Author SHA1 Message Date
westfarn 00686ba53f Update workflow to use server-infra 2026-07-08 06:02:17 -05:00
westfarnandCursor d2f2409a53 fix(static): don't 500 on missing manifest entries at runtime
CI / test (pull_request) Successful in 10s
Unit Tests / test (pull_request) Successful in 9s
Templates reference public/img/logo.png (favicon, brand logo, social
share images) which isn't present in the repo. With the strict manifest
storage this raised ValueError at request time -> HTTP 500. Override
stored_name (and set manifest_strict=False) to fall back to the plain
name so a missing static degrades to a broken asset instead of a 500,
matching the previous non-manifest behaviour.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-07 13:18:49 -05:00
westfarnandCursor 5d378b7b19 fix(settings): accept JSON-array env lists in env_list
CI / test (pull_request) Successful in 10s
Unit Tests / test (pull_request) Successful in 9s
The production .env stores DJANGO_ALLOWED_HOSTS as a JSON array (legacy
format), but env_list only split on commas, yielding broken entries like
'["aimloperations.com"' and causing DisallowedHost (HTTP 400) for every
request. Parse JSON arrays as well as comma-separated values.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-07 13:13:57 -05:00
westfarnandCursor 5899c1f14f fix(static): tolerate missing asset references in collectstatic
CI / test (pull_request) Successful in 10s
Unit Tests / test (pull_request) Successful in 10s
WhiteNoise's manifest storage strictly resolves every referenced file
during collectstatic, including sourceMappingURL comments in vendored
JS bundles. A missing .map (financial/js/.../dashboard-free.js.map)
broke the prod container at startup. Add TolerantManifestStaticFilesStorage
which leaves unresolved references untouched instead of raising.

Co-authored-by: Cursor <cursoragent@cursor.com>
2026-07-07 13:10:51 -05:00
westfarn a4b37a0bb0 g
CI / test (pull_request) Successful in 10s
Unit Tests / test (pull_request) Successful in 10s
2026-07-07 11:20:15 -05:00
westfarn 115c5ae319 Dockerize Django app with dev/beta/prod env config and uv.
CI / test (pull_request) Successful in 11s
Unit Tests / test (pull_request) Failing after 6s
Replace hardcoded settings with environment-driven config, add Docker
compose for local and production deploys, migrate from pip to uv, and
split Gitea workflows so PRs run tests only while master pushes deploy.
2026-07-07 05:58:44 -05:00
10 changed files with 31 additions and 136 deletions
-2
View File
@@ -4,8 +4,6 @@ DJANGO_ENV=dev
DJANGO_DEBUG=true DJANGO_DEBUG=true
DJANGO_SECRET_KEY=change-me-for-local-development DJANGO_SECRET_KEY=change-me-for-local-development
DJANGO_ALLOWED_HOSTS=localhost,127.0.0.1,0.0.0.0 DJANGO_ALLOWED_HOSTS=localhost,127.0.0.1,0.0.0.0
# Optional; when unset, http:// origins are derived for local hosts.
# DJANGO_CSRF_TRUSTED_ORIGINS=http://localhost:8000,http://127.0.0.1:8000
# Database (docker-compose sets DATABASE_URL for the web service) # Database (docker-compose sets DATABASE_URL for the web service)
DATABASE_URL=postgres://company_site:company_site@db:5432/company_site DATABASE_URL=postgres://company_site:company_site@db:5432/company_site
-2
View File
@@ -7,8 +7,6 @@ DJANGO_ENV=prod
DJANGO_DEBUG=false DJANGO_DEBUG=false
DJANGO_SECRET_KEY=replace-with-a-long-random-secret DJANGO_SECRET_KEY=replace-with-a-long-random-secret
DJANGO_ALLOWED_HOSTS=aimloperations.com,www.aimloperations.com DJANGO_ALLOWED_HOSTS=aimloperations.com,www.aimloperations.com
# Optional override; when unset, https:// origins are derived from DJANGO_ALLOWED_HOSTS.
# DJANGO_CSRF_TRUSTED_ORIGINS=https://aimloperations.com,https://www.aimloperations.com
# Logging (optional override; defaults: dev=DEBUG, beta=INFO, prod=WARNING) # Logging (optional override; defaults: dev=DEBUG, beta=INFO, prod=WARNING)
# DJANGO_LOG_LEVEL=WARNING # DJANGO_LOG_LEVEL=WARNING
+26 -6
View File
@@ -1,6 +1,6 @@
name: Deploy Company Site name: Deploy Company Site
# Runs after Unit Tests completes on master. Direct pushes only (not PRs). # Deploy pipeline runs only on pushes to master (never on pull requests).
on: on:
workflow_run: workflow_run:
workflows: [Unit Tests] workflows: [Unit Tests]
@@ -8,14 +8,34 @@ on:
branches: [master] branches: [master]
jobs: jobs:
docker: test:
if: gitea.event.workflow_run.conclusion == 'success' && gitea.event.workflow_run.event == 'push'
runs-on: self-hosted runs-on: self-hosted
steps: steps:
- name: Checkout - name: Checkout
uses: actions/checkout@v4 uses: actions/checkout@v4
with:
ref: ${{ gitea.event.workflow_run.head_sha }} - name: Install uv
run: |
curl -LsSf https://astral.sh/uv/install.sh | sh
echo "$HOME/.local/bin" >> "$GITHUB_PATH"
- name: Install dependencies
run: uv sync --frozen
- name: Run unit tests
env:
DJANGO_ENV: dev
DJANGO_SECRET_KEY: test-secret-key
run: |
cd company_site
uv run python manage.py test
docker:
runs-on: self-hosted
needs: test
steps:
- name: Checkout
uses: actions/checkout@v4
- name: Build Docker image - name: Build Docker image
run: docker compose build run: docker compose build
@@ -33,7 +53,7 @@ jobs:
deploy: deploy:
if: gitea.event.workflow_run.conclusion == 'success' && gitea.event.workflow_run.event == 'push' if: gitea.event.workflow_run.conclusion == 'success' && gitea.event.workflow_run.event == 'push'
runs-on: self-hosted runs-on: self-hosted
needs: docker needs: [test, docker]
env: env:
SERVER_INFRA_ROOT: /home/westfarn/Documents/repos/server-infra SERVER_INFRA_ROOT: /home/westfarn/Documents/repos/server-infra
steps: steps:
@@ -82,34 +82,6 @@ WEBMCP_ENABLED = env_bool("WEBMCP_ENABLED", False)
allowed_hosts = env_list("DJANGO_ALLOWED_HOSTS", "*") allowed_hosts = env_list("DJANGO_ALLOWED_HOSTS", "*")
ALLOWED_HOSTS = allowed_hosts if allowed_hosts else ["*"] ALLOWED_HOSTS = allowed_hosts if allowed_hosts else ["*"]
def build_csrf_trusted_origins(
allowed_hosts: list[str], explicit: list[str] | None = None
) -> list[str]:
"""Build CSRF_TRUSTED_ORIGINS for Django 4+ Origin checks on HTTPS POSTs.
Prefer DJANGO_CSRF_TRUSTED_ORIGINS when set. Otherwise derive from ALLOWED_HOSTS:
https for public hosts, http for local loopback hosts.
"""
if explicit:
return explicit
local_hosts = {"localhost", "127.0.0.1", "0.0.0.0"}
origins: list[str] = []
for host in allowed_hosts:
if not host or host == "*" or host.startswith("."):
continue
hostname = host.split(":")[0]
scheme = "http" if hostname in local_hosts else "https"
origins.append(f"{scheme}://{host}")
return origins
CSRF_TRUSTED_ORIGINS = build_csrf_trusted_origins(
ALLOWED_HOSTS,
env_list("DJANGO_CSRF_TRUSTED_ORIGINS"),
)
INSTALLED_APPS = [ INSTALLED_APPS = [
"public.apps.PublicConfig", "public.apps.PublicConfig",
"financial.apps.FinancialConfig", "financial.apps.FinancialConfig",
@@ -11,10 +11,4 @@ if DEBUG:
warnings.warn("DEBUG is enabled in beta environment.", stacklevel=1) warnings.warn("DEBUG is enabled in beta environment.", stacklevel=1)
# Same reverse-proxy assumptions as production when TLS is terminated upstream.
SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https")
USE_X_FORWARDED_HOST = True
SESSION_COOKIE_SECURE = not DEBUG
CSRF_COOKIE_SECURE = not DEBUG
LOGGING = build_logging_config(logging_level_for_env("beta"), "beta") LOGGING = build_logging_config(logging_level_for_env("beta"), "beta")
@@ -9,10 +9,4 @@ TIANJI_ENABLED = env_bool("TIANJI_ENABLED", True) # noqa: F405
if not env("DJANGO_SECRET_KEY"): # noqa: F405 if not env("DJANGO_SECRET_KEY"): # noqa: F405
raise ValueError("DJANGO_SECRET_KEY must be set in production.") raise ValueError("DJANGO_SECRET_KEY must be set in production.")
# App sits behind a reverse proxy that terminates TLS (docker :8000).
SECURE_PROXY_SSL_HEADER = ("HTTP_X_FORWARDED_PROTO", "https")
USE_X_FORWARDED_HOST = True
SESSION_COOKIE_SECURE = True
CSRF_COOKIE_SECURE = True
LOGGING = build_logging_config(logging_level_for_env("prod"), "prod") LOGGING = build_logging_config(logging_level_for_env("prod"), "prod")
Binary file not shown.

Before

Width:  |  Height:  |  Size: 22 KiB

Binary file not shown.

Before

Width:  |  Height:  |  Size: 99 KiB

+1 -79
View File
@@ -1,90 +1,12 @@
from unittest.mock import patch from unittest.mock import patch
from django.contrib.auth.models import User
from django.test import Client, TestCase, override_settings from django.test import Client, TestCase, override_settings
from django.urls import reverse from django.urls import reverse
from company_site.settings.base import build_csrf_trusted_origins from .models import Contact
from .models import Contact, EmailMessage
from .seo import SERVICE_URL_NAMES, get_service_entries from .seo import SERVICE_URL_NAMES, get_service_entries
class CsrfTrustedOriginsTests(TestCase):
def test_derives_https_origins_from_public_hosts(self):
origins = build_csrf_trusted_origins(
["aimloperations.com", "www.aimloperations.com"]
)
self.assertEqual(
origins,
[
"https://aimloperations.com",
"https://www.aimloperations.com",
],
)
def test_derives_http_origins_for_local_hosts(self):
origins = build_csrf_trusted_origins(["localhost", "127.0.0.1"])
self.assertEqual(origins, ["http://localhost", "http://127.0.0.1"])
def test_explicit_origins_win(self):
origins = build_csrf_trusted_origins(
["aimloperations.com"],
["https://custom.example"],
)
self.assertEqual(origins, ["https://custom.example"])
class LogoutCsrfTests(TestCase):
def setUp(self):
self.client = Client(enforce_csrf_checks=True)
self.user = User.objects.create_user(username="logout_user", password="pass")
def test_logout_post_with_csrf_succeeds(self):
self.client.login(username="logout_user", password="pass")
self.client.get("/")
csrf = self.client.cookies["csrftoken"].value
response = self.client.post(
reverse("logout"),
{"csrfmiddlewaretoken": csrf},
)
self.assertEqual(response.status_code, 302)
self.assertEqual(response.url, "/")
self.assertNotIn("_auth_user_id", self.client.session)
class PreviewEmailAuthTests(TestCase):
def setUp(self):
self.client = Client()
self.user = User.objects.create_user(username="previewer", password="pass")
self.email = EmailMessage.objects.create(
subject="Preview subject",
body="Preview body content",
recipient="recipient@example.com",
)
self.url = reverse("preview_email", kwargs={"pk": self.email.pk})
def test_unauthenticated_user_is_redirected_to_login(self):
response = self.client.get(self.url)
self.assertEqual(response.status_code, 302)
self.assertIn("/accounts/login/", response.url)
def test_authenticated_user_can_preview_email(self):
self.client.login(username="previewer", password="pass")
response = self.client.get(self.url)
self.assertEqual(response.status_code, 200)
self.assertContains(response, "Preview subject")
self.assertContains(response, "Preview body content")
@override_settings( @override_settings(
DEBUG=True, DEBUG=True,
EMAIL_BACKEND="django.core.mail.backends.locmem.EmailBackend", EMAIL_BACKEND="django.core.mail.backends.locmem.EmailBackend",
+4 -7
View File
@@ -18,14 +18,11 @@ services:
build: . build: .
ports: ports:
- "8000:8000" - "8000:8000"
# No required env_file — CI has no .env. Defaults below; for local secrets: env_file:
# docker compose --env-file .env up - .env
environment: environment:
DJANGO_ENV: ${DJANGO_ENV:-dev} DJANGO_ENV: dev
DJANGO_SECRET_KEY: ${DJANGO_SECRET_KEY:-dev-only-change-me} DATABASE_URL: postgres://company_site:company_site@db:5432/company_site
DJANGO_DEBUG: ${DJANGO_DEBUG:-true}
DJANGO_ALLOWED_HOSTS: ${DJANGO_ALLOWED_HOSTS:-localhost,127.0.0.1,0.0.0.0}
DATABASE_URL: ${DATABASE_URL:-postgres://company_site:company_site@db:5432/company_site}
depends_on: depends_on:
db: db:
condition: service_healthy condition: service_healthy