Repository navigation
Conversation
Sessions and probe insertions REST filters no longer join the datasets table into the main query, which made them 3-174x faster ( went from 194 s to 1.3 s against the production database, and from 112 s to 3.5 s). Adding indexes was measured and rejected: a covering index on is used but only worth ~5% of the remaining query time, and is not worth 153 MB plus the write amplification on a table the ingest pipeline writes to constantly. The remaining cost is one index lookup per tagged dataset to map it to its session; removing that needs the tags denormalised to the session level. Resolves int-brain-lab/iblalyx#143
Bumps [cryptography](https://github.com/pyca/cryptography) from 48.0.1 to 50.0.0. - [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst) - [Commits](pyca/cryptography@48.0.1...50.0.0) --- updated-dependencies: - dependency-name: cryptography dependency-version: 50.0.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
Bumps [sqlparse](https://github.com/andialbrecht/sqlparse) from 0.5.4 to 0.6.0. - [Changelog](https://github.com/andialbrecht/sqlparse/blob/master/CHANGELOG) - [Commits](andialbrecht/sqlparse@0.5.4...0.6.0) --- updated-dependencies: - dependency-name: sqlparse dependency-version: 0.6.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
Bumps [django](https://github.com/django/django) from 5.2.15 to 5.2.16. - [Commits](django/django@5.2.15...5.2.16) --- updated-dependencies: - dependency-name: django dependency-version: 5.2.16 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
* pandas 3 fix for revisions in one_cache In pandas 3 the revision column contains nans instead of empty strings which means the old check for truthiness always passes, resulting in #nan# in the relative path. This fix uses pd.isna and is backwards compatible * Update CHANGELOG
* User sign up * Remove is_redacted field; anonymize all non-public users by default * Ensure migrations use schema editor db alias * OICD SSO * Improved templates; bot protection * Updates to API docs for AI agents /me endpoint now used validating token * Handle missing settings * Reduce comment bloat * Add emails preferences to LabMember JSON * Change to release approach * pandas 3 fix for revisions in one_cache (#1044) * pandas 3 fix for revisions in one_cache In pandas 3 the revision column contains nans instead of empty strings which means the old check for truthiness always passes, resulting in #nan# in the relative path. This fix uses pd.isna and is backwards compatible * Update CHANGELOG * Fix Data Notice admin changeview * Move ec2_modify_groups into container
Remote code execution can occur via the django= / JSON REST filters. E.g. GET /sessions?django=x,[__import__('os').popen('id').read()]. Fix'd with test coverage.
The signup and email-change confirmations build their links from request.get_host() / build_absolute_uri. An attacker sending a Host: header for any *.eu-west-2.compute.amazonaws.com box they control passes host validation, so the victim's confirmation/verification link points at the attacker's host — capturing the token. Also hardened session cookie so it can't leak over an HTTP request. Now Django itself redirects to https, not just Apache
Traceback now logged to file and hidden from response context. Also status now actually 500 (was previously 200)
Four admin views were anonymously-accessible: /admin-tasks/status, /admin-actions/training, /admin-actions/subject-history, /admin-actions/water-history Four REST endpoints were anonymously-accessible: POST /register-file, POST|GET /sync-file-status, POST /new-download, GET /check-protected
Remove the coreapi-compatibility shim on /docs: the trip-wire test, SpectacularRedocViewCoreAPIDeprecation, and data/coreapi.json are gone. /docs now serves SpectacularRedocView directly regardless of Accept header. Closes #1055
* ea61382 (Signup #1057) inserted the SSO step between "Run tests" and its env: block, orphaning it. That left two env: keys on one step — a duplicate mapping key, which Actions rejects, so the workflow didn't run. * 62c4433 "Remove duplicate env block" merged them into one valid block. Correct as a dedup, but both blocks were already on the SSO step, so the merge left "Run tests" with nothing. The workflow became valid and finally ran — revealing the breakage. * PYTHONPATH: $HOME/builds/cortexlab/alyx — Actions does not expand $HOME in an env: block, so this is the literal string and points nowhere. Harmless, looks like a Travis leftover. * /var/log/alyx is created by sudo mkdir so it's root-owned 755; only the log file is 666. RotatingFileHandler needs to create files in that directory to roll at 4 MB, and --parallel has several processes writing the same file.
Previously an SSO signup would redirect to /me/preferences, which would lead to a 404 on non-public databases. Now it only redirects if email preferences are set (unlikely for institutional SSO)
Bumps [djangorestframework](https://github.com/encode/django-rest-framework) from 3.16.0 to 3.17.2. - [Release notes](https://github.com/encode/django-rest-framework/releases) - [Commits](encode/django-rest-framework@3.16.0...3.17.2) --- updated-dependencies: - dependency-name: djangorestframework dependency-version: 3.17.2 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
Bumps [pyjwt](https://github.com/jpadilla/pyjwt) from 2.13.0 to 2.15.0. - [Release notes](https://github.com/jpadilla/pyjwt/releases) - [Changelog](https://github.com/jpadilla/pyjwt/blob/master/CHANGELOG.rst) - [Commits](jpadilla/pyjwt@2.13.0...2.15.0) --- updated-dependencies: - dependency-name: pyjwt dependency-version: 2.15.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
Bumps [django](https://github.com/django/django) from 5.2.16 to 5.2.17. - [Commits](django/django@5.2.16...5.2.17) --- updated-dependencies: - dependency-name: django dependency-version: 5.2.17 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
Bumps [urllib3](https://github.com/urllib3/urllib3) from 2.7.0 to 2.8.0. - [Release notes](https://github.com/urllib3/urllib3/releases) - [Changelog](https://github.com/urllib3/urllib3/blob/main/CHANGES.rst) - [Commits](urllib3/urllib3@2.7.0...2.8.0) --- updated-dependencies: - dependency-name: urllib3 dependency-version: 2.8.0 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Added
PUBLIC_DATABASElab setting.Adds a sign-up page at
/signup, email confirmation of new accounts, and a password resetflow so that self-registered accounts are recoverable without an administrator
set_public_permissionsmanagement command, creating a 'Public users' group carrying viewpermissions only, and never over user accounts or the permission structure itself
Changed
/usersreturnsredacted users and the requester only, without email addresses; in the admin, the user and
group models are hidden and user filter dropdowns no longer enumerate every account
set_user_permissionsskips public users, which it previously added to the labmembers group and marked active - granting members of the public write access and activating
accounts that had never confirmed their email address
Removed
/docsendpoint.SpectacularRedocViewCoreAPIDeprecationanddata/coreapi.jsonare gone;/docsnow servesSpectacularRedocViewdirectly regardless ofthe request's
Acceptheader. #1055Fixed
returned a 500 status when it matched more than one subject; the lab is now used to resolve
duplicates - the
labfield of the request data,?lab=on/subjects/<nickname>and/water-requirement/<nickname>, orlabsand the repository's labs for/register-file.An unresolved duplicate returns a 400 status, or 409 for a lookup, naming the labs.
/subjects/<id>also accepts the subject UUID.is added with the same date, not only when the death date is first set. The subject's
protocol number is now updated when its water restrictions are ended.
every attached dataset had to be fetched and rendered as a selected option, which did not scale past a few hundred, and saving posted one form field per dataset, which exceeded
DATA_UPLOAD_MAX_NUMBER_FIELDSand failed with a 400 status. The datasets are now a read-only, scrollable list of the first 100, with the total count and a link to them in the dataset list. They can still be attached when creating a notice, or through the REST API.