fix: harden week-two ordering, artwork and operations
This commit is contained in:
@@ -21,6 +21,7 @@ WORKDIR /app
|
||||
COPY infra/requirements.txt infra/requirements.lock /app/infra/
|
||||
RUN python -m pip install --no-cache-dir --require-hashes -r infra/requirements.lock
|
||||
COPY app /app/app
|
||||
COPY ops /app/ops
|
||||
RUN useradd --uid 10001 --create-home --shell /usr/sbin/nologin dtf
|
||||
USER 10001:10001
|
||||
ENV PYTHONDONTWRITEBYTECODE=1 PYTHONUNBUFFERED=1 PYTHONPATH=/app
|
||||
|
||||
@@ -176,6 +176,8 @@ def config_errors(values):
|
||||
errors.append('OWNER_UPLOAD_QUOTA_BYTES cannot exceed STORAGE_QUOTA_BYTES')
|
||||
if numeric.get('SCAN_MAX_BYTES', 0) > numeric.get('MAX_UPLOAD_BYTES', 0):
|
||||
errors.append('SCAN_MAX_BYTES cannot exceed MAX_UPLOAD_BYTES')
|
||||
if numeric.get('SCAN_MAX_BYTES', 0) > 128 * 1024 * 1024:
|
||||
errors.append('SCAN_MAX_BYTES cannot exceed the configured ClamAV 128 MiB stream limit')
|
||||
ports = {}
|
||||
for name in ('SITE_PORT', 'KANBAN_PORT'):
|
||||
try:
|
||||
|
||||
@@ -112,6 +112,7 @@ class ProductionPreflightTests(unittest.TestCase):
|
||||
self.assertTrue(any('distinct external Swarm secret' in error for error in errors))
|
||||
self.assertIn('OWNER_UPLOAD_QUOTA_BYTES cannot exceed STORAGE_QUOTA_BYTES', errors)
|
||||
self.assertIn('SCAN_MAX_BYTES cannot exceed MAX_UPLOAD_BYTES', errors)
|
||||
self.assertTrue(any('configured ClamAV 128 MiB stream limit' in error for error in errors))
|
||||
|
||||
|
||||
if __name__ == '__main__':
|
||||
|
||||
Reference in New Issue
Block a user