GB minimum with the shipped defaults, 16 GB for a small active community. 4 GB needs the [low-memory overrides](/operator/configuration/#resources) |
@@ -148,7 +148,7 @@ The run prints one line per phase and ends with the URL to open. It takes severa
| --- | --- |
| `--domain <host>` | Hostname the instance answers on. Prompted when absent |
| `--email <address>` | Contact address written as `FLUXER_VAPID_EMAIL`. Prompted when absent |
| `--dir <path>` | Working directory. Default `~/fluxer` |
| `--dir <path>` | Working directory. Default `~/fluxer`, or the current directory when it holds an instance |
| `--ref <git ref>` | Ref the stack files come from. Defaults to the image tag, and to `main` when that tag is `v1` or `latest` |
| `--image-tag <tag>` | Image tag the stack runs. Default `v1` |
| `--tls <mode>` | `bundled` or `proxy`. Default `bundled` |
@@ -159,6 +159,7 @@ The run prints one line per phase and ends with the URL to open. It takes severa
| `--update` | Upgrade: record, back up, refresh, pull, recreate, verify |
| `--rollback` | Put back the images and stack files of the newest record |
| `--allow-root` | Permit running as root |
| `--engine <command>` | Container engine to drive. Default `docker`, or `podman` when `docker` is absent |
Run `--dry-run` first to see what a set of flags does. The PowerShell script takes the same flags as `-Domain`, `-Email` and so on, and has no `-AllowRoot`. [Upgrading](/operator/upgrading/#run-the-upgrade) has the flags that only `--update` and `--rollback` read, and the exit codes.
@@ -255,14 +256,16 @@ A dump and a tarball in `backups`, and every service back to `running`, is the s
### Remove the instance
:::danger[This deletes every account, message and upload]
`-v` deletes all seven named volumes. Every account, message, upload, search index and certificate the instance holds is gone, and no `docker compose up -d` brings any of it back. Take the copies above first. To upgrade rather than delete, the command is `sh install.sh --update`, below.
:::
Take the instance down and delete its data:
```bash
docker compose down -v
```
`-v` deletes all seven named volumes, so every account, message, upload, search index and certificate the instance holds is gone, and no `docker compose up -d` brings them back. Take the copies above first.
## Upgrading
The default tag `v1` tracks the latest compatible release. The same script upgrades the instance:
@@ -272,7 +275,7 @@ cd ~/fluxer
sh install.sh --update
```
`--update` records the running images, backs up the database and the uploads, refreshes the four stack files, pulls, recreates, and verifies. It leaves every secret in `.env` untouched. On Windows it is `.\install.ps1 -Update`. Run `sh install.sh --update --dry-run` first to see the plan.
`--update` records the running images, backs up the database and the uploads, refreshes the five stack files, pulls, recreates, and verifies. It leaves every secret in `.env` untouched. On Windows it is `.\install.ps1 -Update`. Run `sh install.sh --update --dry-run` first to see the plan.
[Upgrading](/operator/upgrading/) covers what the backup holds, rolling back, pinning a release and reclaiming disk.
@@ -31,6 +31,7 @@ The repository holds no ref by the name of a pinned image tag. A release tags ea
| Step | What it does |
| --- | --- |
| Mint | Writes any key the refreshed stack requires that `.env` does not hold, listed under [Run the upgrade](#run-the-upgrade) |
| Record | Writes the image references, the image ID each container has, and the tag `.env` names, into a new record directory |
| Save | Copies `.env` and the five stack files into that record |
| Dump | Dumps the database with the stack still serving, and checks the custom-format header on the result |
@@ -46,6 +47,8 @@ A failed run leaves the instance running on the images it already had.
`docker compose up -d` does not notice a changed `Caddyfile`. The script restarts `edge` by name to pick it up.
An instance older than the `/livekit` routing needs one edit no upgrade can make for it. [Voice signalling moved to /livekit](#voice-signalling-moved-to-livekit) has it, and voice stays silent until it is made.
The refreshed `docker-compose.yml` renames the `caddy` service to `edge`, and the two publish the same host ports. `--remove-orphans` takes the old container down in the same call, so the new one can bind them. Without it the step stops with `Bind for 0.0.0.0:443 failed`. It also removes any container in the project whose service the loaded Compose files no longer define, so keep `COMPOSE_FILE` the same across an upgrade. [Keep a local compose change](#keep-a-local-compose-change) has the file layout that survives one, and [When the compose file list names a missing file](#when-the-compose-file-list-names-a-missing-file) has the failure a line naming an absent file produces.
The rename also moves the `caddy-data` and `caddy-config` volumes to `edge-data` and `edge-config`, so the old two are left unused and the edge requests its certificate again on the first start.
@@ -86,7 +89,7 @@ COMPOSE_FILE=docker-compose.yml:docker-compose.proxy.yml:local.compose.yml
Compose merges the files left to right, so `local.compose.yml` wins over the ones before it. An upgrade refreshes the five stack files and nothing else, so a file outside that set survives every upgrade untouched. A record copies `.env` and those five files, and no other file from the working directory, so an override file is never backed up with them and belongs wherever the rest of the configuration lives.
`.env` needs no such file. `FLUXER_IMAGE_TAG` is the only line either upgrade mode writes.
`.env` needs no such file. The only value either upgrade mode replaces there is `FLUXER_IMAGE_TAG`, and the Mint step adds a required key the file does not hold at all.
[Enable the overlay](/operator/reverse-proxy/#enable-the-overlay) has the overlay this is most often used for, and [Docker labels](/operator/reverse-proxy/#docker-labels) has a worked third file.
+115 -21
View File
@@ -40,6 +40,7 @@ param(
[string]$Domain = '',
[string]$Email = '',
[string]$Dir = '',
[string]$Engine = '',
[string]$Ref = '',
[string]$ImageTag = 'v1',
[string]$Tls = 'bundled',
@@ -65,6 +66,7 @@ $FluxerRawBase = 'https://raw.githubusercontent.com/fluxerapp/fluxer'
$FluxerStackPath = 'deploy/self-hosting'
$FluxerHealthPath = '/_health'
$FluxerInitService = 'seaweedfs-init'
$FluxerMinimumPodmanVersion = '5.0.0'
$FluxerMinimumEngineVersion = '24.0.0'
$FluxerMinimumComposeVersion = '2.20.2'
$FluxerReadyTimeoutSeconds = 600
@@ -194,7 +196,11 @@ function Show-FluxerUsage {
Write-FluxerLine 'Options:'
Write-FluxerLine ' -Domain <host> Hostname the instance answers on. Prompted when absent.'
Write-FluxerLine ' -Email <address> Address written as FLUXER_VAPID_EMAIL. Prompted when absent.'
Write-FluxerLine ' -Dir <path> Working directory. Default: the fluxer folder in the home directory.'
Write-FluxerLine ' -Engine <command> Container engine to drive. Default: docker, or podman when'
Write-FluxerLine ' docker is absent.'
Write-FluxerLine ' -Dir <path> Working directory. Default: the fluxer folder in the home'
Write-FluxerLine ' directory, or the working directory itself when -Update or'
Write-FluxerLine ' -Rollback is given and it holds an instance.'
Write-FluxerLine ' -Ref <git ref> Ref the stack files come from. Default: the image tag, and main when that tag is v1 or latest.'
Write-FluxerLine ' -ImageTag <tag> Value written as FLUXER_IMAGE_TAG. Default: v1.'
Write-FluxerLine ' -Tls <bundled|proxy> Certificate mode. Default: bundled.'
@@ -254,6 +260,9 @@ function Test-FluxerVersionAtLeast([string]$Found, [string]$Minimum) {
# is kept rather than discarded. The two streams stay apart because every caller reads Text as
# data, and one warning line on stderr would be one more line of JSON, one more image reference or
# one more container ID.
$script:FluxerEngine = 'docker'
$script:FluxerEngineLabel = 'Docker Engine'
function Invoke-FluxerCapture([string[]]$CommandArgs) {
$previous = $ErrorActionPreference
$ErrorActionPreference = 'Continue'
@@ -261,7 +270,7 @@ function Invoke-FluxerCapture([string[]]$CommandArgs) {
$err = @()
$code = 0
try {
$output = & docker @CommandArgs 2>&1
$output = & $script:FluxerEngine @CommandArgs 2>&1
$code = $LASTEXITCODE
foreach ($item in @($output)) {
if ($item -is [System.Management.Automation.ErrorRecord]) {
@@ -281,7 +290,7 @@ function Invoke-FluxerDocker([string[]]$CommandArgs) {
$ErrorActionPreference = 'Continue'
$code = 0
try {
& docker @CommandArgs
& $script:FluxerEngine @CommandArgs
$code = $LASTEXITCODE
} finally {
$ErrorActionPreference = $previous
@@ -293,7 +302,7 @@ function Invoke-FluxerDocker([string[]]$CommandArgs) {
# it, so the bytes go to the file through the process itself.
function Invoke-FluxerDockerToFile([string[]]$CommandArgs, [string]$OutFile, [string]$WorkingDir) {
$errorFile = "$OutFile.stderr"
$process = Start-Process -FilePath 'docker' -ArgumentList $CommandArgs -RedirectStandardOutput $OutFile -RedirectStandardError $errorFile -WorkingDirectory $WorkingDir -NoNewWindow -Wait -PassThru
$process = Start-Process -FilePath $script:FluxerEngine -ArgumentList $CommandArgs -RedirectStandardOutput $OutFile -RedirectStandardError $errorFile -WorkingDirectory $WorkingDir -NoNewWindow -Wait -PassThru
$code = $process.ExitCode
if (Test-Path -LiteralPath $errorFile) {
Remove-Item -LiteralPath $errorFile -Force
@@ -328,22 +337,40 @@ function Invoke-FluxerPreflight {
if ($PSVersionTable.PSVersion.Major -lt 6) {
[System.Net.ServicePointManager]::SecurityProtocol = [System.Net.SecurityProtocolType]::Tls12
}
if ($null -eq (Get-Command docker -ErrorAction SilentlyContinue)) {
Stop-Fluxer 'docker is not on PATH. Install Docker Desktop with the WSL2 backend.' $FluxerExitPrerequisite
if ($Engine.Length -gt 0) {
$script:FluxerEngine = $Engine
} elseif ($null -ne (Get-Command docker -ErrorAction SilentlyContinue)) {
$script:FluxerEngine = 'docker'
} elseif ($null -ne (Get-Command podman -ErrorAction SilentlyContinue)) {
$script:FluxerEngine = 'podman'
} else {
Stop-Fluxer 'Neither docker nor podman is on PATH. Install Docker Desktop with the WSL2 backend, or pass -Engine with the command that drives your containers.' $FluxerExitPrerequisite
}
if ($null -eq (Get-Command $script:FluxerEngine -ErrorAction SilentlyContinue)) {
Stop-Fluxer "$($script:FluxerEngine) is not on PATH. Pass -Engine with the command that drives your containers." $FluxerExitPrerequisite
}
# Every engine that speaks the Docker CLI reports itself as "<name> version X",
# and Podman's 5.x is not Docker's 5.x, so the floor has to belong to whichever
# one answered.
$reported = Invoke-FluxerCapture @('--version')
$minimumEngine = $FluxerMinimumEngineVersion
if ($reported.Code -eq 0 -and $reported.Text -match '^\s*podman\s+version') {
$script:FluxerEngineLabel = 'Podman'
$minimumEngine = $FluxerMinimumPodmanVersion
}
$engine = Invoke-FluxerCapture @('version', '--format', '{{.Server.Version}}')
if ($engine.Code -ne 0) {
Stop-Fluxer 'The Docker daemon does not answer. Start Docker Desktop and run this script again.' $FluxerExitPrerequisite
Stop-Fluxer "$($script:FluxerEngine) does not answer. Start it and run this script again." $FluxerExitPrerequisite
}
$compose = Invoke-FluxerCapture @('compose', 'version', '--short')
if ($compose.Code -ne 0) {
Stop-Fluxer 'The Docker Compose v2 plugin is missing. Docker Desktop ships it.' $FluxerExitPrerequisite
}
if (-not (Test-FluxerVersionAtLeast $engine.Text $FluxerMinimumEngineVersion)) {
Stop-Fluxer "Docker Engine $($engine.Text) is older than $FluxerMinimumEngineVersion. Compose is $($compose.Text)." $FluxerExitPrerequisite
if (-not (Test-FluxerVersionAtLeast $engine.Text $minimumEngine)) {
Stop-Fluxer "$($script:FluxerEngineLabel) $($engine.Text) is older than $minimumEngine. Compose is $($compose.Text)." $FluxerExitPrerequisite
}
if (-not (Test-FluxerVersionAtLeast $compose.Text $FluxerMinimumComposeVersion)) {
Stop-Fluxer "Docker Compose $($compose.Text) is older than $FluxerMinimumComposeVersion. Engine is $($engine.Text)." $FluxerExitPrerequisite
Stop-Fluxer "Compose $($compose.Text) is older than $FluxerMinimumComposeVersion. $($script:FluxerEngineLabel) is $($engine.Text)." $FluxerExitPrerequisite
}
$osType = Invoke-FluxerCapture @('info', '--format', '{{.OSType}}')
if ($osType.Code -ne 0) {
@@ -352,7 +379,7 @@ function Invoke-FluxerPreflight {
if ($osType.Text -ne 'linux') {
Stop-Fluxer "Docker runs $($osType.Text) containers. Switch Docker Desktop to Linux containers." $FluxerExitPrerequisite
}
Write-FluxerLine "Docker Engine $($engine.Text) and Compose $($compose.Text) are ready."
Write-FluxerLine "$($script:FluxerEngineLabel) $($engine.Text) and Compose $($compose.Text) are ready."
if (-not (Test-FluxerWsl2)) {
Write-FluxerLine 'WSL 2 is not present. Docker Desktop with the WSL2 backend is the supported Windows setup.'
}
@@ -773,6 +800,7 @@ function Get-FluxerComposeProject([string]$TargetDir) {
}
$script:FluxerComposeOut = ''
$script:FluxerComposeSelector = ''
$script:FluxerComposeErr = ''
# One read-only Compose query, with what Compose printed on stderr kept.
@@ -785,9 +813,19 @@ function Invoke-FluxerComposeQuery([string]$Selector) {
$result = Invoke-FluxerCapture @('compose', 'config', $Selector)
$script:FluxerComposeOut = $result.Text
$script:FluxerComposeErr = $result.Error
$script:FluxerComposeSelector = $Selector
return $result.Code
}
# The two readers below parse whatever the last query returned, so each one names
# the selector it belongs to. Reading the wrong one would otherwise hand back the
# other kind of list with nothing to say it was wrong.
function Assert-FluxerComposeSelector([string]$Selector) {
if ($script:FluxerComposeSelector -ne $Selector) {
Stop-Fluxer "Internal error: read of $Selector after a $($script:FluxerComposeSelector) query." $FluxerExitSecret
}
}
# What Compose printed on the last query, indented one level for the caller.
function Get-FluxerComposeError([string]$Indent) {
if ($script:FluxerComposeErr.Length -eq 0) {
@@ -803,6 +841,7 @@ function Get-FluxerComposeError([string]$Indent) {
# By hand:
# docker compose config --images
function Get-FluxerComposeImages {
Assert-FluxerComposeSelector '--images'
$refs = @()
foreach ($line in $script:FluxerComposeOut.Split("`n")) {
$candidate = $line.Trim()
@@ -833,10 +872,22 @@ function Get-FluxerImageId([string]$Reference) {
#
# By hand:
# docker compose ps -aq | xargs docker inspect --format '{{.Config.Image}} {{.Image}}'
# The text of a captured stream, indented one level for the caller, or a word
# saying there was none.
function Get-FluxerIndented([string]$Text, [string]$Indent) {
if ([string]::IsNullOrWhiteSpace($Text)) {
return "${Indent}nothing"
}
return (($Text -split "`n") | ForEach-Object {"$Indent$_"}) -join "`n"
}
function Get-FluxerRunningImageIds {
$ids = Invoke-FluxerCapture @('compose', 'ps', '-aq')
$map = @{}
if ($ids.Code -ne 0 -or $ids.Text.Length -eq 0) {
if ($ids.Code -ne 0) {
Stop-Fluxer "docker compose ps failed, so what is running cannot be read and the record would name no image ID at all. Compose printed:`n$(Get-FluxerIndented $ids.Error ' ')" $FluxerExitPrerequisite
}
if ($ids.Text.Length -eq 0) {
return $map
}
foreach ($container in $ids.Text.Split("`n")) {
@@ -846,7 +897,7 @@ function Get-FluxerRunningImageIds {
}
$row = Invoke-FluxerCapture @('inspect', '--format', '{{.Config.Image}} {{.Image}}', $candidate)
if ($row.Code -ne 0) {
continue
Stop-Fluxer "docker inspect failed for $candidate, so the image ID under its reference cannot be read and a rollback would have nothing to go back to. Docker printed:`n$(Get-FluxerIndented $row.Error ' ')" $FluxerExitPrerequisite
}
$parts = $row.Text.Trim().Split(' ')
if ($parts.Count -lt 2) {
@@ -925,6 +976,7 @@ function Get-FluxerChangedMounts([string]$TargetDir, [string]$StagingDir) {
# By hand:
# docker compose config --services
function Get-FluxerComposeServices {
Assert-FluxerComposeSelector '--services'
$services = @()
foreach ($line in $script:FluxerComposeOut.Split("`n")) {
$candidate = $line.Trim()
@@ -1011,6 +1063,30 @@ function Set-FluxerEnvValue([string]$EnvPath, [string]$Name, [string]$Value) {
# every command this script runs before it reaches the step that would have reported it. Writing
# the value first is what makes the rest of the run possible. This runs before the record, so the
# .env the record saves is the one that works.
# The keys the run would write, without writing any of them. The plan and the run
# read the same list, so a plan cannot describe a run that does something else.
function Get-FluxerMissingRequiredSecrets([string]$EnvPath) {
$missing = @()
foreach ($entry in $FluxerUpgradeSecretKeys) {
$current = Get-FluxerEnvValue $EnvPath $entry.Name
if ($current.Length -eq 0 -or $current -eq 'CHANGE_ME') {
$missing += $entry.Name
}
}
return @($missing)
}
# A plan writes nothing itself. The run it describes writes .env before it reads
# anything when a required key is absent, and saying otherwise would describe a
# different run.
function Write-FluxerPlanFooter($Missing) {
if ($Missing.Count -gt 0) {
Write-FluxerLine 'This plan wrote nothing. The run it describes writes the keys above into .env before anything else.'
} else {
Write-FluxerLine 'Nothing outside a temporary directory was written.'
}
}
function Add-FluxerRequiredSecrets([string]$EnvPath) {
foreach ($entry in $FluxerUpgradeSecretKeys) {
$current = Get-FluxerEnvValue $EnvPath $entry.Name
@@ -1101,8 +1177,11 @@ function Save-FluxerCurrentFiles([string]$Record, [string]$TargetDir, [string]$E
Set-FluxerPrivateFile $envCopy
foreach ($name in $FluxerStackFiles) {
$source = Join-Path $TargetDir $name
if (Test-Path -LiteralPath $source) {
$length = Get-FluxerFileLength $source
if ($length -gt 0) {
Copy-Item -LiteralPath $source -Destination (Join-Path $Record $name) -Force
} elseif (Test-Path -LiteralPath $source) {
Stop-Fluxer "$source is empty, so the record would hold a file a rollback could not use. Put the file back before upgrading." $FluxerExitBackup
}
}
}
@@ -1169,7 +1248,7 @@ function Backup-FluxerDatabase([string]$Record, [string]$TargetDir) {
}
if (-not (Test-FluxerDumpHeader $dump)) {
Remove-FluxerTemporary $dump
Stop-Fluxer 'The dump does not carry the custom-format header. The instance is untouched.' $FluxerExitBackup
Stop-Fluxer 'The dump does not begin with the custom-format header. The instance is untouched.' $FluxerExitBackup
}
Write-FluxerLine "Dumped the database to $dump."
}
@@ -1317,20 +1396,31 @@ function Show-FluxerUpdatePlan([string]$TargetDir, [string]$EnvPath, [string]$Ba
Write-FluxerLine " Ref: $Ref"
Write-FluxerLine " Image tag: $(Get-FluxerEnvValue $EnvPath 'FLUXER_IMAGE_TAG') from .env"
Write-FluxerLine " Backup dir: $BackupRoot"
$missing = Get-FluxerMissingRequiredSecrets $EnvPath
if ($missing.Count -gt 0) {
Write-FluxerLine ' Writes .env: the run mints these before it reads anything, because the refreshed stack requires them'
foreach ($name in $missing) {
Write-FluxerLine " $name"
}
}
$running = Get-FluxerRunningImageIds
if ((Invoke-FluxerComposeQuery '--images') -ne 0) {
Write-FluxerLine ' Refusal: docker compose config --images fails here, and step 1 of the upgrade reads that list'
Write-FluxerLine ' Compose said:'
Write-FluxerLine (Get-FluxerComposeError ' ')
Write-FluxerLine ' Outcome: the run stops on step 1 and changes nothing'
Write-FluxerLine 'Nothing outside a temporary directory was written. Fix what Compose reports, then run this again.'
if ($missing.Count -gt 0) {
Write-FluxerLine ' Outcome: the run writes the keys above first, which may be what Compose is missing, so this refusal may not stand'
} else {
Write-FluxerLine ' Outcome: the run stops on step 1 and changes nothing'
}
Write-FluxerPlanFooter $missing
return
}
Write-FluxerLine ' Running now:'
foreach ($reference in Get-FluxerComposeImages) {
$id = Get-FluxerRunningImageId $running $reference
if ($id.Length -eq 0) {
$id = 'no container carries this image'
$id = 'no container runs this image'
}
Write-FluxerLine " $reference $id"
}
@@ -1370,7 +1460,7 @@ function Show-FluxerUpdatePlan([string]$TargetDir, [string]$EnvPath, [string]$Ba
if ($old.Length -gt 0 -and $new.Length -gt 0 -and $old -ne $new) {
Write-FluxerLine " Refusal: postgres moves from $old to $new, which this script does not do"
Write-FluxerLine ' Outcome: the run stops at that refusal and changes nothing'
Write-FluxerLine 'Nothing outside a temporary directory was written.'
Write-FluxerPlanFooter $missing
return
}
foreach ($entry in Get-FluxerChangedMounts $TargetDir $staging) {
@@ -1380,7 +1470,8 @@ function Show-FluxerUpdatePlan([string]$TargetDir, [string]$EnvPath, [string]$Ba
Remove-FluxerStagingDirectory $staging
}
Write-FluxerLine ' Commands: docker compose pull, docker compose up -d'
Write-FluxerLine 'Nothing outside a temporary directory was written. Drop -DryRun to run this.'
Write-FluxerPlanFooter $missing
Write-FluxerLine 'Drop -DryRun to run this.'
}
function Show-FluxerRollbackPlan([string]$TargetDir, [string]$EnvPath, [string]$BackupRoot) {
@@ -1539,8 +1630,11 @@ function Invoke-FluxerRollback([string]$TargetDir, [string]$EnvPath, [string]$Ba
foreach ($name in $FluxerStackFiles) {
$source = Join-Path $record $name
if (Test-Path -LiteralPath $source) {
$length = Get-FluxerFileLength $source
if ($length -gt 0) {
Copy-Item -LiteralPath $source -Destination (Join-Path $TargetDir $name) -Force
} elseif (Test-Path -LiteralPath $source) {
Stop-Fluxer "$source is empty, so restoring it would replace a working file with nothing. Nothing was restored. Take the file from another record or from the ref the record names." $FluxerExitRefused
}
}
Write-FluxerLine "Stack files in $TargetDir are the ones the record holds."
+185 -68
View File
@@ -53,7 +53,15 @@ export LC_ALL
FLUXER_RAW_BASE='https://raw.githubusercontent.com/fluxerapp/fluxer'
FLUXER_STACK_PATH='deploy/self-hosting'
FLUXER_MIN_ENGINE='24.0.0'
# Podman numbers its releases on its own scale, so the Docker Engine floor says
# nothing about it. 5.0 is the first release that runs this stack's compose file
# as written, healthcheck conditions and all.
FLUXER_MIN_PODMAN='5.0.0'
FLUXER_MIN_COMPOSE='2.20.2'
# Both overlays this script downloads use the !override tag, which Compose learned
# in 2.24.4. A stack that loads neither runs on the lower minimum, so the higher
# one is required only once COMPOSE_FILE names more than one file.
FLUXER_MIN_COMPOSE_OVERLAY='2.24.4'
FLUXER_READY_TIMEOUT=600
FLUXER_READY_INTERVAL=5
FLUXER_VAPID_ATTEMPTS=8
@@ -170,7 +178,11 @@ Usage: sh install.sh --domain <host> --email <address> [options]
Options:
--domain <host> Hostname the instance answers on. Prompted when absent.
--email <address> Address the operator reads. Prompted when absent.
--dir <path> Working directory. Default ~/fluxer.
--engine <command> Container engine to drive. Default docker, or podman
when docker is absent.
--dir <path> Working directory. Default ~/fluxer, or the working
directory itself when --update or --rollback is given
and it holds an instance.
--ref <git ref> Ref the stack files come from. Default: the image tag,
and main when that tag is v1 or latest.
--image-tag <tag> Image tag the stack runs. Default v1.
@@ -178,7 +190,7 @@ Options:
--edge-bind <addr:port> Plain HTTP bind under --tls proxy. Default 127.0.0.1:8080.
--non-interactive Never prompt. A missing required value is an error.
--dry-run Print the plan. Change nothing.
--no-start Write everything and skip docker compose up -d.
--no-start Write everything and skip $fluxer_engine compose up -d.
--update Upgrade: record, back up, refresh, pull, recreate, verify.
--rollback Restore the images and stack files of the last record.
--backup-dir <path> Where records go. Default <dir>/backups.
@@ -241,6 +253,9 @@ trap fluxer_on_signal TERM
opt_domain=''
opt_email=''
opt_dir=''
opt_engine=''
fluxer_engine='docker'
fluxer_engine_label='Docker Engine'
opt_ref=''
opt_image_tag='v1'
opt_tls='bundled'
@@ -267,6 +282,11 @@ while [ $# -gt 0 ]; do
opt_email=$2
shift 2
;;
--engine)
fluxer_take_value '--engine' $# "${2:-}"
opt_engine=$2
shift 2
;;
--dir)
fluxer_take_value '--dir' $# "${2:-}"
opt_dir=$2
@@ -461,29 +481,59 @@ fluxer_version_ge() {
fluxer_engine_version=''
fluxer_compose_version=''
# Every engine that speaks the Docker CLI reports itself as "<name> version X".
# Docker says "Docker version 28.0.0, build ...", Podman says "podman version
# 5.8.4", and the podman-docker shim answers as Podman under the name docker.
# Reading the name as well as the number is what lets the floor below belong to
# the engine actually in use, because Podman's 5.x is not Docker's 5.x.
fluxer_resolve_engine() {
if [ -n "$opt_engine" ]; then
fluxer_engine=$opt_engine
elif command -v docker >/dev/null 2>&1; then
fluxer_engine='docker'
elif command -v podman >/dev/null 2>&1; then
fluxer_engine='podman'
else
fluxer_fail 2 "Neither docker nor podman is installed. $(fluxer_docker_hint)"
fi
if ! command -v "$fluxer_engine" >/dev/null 2>&1; then
fluxer_fail 2 "$fluxer_engine is not installed. Pass --engine with the command that drives your containers."
fi
}
fluxer_preflight() {
if [ "$opt_allow_root" -eq 0 ] && [ "$(id -u)" -eq 0 ]; then
fluxer_fail 2 'Running as root. Use an account in the docker group, or pass --allow-root.'
fi
if ! command -v docker >/dev/null 2>&1; then
fluxer_fail 2 "Docker is not installed. $(fluxer_docker_hint)"
fluxer_resolve_engine
if ! $fluxer_engine compose version >/dev/null 2>&1; then
fluxer_fail 2 "$fluxer_engine has no compose subcommand. $(fluxer_docker_hint)"
fi
if ! docker compose version >/dev/null 2>&1; then
fluxer_fail 2 "The Docker Compose v2 plugin is missing. $(fluxer_docker_hint)"
fi
fluxer_engine_version=$(docker --version 2>/dev/null | sed -n 's/^Docker version \([0-9][0-9.]*\).*/\1/p')
fluxer_compose_version=$(docker compose version --short 2>/dev/null | sed -n 's/^v\{0,1\}\([0-9][0-9.]*\).*/\1/p')
fluxer_engine_report=$($fluxer_engine --version 2>/dev/null)
fluxer_engine_kind=$(printf '%s\n' "$fluxer_engine_report" | sed -n 's/^\([A-Za-z][A-Za-z]*\) version .*/\1/p' | tr 'A-Z' 'a-z')
fluxer_engine_version=$(printf '%s\n' "$fluxer_engine_report" | sed -n 's/^[A-Za-z][A-Za-z]* version v\{0,1\}\([0-9][0-9.]*\).*/\1/p')
fluxer_compose_version=$($fluxer_engine compose version --short 2>/dev/null | sed -n 's/^v\{0,1\}\([0-9][0-9.]*\).*/\1/p')
if [ -z "$fluxer_engine_version" ] || [ -z "$fluxer_compose_version" ]; then
fluxer_fail 2 'Cannot read the Docker Engine and Compose versions.'
fluxer_fail 2 "Cannot read the engine and Compose versions from $fluxer_engine. It answered \"$fluxer_engine_report\" to --version."
fi
if ! fluxer_version_ge "$fluxer_engine_version" "$FLUXER_MIN_ENGINE"; then
fluxer_fail 2 "Docker Engine $fluxer_engine_version with Compose $fluxer_compose_version. Fluxer needs Engine $FLUXER_MIN_ENGINE or newer."
case $fluxer_engine_kind in
podman)
fluxer_engine_label='Podman'
fluxer_min_engine=$FLUXER_MIN_PODMAN
;;
*)
fluxer_engine_label='Docker Engine'
fluxer_min_engine=$FLUXER_MIN_ENGINE
;;
esac
if ! fluxer_version_ge "$fluxer_engine_version" "$fluxer_min_engine"; then
fluxer_fail 2 "$fluxer_engine_label $fluxer_engine_version with Compose $fluxer_compose_version. Fluxer needs $fluxer_engine_label $fluxer_min_engine or newer."
fi
if ! fluxer_version_ge "$fluxer_compose_version" "$FLUXER_MIN_COMPOSE"; then
fluxer_fail 2 "Docker Engine $fluxer_engine_version with Compose $fluxer_compose_version. Fluxer needs Compose $FLUXER_MIN_COMPOSE or newer."
fluxer_fail 2 "$fluxer_engine_label $fluxer_engine_version with Compose $fluxer_compose_version. Fluxer needs Compose $FLUXER_MIN_COMPOSE or newer."
fi
if ! docker info >/dev/null 2>&1; then
fluxer_fail 2 'The Docker daemon does not answer. Start Docker and run this again.'
if ! $fluxer_engine info >/dev/null 2>&1; then
fluxer_fail 2 "$fluxer_engine does not answer. Start it and run this again."
fi
if ! command -v curl >/dev/null 2>&1; then
fluxer_fail 2 "curl is not installed. $(fluxer_host_tool_hint curl)"
@@ -491,7 +541,7 @@ fluxer_preflight() {
if ! command -v openssl >/dev/null 2>&1; then
fluxer_fail 2 "openssl is not installed. $(fluxer_host_tool_hint openssl)"
fi
fluxer_say "Docker Engine $fluxer_engine_version with Compose $fluxer_compose_version."
fluxer_say "$fluxer_engine_label $fluxer_engine_version with Compose $fluxer_compose_version."
}
fluxer_valid_domain() {
@@ -679,7 +729,7 @@ fluxer_fetch_stack() {
fluxer_fail 4 "Downloaded $fluxer_file is empty."
fi
if [ "$fluxer_file" = 'docker-compose.yml' ] && ! grep -q '^services:' "$fluxer_part"; then
fluxer_fail 4 'The downloaded docker-compose.yml carries no services block.'
fluxer_fail 4 "The docker-compose.yml downloaded from $opt_ref holds no services block."
fi
done < "$fluxer_scratch/files"
}
@@ -729,9 +779,9 @@ fluxer_check_volumes() {
if [ -z "$fluxer_project" ]; then
return 0
fi
docker volume ls -q --filter "label=com.docker.compose.project=$fluxer_project" > "$fluxer_scratch/volumes" 2>/dev/null || return 0
$fluxer_engine volume ls -q --filter "label=com.docker.compose.project=$fluxer_project" > "$fluxer_scratch/volumes" 2>/dev/null || return 0
if [ -s "$fluxer_scratch/volumes" ]; then
fluxer_fail 3 "Docker already holds volumes for the $fluxer_project project. They carry the secrets of an earlier install, and this .env does not open them. Run install.sh --update in the directory that holds that instance, or remove the volumes with docker volume rm before you install again."
fluxer_fail 3 "Docker already holds volumes for the $fluxer_project project. They hold the secrets of an earlier install, and this .env does not open them. Run install.sh --update in the directory that holds that instance, or remove the volumes with $fluxer_engine volume rm before you install again."
fi
}
@@ -839,9 +889,9 @@ fluxer_write_env() {
}
fluxer_stack_ready() {
docker compose ps -aq > "$fluxer_scratch/ids" 2>/dev/null || return 1
$fluxer_engine compose ps -aq > "$fluxer_scratch/ids" 2>/dev/null || return 1
[ -s "$fluxer_scratch/ids" ] || return 1
xargs docker inspect --format "$FLUXER_INSPECT_FORMAT" < "$fluxer_scratch/ids" > "$fluxer_scratch/state" 2>/dev/null || return 1
xargs $fluxer_engine inspect --format "$FLUXER_INSPECT_FORMAT" < "$fluxer_scratch/ids" > "$fluxer_scratch/state" 2>/dev/null || return 1
fluxer_ready=1
fluxer_init_done=0
while read -r fluxer_service fluxer_status fluxer_health fluxer_code; do
@@ -961,6 +1011,20 @@ fluxer_env_set() {
#
# This runs before the record, so the .env the record saves is the one that
# works and a rollback does not reintroduce the gap.
# The keys the run would write, one per line, without writing any of them. The
# plan and the run read the same list, so a plan cannot describe a run that does
# something else.
fluxer_missing_required_secrets() {
fluxer_upgrade_secret_keys > "$fluxer_scratch/upgrade-keys"
while read -r fluxer_key fluxer_kind; do
[ -n "$fluxer_key" ] || continue
fluxer_current=$(fluxer_env_value "$fluxer_key")
case ${fluxer_current:-} in
''|CHANGE_ME) printf '%s\n' "$fluxer_key" ;;
esac
done < "$fluxer_scratch/upgrade-keys"
}
fluxer_fill_required_secrets() {
fluxer_upgrade_secret_keys > "$fluxer_scratch/upgrade-keys"
while read -r fluxer_key fluxer_kind; do
@@ -1037,6 +1101,7 @@ fluxer_require_compose_files() {
if [ -z "$fluxer_path_sep" ]; then
fluxer_path_sep=':'
fi
fluxer_compose_count=0
fluxer_rest=$fluxer_compose_file
while [ -n "$fluxer_rest" ]; do
case $fluxer_rest in
@@ -1054,14 +1119,19 @@ fluxer_require_compose_files() {
/*) fluxer_path=$fluxer_name ;;
*) fluxer_path="$opt_dir/$fluxer_name" ;;
esac
fluxer_compose_count=$((${fluxer_compose_count:-0} + 1))
[ ! -e "$fluxer_path" ] || continue
if fluxer_stack_files | grep -qxF "$fluxer_name"; then
fluxer_fail 2 "COMPOSE_FILE from $fluxer_compose_from names $fluxer_name and $fluxer_path is not there, so every docker compose command in $opt_dir fails and this run stops before it changes anything. This script downloads $fluxer_name, and an instance set up before it existed does not hold that file yet. Put it in place and run this again:
fluxer_fail 2 "COMPOSE_FILE from $fluxer_compose_from names $fluxer_name and $fluxer_path is not there, so every $fluxer_engine compose command in $opt_dir fails and this run stops before it changes anything. This script downloads $fluxer_name, and an instance set up before it existed does not hold that file yet. Put it in place and run this again:
curl -fsSL --proto '=https' --tlsv1.2 -o $fluxer_path $FLUXER_RAW_BASE/$opt_ref/$FLUXER_STACK_PATH/$fluxer_name
Leave the COMPOSE_FILE line as it is. Without $fluxer_name the edge container binds 80 and 443 and requests its own certificate."
fi
fluxer_fail 2 "COMPOSE_FILE from $fluxer_compose_from names $fluxer_name and $fluxer_path is not there, so every docker compose command in $opt_dir fails. This script does not download $fluxer_name. Put that file back, or take it out of the COMPOSE_FILE line."
fluxer_fail 2 "COMPOSE_FILE from $fluxer_compose_from names $fluxer_name and $fluxer_path is not there, so every $fluxer_engine compose command in $opt_dir fails. This script does not download $fluxer_name. Put that file back, or take it out of the COMPOSE_FILE line."
done
if [ "$fluxer_compose_count" -gt 1 ] &&
! fluxer_version_ge "$fluxer_compose_version" "$FLUXER_MIN_COMPOSE_OVERLAY"; then
fluxer_fail 2 "COMPOSE_FILE from $fluxer_compose_from loads $fluxer_compose_count files and this host runs Compose $fluxer_compose_version. Every overlay this script downloads uses the !override tag, which needs Compose $FLUXER_MIN_COMPOSE_OVERLAY or newer. Upgrade Compose, or load only docker-compose.yml."
fi
}
# One read-only Compose query, with what Compose printed on stderr kept.
@@ -1076,7 +1146,7 @@ Leave the COMPOSE_FILE line as it is. Without $fluxer_name the edge container bi
# command.
fluxer_compose_query() {
fluxer_query_status=0
docker compose config "$1" > "$fluxer_scratch/compose-out" 2> "$fluxer_scratch/compose-err" || fluxer_query_status=$?
$fluxer_engine compose config "$1" > "$fluxer_scratch/compose-out" 2> "$fluxer_scratch/compose-err" || fluxer_query_status=$?
return "$fluxer_query_status"
}
@@ -1113,10 +1183,29 @@ fluxer_compose_images() {
#
# By hand:
# docker compose ps -aq | xargs docker inspect --format '{{.Config.Image}} {{.Image}}'
# The text of a captured stream, indented one level for the caller, or a word
# saying there was none. A command that fails without printing is rarer than one
# that prints the reason, and both read the same way here.
fluxer_indent_file() {
if [ -s "$1" ]; then
sed "s/^/$2/" "$1"
else
printf '%snothing\n' "$2"
fi
}
fluxer_running_image_ids() {
docker compose ps -aq > "$fluxer_scratch/containers" 2>/dev/null || return 0
if ! $fluxer_engine compose ps -aq > "$fluxer_scratch/containers" 2> "$fluxer_scratch/ps-err"; then
fluxer_fail 2 "$fluxer_engine compose ps failed in $opt_dir, so what is running cannot be read and the record would name no image ID at all. Compose printed:
$(fluxer_indent_file "$fluxer_scratch/ps-err" ' ')"
fi
[ -s "$fluxer_scratch/containers" ] || return 0
xargs docker inspect --format '{{.Config.Image}} {{.Image}}' < "$fluxer_scratch/containers" 2>/dev/null | sort -u
if ! xargs $fluxer_engine inspect --format '{{.Config.Image}} {{.Image}}' \
< "$fluxer_scratch/containers" > "$fluxer_scratch/inspected" 2> "$fluxer_scratch/inspect-err"; then
fluxer_fail 2 "$fluxer_engine inspect failed in $opt_dir, so the image ID under each reference cannot be read and a rollback would have nothing to go back to. Docker printed:
$(fluxer_indent_file "$fluxer_scratch/inspect-err" ' ')"
fi
sort -u "$fluxer_scratch/inspected"
}
# The recorded ID for one reference, or nothing when no container carries it.
@@ -1142,11 +1231,11 @@ fluxer_recorded_id_for() {
fluxer_record_state() {
fluxer_running_image_ids > "$fluxer_scratch/running"
if ! fluxer_compose_images > "$fluxer_scratch/refs"; then
fluxer_fail 2 "docker compose config --images failed in $opt_dir, so the running version cannot be recorded. Compose printed:
fluxer_fail 2 "$fluxer_engine compose config --images failed in $opt_dir, so the running version cannot be recorded. Compose printed:
$(fluxer_compose_error ' ')"
fi
if [ ! -s "$fluxer_scratch/refs" ]; then
fluxer_fail 2 "docker compose config --images returned nothing in $opt_dir, so the running version cannot be recorded. The stack files there declare no service with an image."
fluxer_fail 2 "$fluxer_engine compose config --images returned nothing in $opt_dir, so the running version cannot be recorded. The stack files there declare no service with an image."
fi
fluxer_prepare_record
printf '%s\n' "$(fluxer_env_value FLUXER_IMAGE_TAG)" > "$fluxer_record/$FLUXER_TAG_FILE"
@@ -1171,16 +1260,18 @@ fluxer_save_current_files() {
chmod 600 "$fluxer_record/.env"
while read -r fluxer_file; do
[ -n "$fluxer_file" ] || continue
if [ -e "$opt_dir/$fluxer_file" ]; then
if [ -s "$opt_dir/$fluxer_file" ]; then
cp -p "$opt_dir/$fluxer_file" "$fluxer_record/$fluxer_file"
elif [ -e "$opt_dir/$fluxer_file" ]; then
fluxer_fail 7 "$opt_dir/$fluxer_file is empty, so the record would hold a file a rollback could not use. Put the file back before upgrading."
fi
done < "$fluxer_scratch/files"
}
fluxer_postgres_running() {
fluxer_pg_id=$(docker compose ps -q postgres 2>/dev/null | head -n 1)
fluxer_pg_id=$($fluxer_engine compose ps -q postgres 2>/dev/null | head -n 1)
[ -n "$fluxer_pg_id" ] || return 1
[ "$(docker inspect --format '{{.State.Status}}' "$fluxer_pg_id" 2>/dev/null)" = 'running' ]
[ "$($fluxer_engine inspect --format '{{.State.Status}}' "$fluxer_pg_id" 2>/dev/null)" = 'running' ]
}
# Step 2 of an upgrade, and the part that gates the rest.
@@ -1208,19 +1299,19 @@ fluxer_postgres_running() {
fluxer_dump_postgres() {
if ! fluxer_postgres_running; then
fluxer_say 'Postgres is not running. Starting it for the dump.'
if ! docker compose up -d --wait postgres; then
if ! $fluxer_engine compose up -d --wait postgres; then
fluxer_fail 7 "Postgres does not start in $opt_dir, so no dump can be taken."
fi
fi
fluxer_dump_path="$fluxer_record/$FLUXER_DUMP_FILE"
fluxer_say 'Dumping the database.'
if ! docker compose exec -T postgres pg_dump -U fluxer -d fluxer --format=custom > "$fluxer_dump_path"; then
if ! $fluxer_engine compose exec -T postgres pg_dump -U fluxer -d fluxer --format=custom > "$fluxer_dump_path"; then
rm -f "$fluxer_dump_path"
fluxer_fail 7 'pg_dump failed. The instance is untouched.'
fi
if [ "$(head -c 5 "$fluxer_dump_path")" != 'PGDMP' ]; then
rm -f "$fluxer_dump_path"
fluxer_fail 7 'The dump does not carry the custom-format header. The instance is untouched.'
fluxer_fail 7 'The dump does not begin with the custom-format header. The instance is untouched.'
fi
fluxer_say "Dumped the database to $fluxer_dump_path."
}
@@ -1235,7 +1326,7 @@ fluxer_volume_error() {
}
fluxer_volume_size_kb() {
docker run --rm -v "$1:/data:ro" "$FLUXER_HELPER_IMAGE" du -sk /data 2> "$fluxer_scratch/volume-err" |
$fluxer_engine run --rm -v "$1:/data:ro" "$FLUXER_HELPER_IMAGE" du -sk /data 2> "$fluxer_scratch/volume-err" |
awk 'NR==1 {print $1}'
}
@@ -1260,7 +1351,7 @@ fluxer_copy_volumes() {
while read -r fluxer_volume; do
[ -n "$fluxer_volume" ] || continue
fluxer_full="${fluxer_project}_${fluxer_volume}"
if ! docker volume inspect "$fluxer_full" >/dev/null 2>&1; then
if ! $fluxer_engine volume inspect "$fluxer_full" >/dev/null 2>&1; then
fluxer_fail 7 "The volume $fluxer_full does not exist, so the uploads cannot be copied. The stack declares that volume, so this is a project name other than $fluxer_project or a volume that was removed. Pass --no-volume-backup to take the database dump alone when the uploads of this instance live somewhere this script cannot reach."
fi
fluxer_size=$(fluxer_volume_size_kb "$fluxer_full")
@@ -1284,21 +1375,21 @@ $(fluxer_volume_error ' ')" ;;
return 0
fi
fluxer_say 'Stopping the stack for a consistent copy of the uploads.'
if ! docker compose stop; then
fluxer_fail 7 "docker compose stop failed in $opt_dir."
if ! $fluxer_engine compose stop; then
fluxer_fail 7 "$fluxer_engine compose stop failed in $opt_dir."
fi
while read -r fluxer_volume; do
[ -n "$fluxer_volume" ] || continue
fluxer_full="${fluxer_project}_${fluxer_volume}"
fluxer_say "Copying $fluxer_full."
if ! docker run --rm -v "$fluxer_full:/data:ro" -v "$fluxer_record:/backup" "$FLUXER_HELPER_IMAGE" tar czf "/backup/$fluxer_volume.tgz" -C /data .; then
docker compose up -d --remove-orphans || true
if ! $fluxer_engine run --rm -v "$fluxer_full:/data:ro" -v "$fluxer_record:/backup" "$FLUXER_HELPER_IMAGE" tar czf "/backup/$fluxer_volume.tgz" -C /data .; then
$fluxer_engine compose up -d --remove-orphans || true
fluxer_fail 7 "Copying $fluxer_full failed. The stack is started again on the images it was running."
fi
done < "$fluxer_scratch/copy-volumes"
fluxer_say 'Starting the stack again before the upgrade continues.'
if ! docker compose up -d --remove-orphans; then
fluxer_fail 7 "docker compose up -d failed in $opt_dir after the copy. Read docker compose logs there."
if ! $fluxer_engine compose up -d --remove-orphans; then
fluxer_fail 7 "$fluxer_engine compose up -d failed in $opt_dir after the copy. Read $fluxer_engine compose logs there."
fi
}
@@ -1373,7 +1464,7 @@ fluxer_compose_services() {
fluxer_restart_mounted() {
[ -s "$fluxer_scratch/restart" ] || return 0
if ! fluxer_compose_services > "$fluxer_scratch/services"; then
fluxer_fail 6 "docker compose config --services failed in $opt_dir, so the services that mount a refreshed file cannot be restarted. Compose printed:
fluxer_fail 6 "$fluxer_engine compose config --services failed in $opt_dir, so the services that mount a refreshed file cannot be restarted. Compose printed:
$(fluxer_compose_error ' ')"
fi
while read -r fluxer_file fluxer_service; do
@@ -1383,8 +1474,8 @@ $(fluxer_compose_error ' ')"
continue
fi
fluxer_say "Restarting $fluxer_service, because $fluxer_file is mounted into it and up -d does not reload a mounted file."
if ! docker compose restart "$fluxer_service"; then
fluxer_fail 6 "docker compose restart $fluxer_service failed in $opt_dir."
if ! $fluxer_engine compose restart "$fluxer_service"; then
fluxer_fail 6 "$fluxer_engine compose restart $fluxer_service failed in $opt_dir."
fi
done < "$fluxer_scratch/restart"
}
@@ -1417,7 +1508,7 @@ fluxer_newest_record() {
fluxer_verify_stack() {
fluxer_say 'Waiting for every service to report ready.'
if ! fluxer_wait_ready; then
fluxer_fail 6 "The stack is not ready after $FLUXER_READY_TIMEOUT seconds. Read docker compose logs in $opt_dir."
fluxer_fail 6 "The stack is not ready after $FLUXER_READY_TIMEOUT seconds. Read $fluxer_engine compose logs in $opt_dir."
fi
fluxer_domain_value=$(fluxer_env_value FLUXER_DOMAIN)
if [ -n "$fluxer_domain_value" ]; then
@@ -1425,19 +1516,42 @@ fluxer_verify_stack() {
fi
}
# A plan writes nothing itself. The run it describes writes .env before it reads
# anything when a required key is absent, and saying otherwise would describe a
# different run.
fluxer_plan_footer() {
if [ -s "$fluxer_scratch/plan-secrets" ]; then
fluxer_say 'This plan wrote nothing. The run it describes writes the keys above into .env before anything else.'
else
fluxer_say 'Nothing outside a temporary directory was written.'
fi
}
fluxer_plan_update() {
fluxer_say 'Plan: upgrade'
fluxer_say " directory $opt_dir"
fluxer_say " ref $opt_ref"
fluxer_say " image tag $(fluxer_env_value FLUXER_IMAGE_TAG) from .env"
fluxer_say " backup dir $opt_backup_dir"
fluxer_missing_required_secrets > "$fluxer_scratch/plan-secrets"
if [ -s "$fluxer_scratch/plan-secrets" ]; then
fluxer_say ' writes .env the run mints these before it reads anything, because the refreshed stack requires them'
while read -r fluxer_key; do
[ -n "$fluxer_key" ] || continue
fluxer_say " $fluxer_key"
done < "$fluxer_scratch/plan-secrets"
fi
fluxer_running_image_ids > "$fluxer_scratch/running"
if ! fluxer_compose_images > "$fluxer_scratch/refs"; then
fluxer_say ' refusal docker compose config --images fails here, and step 1 of the upgrade reads that list'
fluxer_say ' refusal $fluxer_engine compose config --images fails here, and step 1 of the upgrade reads that list'
fluxer_say ' compose said'
fluxer_compose_error ' '
fluxer_say ' outcome the run stops on step 1 and changes nothing'
fluxer_say 'Nothing outside a temporary directory was written. Fix what Compose reports, then run this again.'
if [ -s "$fluxer_scratch/plan-secrets" ]; then
fluxer_say ' outcome the run writes the keys above first, which may be what Compose is missing, so this refusal may not stand'
else
fluxer_say ' outcome the run stops on step 1 and changes nothing'
fi
fluxer_plan_footer
return 0
fi
fluxer_say ' running now'
@@ -1445,7 +1559,7 @@ fluxer_plan_update() {
[ -n "$fluxer_ref" ] || continue
fluxer_id=$(fluxer_recorded_id_for "$fluxer_ref")
if [ -z "$fluxer_id" ]; then
fluxer_id='no container carries this image'
fluxer_id='no container runs this image'
fi
fluxer_say " $fluxer_ref $fluxer_id"
done < "$fluxer_scratch/refs"
@@ -1480,7 +1594,7 @@ fluxer_plan_update() {
if [ -n "$fluxer_old_major" ] && [ -n "$fluxer_new_major" ] && [ "$fluxer_old_major" != "$fluxer_new_major" ]; then
fluxer_say " refusal postgres moves from $fluxer_old_major to $fluxer_new_major, which this script does not do"
fluxer_say ' outcome the run stops at that refusal and changes nothing'
fluxer_say 'Nothing outside a temporary directory was written.'
fluxer_plan_footer
return 0
fi
fluxer_note_mounted_changes
@@ -1490,8 +1604,9 @@ fluxer_plan_update() {
fluxer_say " restart $fluxer_service, because $fluxer_file changes and a mounted file survives up -d"
done < "$fluxer_scratch/restart"
fi
fluxer_say ' commands docker compose pull, docker compose up -d'
fluxer_say 'Nothing outside a temporary directory was written. Drop --dry-run to run this.'
fluxer_say ' commands $fluxer_engine compose pull, $fluxer_engine compose up -d'
fluxer_plan_footer
fluxer_say 'Drop --dry-run to run this.'
}
fluxer_plan_rollback() {
@@ -1515,7 +1630,7 @@ fluxer_plan_rollback() {
[ -n "$fluxer_ref" ] || continue
if [ "$fluxer_id" = '-' ]; then
fluxer_say " $fluxer_ref was not recorded with an ID"
elif docker image inspect --format '{{.Id}}' "$fluxer_id" >/dev/null 2>&1; then
elif $fluxer_engine image inspect --format '{{.Id}}' "$fluxer_id" >/dev/null 2>&1; then
fluxer_say " $fluxer_ref back to $fluxer_id"
else
fluxer_say " $fluxer_ref is gone from this host, so $fluxer_id cannot come back"
@@ -1545,8 +1660,8 @@ fluxer_run_update() {
# By hand:
# docker compose pull
fluxer_say 'Pulling images.'
if ! docker compose pull; then
fluxer_fail 4 "docker compose pull failed in $opt_dir. The stack files are refreshed and the instance still runs the old images."
if ! $fluxer_engine compose pull; then
fluxer_fail 4 "$fluxer_engine compose pull failed in $opt_dir. The stack files are refreshed and the instance still runs the old images."
fi
# Recreates the containers whose image or configuration changed and leaves
# the rest running.
@@ -1568,8 +1683,8 @@ fluxer_run_update() {
# Gateway, so the hostname returns errors for a minute or two after this
# call. The api healthcheck allows 90 seconds before it counts a failure.
fluxer_say 'Recreating the stack.'
if ! docker compose up -d --remove-orphans; then
fluxer_fail 6 "docker compose up -d failed in $opt_dir. Read docker compose logs there."
if ! $fluxer_engine compose up -d --remove-orphans; then
fluxer_fail 6 "$fluxer_engine compose up -d failed in $opt_dir. Read $fluxer_engine compose logs there."
fi
fluxer_restart_mounted
fluxer_verify_stack
@@ -1650,31 +1765,33 @@ fluxer_run_rollback() {
while read -r fluxer_ref fluxer_id; do
[ -n "$fluxer_ref" ] || continue
[ "$fluxer_id" != '-' ] || continue
if ! docker image inspect --format '{{.Id}}' "$fluxer_id" >/dev/null 2>&1; then
if ! $fluxer_engine image inspect --format '{{.Id}}' "$fluxer_id" >/dev/null 2>&1; then
fluxer_say "$fluxer_ref is gone from this host, so it keeps the image it has now."
continue
fi
if ! docker image tag "$fluxer_id" "$fluxer_ref"; then
if ! $fluxer_engine image tag "$fluxer_id" "$fluxer_ref"; then
fluxer_fail 3 "Cannot put $fluxer_id back on $fluxer_ref."
fi
fluxer_moved=1
done < "$fluxer_rollback_dir/$FLUXER_IMAGES_FILE"
fi
if [ "$fluxer_moved" -eq 0 ]; then
fluxer_fail 2 "Nothing in $fluxer_rollback_dir can be put back. The recorded tag is the one in .env and every recorded image has been removed from this host, which a docker image prune does."
fluxer_fail 2 "Nothing in $fluxer_rollback_dir can be put back. The recorded tag is the one in .env and every recorded image has been removed from this host, which a $fluxer_engine image prune does."
fi
while read -r fluxer_file; do
[ -n "$fluxer_file" ] || continue
if [ -e "$fluxer_rollback_dir/$fluxer_file" ]; then
if [ -s "$fluxer_rollback_dir/$fluxer_file" ]; then
cp -p "$fluxer_rollback_dir/$fluxer_file" "$opt_dir/$fluxer_file"
elif [ -e "$fluxer_rollback_dir/$fluxer_file" ]; then
fluxer_fail 3 "$fluxer_rollback_dir/$fluxer_file is empty, so restoring it would replace a working file with nothing. Nothing was restored. Take the file from another record or from the ref the record names."
fi
done < "$fluxer_scratch/files"
fluxer_say "Stack files in $opt_dir are the ones the record holds."
fluxer_say 'Recreating the stack.'
if ! docker compose up -d --remove-orphans; then
fluxer_fail 6 "docker compose up -d failed in $opt_dir. Read docker compose logs there."
if ! $fluxer_engine compose up -d --remove-orphans; then
fluxer_fail 6 "$fluxer_engine compose up -d failed in $opt_dir. Read $fluxer_engine compose logs there."
fi
# The mounted file came back from the record, so its service restarts.
# Comparing it first would save one restart and cost the reader a reason.
@@ -1747,19 +1864,19 @@ fluxer_write_env
fluxer_say "Wrote $opt_dir/.env, readable by you alone."
if [ "$opt_no_start" -eq 1 ]; then
fluxer_say "Start the instance with docker compose up -d in $opt_dir."
fluxer_say "Start the instance with $fluxer_engine compose up -d in $opt_dir."
fluxer_say 'Open it and create the first admin account. Finish the setup wizard in the same sitting.'
fluxer_say "Secrets live in $opt_dir/.env. Back that file up."
exit 0
fi
fluxer_say 'Starting the stack.'
if ! docker compose up -d; then
fluxer_fail 6 "docker compose up -d failed in $opt_dir. Read docker compose logs there."
if ! $fluxer_engine compose up -d; then
fluxer_fail 6 "$fluxer_engine compose up -d failed in $opt_dir. Read $fluxer_engine compose logs there."
fi
fluxer_say 'Waiting for every service to report ready. This takes several minutes on the first start, which pulls eighteen images.'
if ! fluxer_wait_ready; then
fluxer_fail 6 "The stack is not ready after $FLUXER_READY_TIMEOUT seconds. Read docker compose logs in $opt_dir."
fluxer_fail 6 "The stack is not ready after $FLUXER_READY_TIMEOUT seconds. Read $fluxer_engine compose logs in $opt_dir."
fi
fluxer_probe "$opt_domain"
+1
View File
@@ -60,6 +60,7 @@ export const MAX_PRIVATE_CHANNELS_PER_USER = 250;
export const MAX_GROUP_DMS_PER_USER = 150;
export const MAX_BOOKMARKS_PREMIUM = 300;
export const MAX_BOOKMARKS_NON_PREMIUM = 50;
export const SAVED_MESSAGES_PAGE_SIZE = 50;
export const MAX_FAVORITE_MEMES_PREMIUM = 500;
export const MAX_FAVORITE_MEMES_NON_PREMIUM = 50;
export const MAX_FAVORITE_MEME_TAGS = 10;
+26 -4
View File
@@ -1,7 +1,7 @@
// SPDX-License-Identifier: AGPL-3.0-or-later
use crate::ast::{AlertType, ListItem, Node, ParserFlags, TableAlignment};
use crate::constants::{MAX_AST_NODES, MAX_LINE_LENGTH};
use crate::constants::{CODE_FENCE_LENGTH, MAX_AST_NODES, MAX_LINE_LENGTH};
use crate::links::{has_open_inline_code, has_valid_code_fence_language};
use crate::normalize::{normalize_nodes, replace_trailing_whitespace_with_newline};
use crate::parser::{MarkdownParser, ParseError, RuntimeState};
@@ -157,7 +157,7 @@ pub(crate) fn parse_block(state: &mut RuntimeState<'_>) -> Result<BlockParseResu
}
if ParserFlags::has(state.parser.flags(), ParserFlags::ALLOW_CODE_BLOCKS) {
if let Some(fence_pos) = line.find("```") {
if let Some(fence_pos) = find_unescaped_fence(&line) {
let starts_with_fence =
starts_with(trimmed, "```") && fence_pos == line.len() - trimmed.len();
if starts_with_fence {
@@ -459,7 +459,7 @@ fn parse_code_block(lines: &[Line], current: usize) -> Result<Option<CodeBlockRe
while fence_length < trimmed_line.len() && byte_at(trimmed_line, fence_length) == b'`' {
fence_length += 1;
}
if fence_length < 3 {
if fence_length < CODE_FENCE_LENGTH {
return Ok(None);
}
let language_part = &trimmed_line[fence_length..];
@@ -1197,7 +1197,7 @@ pub(crate) fn opens_code_block_midline(lines: &[Line], index: usize, flags: u32)
return false;
}
let line = &lines[index].text;
let Some(fence_pos) = line.find("```") else {
let Some(fence_pos) = find_unescaped_fence(line) else {
return false;
};
let trimmed = trim_start(line);
@@ -1267,6 +1267,28 @@ fn alert_type(label: &str) -> Option<AlertType> {
}
}
fn find_unescaped_fence(line: &str) -> Option<usize> {
let mut search = 0usize;
while let Some(offset) = line[search..].find("```") {
let fence_pos = search + offset;
if !is_escaped_fence(line, fence_pos) {
return Some(fence_pos);
}
search = fence_pos + 1;
}
None
}
fn is_escaped_fence(line: &str, fence_pos: usize) -> bool {
let mut backslashes = 0usize;
let mut index = fence_pos;
while index > 0 && byte_at(line, index - 1) == b'\\' {
backslashes += 1;
index -= 1;
}
backslashes % 2 == 1
}
fn slice_lines_from_fence(lines: &[Line], current: usize, fence_pos: usize) -> Vec<Line> {
let mut out = Vec::with_capacity(lines.len() - current);
out.push(Line {
@@ -1,5 +1,6 @@
// SPDX-License-Identifier: AGPL-3.0-or-later
pub const CODE_FENCE_LENGTH: usize = 3;
pub const MAX_AST_NODES: usize = 10_000;
pub const MAX_INLINE_DEPTH: usize = 10;
pub const MAX_LINES: usize = 10_000;
+17 -1
View File
@@ -1,7 +1,7 @@
// SPDX-License-Identifier: AGPL-3.0-or-later
use crate::ast::{EmojiKind, Node, ParserFlags, ParserResult};
use crate::constants::{MAX_INLINE_DEPTH, MAX_LINE_LENGTH};
use crate::constants::{CODE_FENCE_LENGTH, MAX_INLINE_DEPTH, MAX_LINE_LENGTH};
use crate::links;
use crate::normalize::{
combine_adjacent_text, compact_empty_text_nodes, flatten_top_level_formatting,
@@ -125,6 +125,14 @@ fn parse_inline_with_context(
position += 1 + emoji.len;
continue;
}
if next == b'`' {
let run = backtick_run_length(text, position + 1);
if run >= CODE_FENCE_LENGTH {
accumulated.extend(std::iter::repeat_n(b'`', run));
position += 1 + run;
continue;
}
}
if is_escapable_character(next)
|| is_ordered_list_marker_dot_escape(text, position)
|| is_word_dot_escape(text, position)
@@ -349,6 +357,14 @@ fn regional_indicator_letter(ch: char) -> Option<char> {
char::from_u32(u32::from(b'a') + codepoint - 0x1f1e6)
}
fn backtick_run_length(text: &str, start: usize) -> usize {
let mut run = 0usize;
while start + run < text.len() && byte_at(text, start + run) == b'`' {
run += 1;
}
run
}
fn is_ordered_list_marker_dot_escape(text: &str, backslash_position: usize) -> bool {
if backslash_position + 2 >= text.len()
|| byte_at(text, backslash_position + 1) != b'.'
@@ -202,3 +202,46 @@ fn unterminated_midline_fence_after_a_line_stays_text() {
json!([{"type": "Text", "content": "hello\nfoo```bar with no closing fence"}])
);
}
#[test]
fn escaped_fence_stays_text_on_one_line() {
assert_eq!(
parse("\\```hello```"),
json!([{"type": "Text", "content": "```hello```"}])
);
}
#[test]
fn escaped_fence_stays_text_across_lines() {
assert_eq!(
parse("\\```rust\nfn main() {}\n```"),
json!([{"type": "Text", "content": "```rust\nfn main() {}\n```"}])
);
}
#[test]
fn escaped_midline_fence_stays_text() {
assert_eq!(
parse("label\\```rust\nfn main() {}\n```"),
json!([{"type": "Text", "content": "label```rust\nfn main() {}\n```"}])
);
}
#[test]
fn escaped_backslash_before_fence_still_opens_a_code_block() {
assert_eq!(
parse("\\\\```hello```"),
json!([
{"type": "Text", "content": "\\"},
{"type": "CodeBlock", "content": "hello"}
])
);
}
#[test]
fn longer_escaped_fence_stays_text() {
assert_eq!(
parse("\\````hello````"),
json!([{"type": "Text", "content": "````hello````"}])
);
}
@@ -590,6 +590,7 @@ export const UserSavedMessagesQueryRequest = z.object({
limit: createQueryIntegerType({minValue: 1, maxValue: 100, defaultValue: 25}).describe(
'Maximum number of saved messages to return (1-100, default 25)',
),
before: SnowflakeType.optional().describe('Get saved messages before this message ID'),
});
export type UserSavedMessagesQueryRequest = z.infer<typeof UserSavedMessagesQueryRequest>;