Skip to content

4.0.0 - #1065

Merged
k1o0 merged 33 commits into
masterfrom
dev
Oct 7, 2026
Merged

4.0.0#1065
k1o0 merged 33 commits into
masterfrom
dev

Conversation

@k1o0

@k1o0 k1o0 commented Oct 7, 2026

Copy link
Copy Markdown
Collaborator

Added

  • Public databases can offer self-registration, enabled with the PUBLIC_DATABASE lab setting.
    Adds a sign-up page at /signup, email confirmation of new accounts, and a password reset
    flow so that self-registered accounts are recoverable without an administrator
  • set_public_permissions management command, creating a 'Public users' group carrying view
    permissions only, and never over user accounts or the permission structure itself
  • ec2_modify_groups.sh script now included in container to remove EC2 firewall before letsencrypt validation

Changed

  • Public users are no longer shown other people's accounts. Over REST, /users returns
    redacted users and the requester only, without email addresses; in the admin, the user and
    group models are hidden and user filter dropdowns no longer enumerate every account
  • set_user_permissions skips public users, which it previously added to the lab
    members group and marked active - granting members of the public write access and activating
    accounts that had never confirmed their email address

Removed

  • Core-api support for the /docs endpoint. SpectacularRedocViewCoreAPIDeprecation and
    data/coreapi.json are gone; /docs now serves SpectacularRedocView directly regardless of
    the request's Accept header. #1055

Fixed

  • Subjects in different labs may share a nickname. REST endpoints taking a subject nickname
    returned a 500 status when it matched more than one subject; the lab is now used to resolve
    duplicates - the lab field of the request data, ?lab= on /subjects/<nickname> and
    /water-requirement/<nickname>, or labs and the repository's labs for /register-file.
    An unresolved duplicate returns a 400 status, or 409 for a lookup, naming the labs.
    /subjects/<id> also accepts the subject UUID.
  • Open water restrictions are ended when a subject already has a death date, e.g. when a cull
    is added with the same date, not only when the death date is first set. The subject's
    protocol number is now updated when its water restrictions are ended.
  • Relative paths correctly rendered in cache table using pandas 3.
  • The data notice admin change page no longer renders the datasets as a multi-select widget:
    every attached dataset had to be fetched and rendered as a selected option, which did not scale past a few hundred, and saving posted one form field per dataset, which exceeded DATA_UPLOAD_MAX_NUMBER_FIELDS and failed with a 400 status. The datasets are now a read-only, scrollable list of the first 100, with the total count and a link to them in the dataset list. They can still be attached when creating a notice, or through the REST API.

k1o0 and others added 30 commits August 28, 2026 13:51
Sessions and probe insertions  REST filters no longer join the datasets table into the
  main query, which made them 3-174x faster ( went from 194 s to
  1.3 s against the production database, and  from 112 s to
  3.5 s). Adding indexes was measured and rejected: a covering index on
   is used but only worth ~5% of the remaining query time,
  and is not worth 153 MB plus the write amplification on a table the ingest pipeline
  writes to constantly. The remaining cost is one index lookup per tagged dataset to map
  it to its session; removing that needs the tags denormalised to the session level.
Resolves int-brain-lab/iblalyx#143
Dataset filtering faster (#894) and stable ordering (#1033)
Bumps [cryptography](https://github.com/pyca/cryptography) from 48.0.1 to 50.0.0.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@48.0.1...50.0.0)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [sqlparse](https://github.com/andialbrecht/sqlparse) from 0.5.4 to 0.6.0.
- [Changelog](https://github.com/andialbrecht/sqlparse/blob/master/CHANGELOG)
- [Commits](andialbrecht/sqlparse@0.5.4...0.6.0)

---
updated-dependencies:
- dependency-name: sqlparse
  dependency-version: 0.6.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [django](https://github.com/django/django) from 5.2.15 to 5.2.16.
- [Commits](django/django@5.2.15...5.2.16)

---
updated-dependencies:
- dependency-name: django
  dependency-version: 5.2.16
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
* pandas 3 fix for revisions in one_cache
In pandas 3 the revision column contains nans instead of empty strings which means the old check for truthiness always passes, resulting in #nan# in the relative path. This fix uses pd.isna and is backwards compatible

* Update CHANGELOG
* User sign up

* Remove is_redacted field; anonymize all non-public users by default

* Ensure migrations use schema editor db alias

* OICD SSO

* Improved templates; bot protection

* Updates to API docs for AI agents
/me endpoint now used validating token

* Handle missing settings

* Reduce comment bloat

* Add emails preferences to LabMember JSON

* Change to release approach

* pandas 3 fix for revisions in one_cache (#1044)

* pandas 3 fix for revisions in one_cache
In pandas 3 the revision column contains nans instead of empty strings which means the old check for truthiness always passes, resulting in #nan# in the relative path. This fix uses pd.isna and is backwards compatible

* Update CHANGELOG

* Fix Data Notice admin changeview

* Move ec2_modify_groups into container
Remote code execution can occur via the django= / JSON REST filters. E.g. GET /sessions?django=x,[__import__('os').popen('id').read()]. Fix'd with test coverage.
The signup and email-change confirmations build their links from request.get_host() / build_absolute_uri. An attacker sending a Host: header for any *.eu-west-2.compute.amazonaws.com box they control passes host validation, so the victim's confirmation/verification link points at the attacker's host — capturing the token.
Also hardened session cookie so it can't leak over an HTTP request. Now Django itself redirects to https, not just Apache
Traceback now logged to file and hidden from response context. Also status now actually 500 (was previously 200)
Four admin views were anonymously-accessible: /admin-tasks/status, /admin-actions/training, /admin-actions/subject-history, /admin-actions/water-history
Four REST endpoints were anonymously-accessible: POST /register-file, POST|GET /sync-file-status, POST /new-download, GET /check-protected
Remove the coreapi-compatibility shim on /docs: the trip-wire test,
SpectacularRedocViewCoreAPIDeprecation, and data/coreapi.json are gone.
/docs now serves SpectacularRedocView directly regardless of Accept header.

Closes #1055
* ea61382 (Signup #1057) inserted the SSO step between "Run tests" and its env: block, orphaning it. That left two env: keys on one step — a duplicate mapping key, which Actions rejects, so the workflow didn't run.
* 62c4433 "Remove duplicate env block" merged them into one valid block. Correct as a dedup, but both blocks were already on the SSO step, so the merge left "Run tests" with nothing. The workflow became valid and finally ran — revealing the breakage.
* PYTHONPATH: $HOME/builds/cortexlab/alyx — Actions does not expand $HOME in an env: block, so this is the literal string and points nowhere. Harmless, looks like a Travis leftover.
* /var/log/alyx is created by sudo mkdir so it's root-owned 755; only the log file is 666. RotatingFileHandler needs to create files in that directory to roll at 4 MB, and --parallel has several processes writing the same file.
Previously an SSO signup would redirect to /me/preferences, which would lead to a 404 on non-public databases.
Now it only redirects if email preferences are set (unlikely for institutional SSO)
Bumps [djangorestframework](https://github.com/encode/django-rest-framework) from 3.16.0 to 3.17.2.
- [Release notes](https://github.com/encode/django-rest-framework/releases)
- [Commits](encode/django-rest-framework@3.16.0...3.17.2)

---
updated-dependencies:
- dependency-name: djangorestframework
  dependency-version: 3.17.2
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0.
- [Release notes](https://github.com/jpadilla/pyjwt/releases)
- [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst)
- [Commits](jpadilla/pyjwt@2.13.0...2.15.0)

---
updated-dependencies:
- dependency-name: pyjwt
  dependency-version: 2.15.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
dependabot Bot and others added 3 commits October 2, 2026 00:48
Bumps [django](https://github.com/django/django) from 5.2.16 to 5.2.17.
- [Commits](django/django@5.2.16...5.2.17)

---
updated-dependencies:
- dependency-name: django
  dependency-version: 5.2.17
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0.
- [Release notes](https://github.com/urllib3/urllib3/releases)
- [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst)
- [Commits](urllib3/urllib3@2.7.0...2.8.0)

---
updated-dependencies:
- dependency-name: urllib3
  dependency-version: 2.8.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <[email protected]>
@k1o0
k1o0 merged commit eb7b20d into master Oct 7, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants