Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
41 commits
Select commit Hold shift + click to select a range
47352bd
feat(desiderata): books the library is looking for, and donations fro…
fabiodalez-dev Sep 16, 2026
91ce48a
fix(desiderata): hide requests everywhere the public can reach, and m…
fabiodalez-dev Sep 16, 2026
d50fd97
fix(desiderata): stop the wanted-list leaking through the seams aroun…
fabiodalez-dev Sep 17, 2026
6e0cbe6
feat(desiderata): make the wanted list a part of the library, not a p…
fabiodalez-dev Sep 17, 2026
529cc5f
ci: keep the workflow linters honest after the requires_app guard mov…
fabiodalez-dev Sep 17, 2026
9d6d1aa
feat(desiderata): tell the operators when a book is offered and when …
fabiodalez-dev Sep 17, 2026
ca43dc4
fix: close the review findings around the wanted list
fabiodalez-dev Sep 17, 2026
4d6ef42
feat(desiderata): let a reader reach the book, page through the list,…
fabiodalez-dev Sep 17, 2026
272005d
test(desiderata): 154 checks over the behaviour this branch added
fabiodalez-dev Sep 17, 2026
0525bc1
test(desiderata): the nine browser tests, and the defect the first of…
fabiodalez-dev Sep 17, 2026
3f5e1a1
fix(i18n): the Danish receipt notification said inventory, not catalogue
fabiodalez-dev Sep 17, 2026
bc48fb8
fix: the locale gate misread JS comments, and a cleanup could swallow…
fabiodalez-dev Sep 17, 2026
9923296
test: a cleanup that dies part-way must not erase the result it was r…
fabiodalez-dev Sep 17, 2026
9281dbd
test: a check that described the developer's machine, and one that wo…
fabiodalez-dev Sep 17, 2026
e9730ea
fix(desiderata): keep the request until the copies exist, and anchor …
fabiodalez-dev Sep 17, 2026
47d098a
chore(release): cut 0.7.86, register desiderata at install, ship book…
fabiodalez-dev Sep 17, 2026
85d7073
test: the ConfigStore precondition described a database, not a behaviour
fabiodalez-dev Sep 17, 2026
7bc704a
fix(desiderata): stop the wanted flag from breaking things outside it…
fabiodalez-dev Sep 17, 2026
1e67740
test(desiderata): stop the dashboard check from asserting a property …
fabiodalez-dev Sep 17, 2026
92e1a1e
docs(visibility): record why the desiderata column probe may be memoised
fabiodalez-dev Sep 17, 2026
fa2fdcf
fix(desiderata): apply the four findings promoted in the walkthrough
fabiodalez-dev Sep 17, 2026
3e28b33
fix(desiderata): stop the thank-you banner depending on a session the…
fabiodalez-dev Sep 17, 2026
8f3153e
test(desiderata): follow the thank-you marker into the two assertions…
fabiodalez-dev Sep 17, 2026
c52e039
fix(forms): show a locked field as locked, and stop three browser che…
fabiodalez-dev Sep 17, 2026
504b93c
test(book-club): stop R16 passing when the declined loan is deleted i…
fabiodalez-dev Sep 17, 2026
305ef6e
fix(desiderata): stop the homepage donation form minting its session …
fabiodalez-dev Sep 18, 2026
5e4ede3
feat(desiderata): let a donor send from a browser the site never gave…
fabiodalez-dev Sep 18, 2026
76fb354
fix(desiderata): serialize CSRF initialization and recover interrupte…
fabiodalez-dev Sep 18, 2026
83e2d54
fix(desiderata): stamp catalogued_at on every insert, fold CSV header…
fabiodalez-dev Sep 18, 2026
24c13c0
test(desiderata): make sandbox suites order-independent and never lea…
fabiodalez-dev Sep 18, 2026
a890f15
fix(desiderata): close the remaining review findings
fabiodalez-dev Sep 18, 2026
757ea10
fix(auth): re-validate the session role on every protected request
fabiodalez-dev Sep 18, 2026
52fff5e
fix: close the remaining review findings and the bugs found while doc…
fabiodalez-dev Sep 18, 2026
67bb024
docs(hooks): document every hook core invokes and correct stale refer…
fabiodalez-dev Sep 18, 2026
e3d61f1
fix: address the CodeRabbit review of 76fb3547
fabiodalez-dev Sep 19, 2026
6364b18
fix(ui): keep typed search text across activity feed swaps, stop fals…
fabiodalez-dev Sep 19, 2026
464bb40
fix(auth): decide admin access on the re-validated role, so promotion…
fabiodalez-dev Sep 19, 2026
9342882
fix: address the CodeRabbit review of 6364b18d
fabiodalez-dev Sep 19, 2026
14d5b8c
test: keep "0" in the sandbox guard's list of real database names
fabiodalez-dev Sep 19, 2026
24bb009
Merge remote-tracking branch 'origin/main' into fix/desiderata-donazioni
fabiodalez-dev Sep 24, 2026
3870484
fix(desiderata): a failed proposals query is not an empty list
fabiodalez-dev Sep 24, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
70 changes: 68 additions & 2 deletions .github/workflows/ci-quality.yml
Original file line number Diff line number Diff line change
Expand Up @@ -109,11 +109,17 @@ jobs:
composer install --no-interaction --prefer-dist --quiet
composer audit --no-dev --abandoned=ignore 2>&1 || { echo "⚠ composer audit: vulnerabilities found (see above)"; exit 1; }

- name: npm audit (known CVEs)
- name: npm audit (known CVEs) # zizmor: ignore[adhoc-packages]
run: |
# npm bundled with Node 22 still POSTs the retired quick-audit
# endpoint (400 since 2026-09-04); npm 11+ talks to the bulk one.
# Tool upgrade, not a dependency: nothing from it ships in any asset.
# The zizmor exemption on this step's name is anchored to the step
# itself, not to a line number: a config pin drifts the moment
# anything above it changes, and it did three times in one day.
# It stays this narrow on purpose — nothing installed on an
# ephemeral runner ships in an asset, and asset reproducibility is
# enforced separately by the vendor-assets and double-build checks.
npm install -g npm@11.19.1 --silent
npm ci --silent
bash scripts/ci-npm-audit.sh .
Expand Down Expand Up @@ -237,6 +243,36 @@ jobs:
done
[ "$FAILED" -eq 0 ] && echo "✓ Tutte le migration hanno versione ≤ $TARGET" || exit 1

# ── Plugin requires_app guard ─────────────────────────────────────────
# Same version_compare ordering hazard as the migration guard, one layer
# up: PluginManager refuses to activate a bundled plugin whose
# requires_app is above version.json, so the plugin ships registered,
# visible and permanently impossible to enable. An empty or absent
# requires_app means "no floor" and is skipped, not failed.
- name: Plugin requires_app guard (bundled plugin.json ≤ version.json)
run: |
TARGET=$(php -r "echo json_decode(file_get_contents('version.json'))->version;")
FAILED=0
for f in storage/plugins/*/plugin.json; do
[ -f "$f" ] || continue
plugin_name="$(basename "$(dirname "$f")")"
# The single quotes below are load-bearing: $m is a PHP variable and
# must reach php unexpanded. The manifest path travels through the
# environment (getenv), so nothing here needs shell interpolation.
# shellcheck disable=SC2016
REQ=$(MANIFEST="$f" php -r '
$m = json_decode((string)file_get_contents(getenv("MANIFEST")), true);
echo is_array($m) && isset($m["requires_app"]) ? (string)$m["requires_app"] : "";
')
[ -n "$REQ" ] || continue
if ! REQUIRES_APP="$REQ" RELEASE_VERSION="$TARGET" php -r \
'exit(version_compare(getenv("REQUIRES_APP"), getenv("RELEASE_VERSION"), "<=") ? 0 : 1);'; then
echo " ✗ ${plugin_name}: requires_app $REQ > $TARGET (il plugin non potrebbe mai essere attivato)"
FAILED=1
fi
done
[ "$FAILED" -eq 0 ] && echo "✓ Tutti i plugin bundled hanno requires_app ≤ $TARGET" || exit 1

# DB-backed unit tests (migration-*, book-field-types, loan-edge-cases,
# session-fixes) read credentials from .env and connect over TCP. Provide
# a CI .env pointing at the MySQL service and load the base schema so the
Expand Down Expand Up @@ -306,6 +342,30 @@ jobs:
php tests/plugin-zip-update.integration.php
php tests/plugin-zip-update-all-bundled.integration.php

# The desiderata feature's advertised coverage: the lifecycle/offer suite
# and the interop-visibility contract (mobile-api, OAI-PMH, SRU, NCIP,
# OpenURL, BIBFRAME). Neither ran in any workflow before, so 400+ lines of
# regression checks executed only if a developer remembered to. Strict
# mode turns any remaining skip into a failure.
- name: PHP desiderata integration suites
env:
CI_STRICT_TESTS: '1'
run: |
php tests/desiderata.integration.php
php tests/desiderata-visibility.integration.php
php tests/desiderata-extended.integration.php
php tests/desiderata-recaptcha.unit.php
php tests/desiderata-core-hooks.unit.php
# desiderata-return-path, desiderata-bookclub-resolvable and
# desiderata-search-facets are NOT listed here: they are *.unit.php
# and the "PHP unit tests" step above already globs them. Naming them
# again would run each one twice.
# Run after plugin schema setup so the cross-plugin cases cannot skip.
REQUIRE_DESIDERATA_TESTS=1 php tests/bookclub-lending.unit.php

- name: Donation form CSRF concurrency regression
run: node --test tests/desiderata-csrf-concurrency.test.cjs

- name: Shell test — bin/setup-permissions.sh
run: bash tests/setup-permissions.test.sh

Expand Down Expand Up @@ -355,9 +415,15 @@ jobs:
cache-dependency-path: |
package-lock.json
frontend/package-lock.json
- name: Install and audit locked dependencies
- name: Install and audit locked dependencies # zizmor: ignore[adhoc-packages]
run: |
# Same retired quick-audit endpoint workaround as the root audit.
# The zizmor exemption on this step's name is anchored to the step
# itself, not to a line number: a config pin drifts the moment
# anything above it changes, and it did three times in one day.
# It stays this narrow on purpose — nothing installed on an
# ephemeral runner ships in an asset, and asset reproducibility is
# enforced separately by the vendor-assets and double-build checks.
npm install -g npm@11.19.1 --silent
npm ci --silent
bash scripts/ci-npm-audit.sh .
Expand Down
8 changes: 7 additions & 1 deletion .github/workflows/release.yml
Original file line number Diff line number Diff line change
Expand Up @@ -48,7 +48,7 @@ jobs:
node-version: '22'
package-manager-cache: false

- name: Install locked build inputs
- name: Install locked build inputs # zizmor: ignore[adhoc-packages]
run: |
sudo apt-get update -q
sudo apt-get install -y jq rsync unzip zip
Expand All @@ -58,6 +58,12 @@ jobs:
# npm bundled with Node 22 POSTs the retired quick-audit endpoint;
# npm 11 uses the bulk one, and the wrapper distinguishes real
# advisories from registry outages (retry, then loud neutral).
# The zizmor exemption on this step's name is anchored to the step
# itself, not to a line number: a config pin drifts the moment
# anything above it changes, and it did three times in one day.
# It stays this narrow on purpose — nothing installed on an
# ephemeral runner ships in an asset, and asset reproducibility is
# enforced separately by the vendor-assets and double-build checks.
npm install -g npm@11.19.1 --silent
npm ci --silent
bash scripts/ci-npm-audit.sh .
Expand Down
17 changes: 0 additions & 17 deletions .github/zizmor.yml

This file was deleted.

8 changes: 8 additions & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -97,6 +97,13 @@ storage/calendar/*
!storage/calendar/.htaccess
!storage/plugins/
storage/plugins/*
!storage/plugins/desiderata/
storage/plugins/desiderata/*
!storage/plugins/desiderata/*.php
!storage/plugins/desiderata/*.json
!storage/plugins/desiderata/*.md
!storage/plugins/desiderata/views/
!storage/plugins/desiderata/views/*.php
!storage/plugins/open-library/
storage/plugins/open-library/*
!storage/plugins/open-library/*.php
Expand Down Expand Up @@ -441,6 +448,7 @@ tests/*
!tests/*.unit.php
!tests/*.integration.php
!tests/*.test.sh
!tests/*.test.cjs
!tests/ci-playwright-policy.json
!tests/seeds/
tests/seeds/*
Expand Down
Loading
Loading