feat: place PDF artwork in print files, add card payment, count only failed logins
All checks were successful
Build and deploy / Validate source (push) Successful in 6s
Build and deploy / Integration suite on a real stack (push) Successful in 2m23s
Build and deploy / Secret scan and release gate (push) Successful in 5s
Build and deploy / Publish images and notify Portainer (push) Has been skipped

PDF artwork: a single-page PDF source is placed in the print file as a
vector form through pikepdf, never rasterised, using the CropBox and
inherited /Rotate the Site measured with pdf.js. Multi-page and protected
PDFs go to hand preparation. PyMuPDF was not used because of its AGPL
licence. Raster tests cover crop, page rotation, placement rotation and
mirroring, and fail when the rotation or crop handling is broken.

Card payment: Mercado Pago's Card Payment Brick on the Site when
MP_PUBLIC_KEY is set; the card becomes a one-time token in Mercado Pago's
secure fields. Each card attempt has its own idempotency key, and the intent
route refuses new attempts once a payment is approved or a card is in
review, so a quote cannot be charged twice. The Site CSP admits Mercado
Pago's origins only through PAYMENT_CSP_SOURCES, empty by default.

Logins: every attempt counts against the source address, only failures
against the account. Counting successful sign-ins let ordinary use lock an
operator out and made CI's final browser sign-in fail.

No new required settings; production behaviour is unchanged until the
provider credentials are configured. Verified with the full CI integration
sequence locally.

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
Cauê Faleiros
2026-09-24 13:14:56 -03:00
parent e3d5558198
commit 4c01e932c3
23 changed files with 703 additions and 64 deletions

View File

@@ -122,8 +122,13 @@ class PrintFileTests(unittest.TestCase):
fake_pdf = os.path.join(self.dir.name, 'art.pdf')
with open(fake_pdf, 'wb') as handle:
handle.write(b'%PDF-1.4\n%%EOF\n')
with self.assertRaisesRegex(Unsupported, 'not an image'):
with self.assertRaisesRegex(Unsupported, 'not a PDF'):
self.render(item([placement(0, 0, 20, 10)], [source(20, 10)], 10), [fake_pdf])
cdr = os.path.join(self.dir.name, 'art.cdr')
with open(cdr, 'wb') as handle:
handle.write(b'not artwork')
with self.assertRaisesRegex(Unsupported, 'not an image'):
self.render(item([placement(0, 0, 20, 10)], [source(20, 10)], 10), [cdr])
def test_long_layouts_scale_user_space_instead_of_splitting(self):
# 6 m is longer than a PDF page may be (about 5.08 m).
@@ -186,5 +191,107 @@ class PrintFileTests(unittest.TestCase):
self.assertEqual(sample(2, 2), (255, 255, 255))
class PdfSourceTests(unittest.TestCase):
"""A customer PDF is placed as a vector form, sized and turned like an image."""
def setUp(self):
self.dir = tempfile.TemporaryDirectory()
self.addCleanup(self.dir.cleanup)
def pdf(self, name, image=None, rotate=None, crop=None, pages=1, password=None):
import pikepdf
path = os.path.join(self.dir.name, name)
image = image or quadrants(80, 40)
image.save(path, 'PDF', resolution=72, save_all=pages > 1,
append_images=[image] * (pages - 1))
if rotate is not None or crop or password:
with pikepdf.open(path, allow_overwriting_input=True) as document:
if rotate is not None:
document.Root.Pages.Rotate = rotate # inherited, not on the page
if crop:
document.pages[0].obj.CropBox = pikepdf.Array(crop)
encryption = pikepdf.Encryption(owner=password, user=password) if password else None
document.save(path, encryption=encryption or False)
return path
def render(self, spec, paths):
out = io.BytesIO()
detail = render(spec, {i: (p, os.path.basename(p)) for i, p in enumerate(paths)}, out, 'test')
return out.getvalue(), detail
def test_pdf_page_is_a_vector_form_placed_per_copy(self):
path = self.pdf('sheet.pdf')
pdf, detail = self.render(item([placement(0, 0, 20, 10), placement(20, 0, 20, 10, copy=1)],
[source(20, 10, copies=2)], 10), [path])
self.assertTrue(pdf.startswith(b'%PDF-1.6'))
self.assertEqual(detail['vector_sources'], 1)
self.assertIsNone(detail['min_dpi'])
import pikepdf
with pikepdf.open(io.BytesIO(pdf)) as document:
page = document.pages[0]
forms = [x for x in page.Resources.XObject.values() if x.Subtype == '/Form']
self.assertEqual(len(forms), 1)
self.assertAlmostEqual(float(page.mediabox[2]), 57 * PT_PER_CM, places=2)
content = b''.join(s.read_bytes() for s in page.obj.Contents) if isinstance(page.obj.Contents, pikepdf.Array) else page.obj.Contents.read_bytes()
self.assertEqual(content.count(b'/Pdf0 Do'), 2)
def test_mixed_raster_and_pdf_sources(self):
png = os.path.join(self.dir.name, 'a.png')
quadrants(80, 40).save(png)
pdf_path = self.pdf('b.pdf')
spec = item([placement(0, 0, 20, 10), placement(0, 0, 20, 10, index=1)],
[source(20, 10), source(20, 10)], 10)
spec['production']['placements'][1]['x_cm'] = 25
pdf, detail = self.render(spec, [png, pdf_path])
self.assertEqual((detail['sources'], detail['vector_sources']), (2, 1))
self.assertEqual(detail['min_dpi'], round(80 / (20 / 2.54)))
def test_refuses_pdfs_it_cannot_place(self):
with self.assertRaisesRegex(Unsupported, '2 pages'):
self.render(item([placement(0, 0, 20, 10)], [source(20, 10)], 10), [self.pdf('two.pdf', pages=2)])
with self.assertRaisesRegex(Unsupported, 'password'):
self.render(item([placement(0, 0, 20, 10)], [source(20, 10)], 10),
[self.pdf('locked.pdf', password='secret')])
with self.assertRaisesRegex(Unsupported, 'proportions'):
self.render(item([placement(0, 0, 20, 20)], [source(20, 20)], 20), [self.pdf('square.pdf')])
@unittest.skipIf(fitz is None, 'PyMuPDF is not installed')
def test_drawn_pdf_matches_what_the_site_measured(self):
framed = Image.new('RGB', (100, 60), (255, 255, 255))
framed.paste(quadrants(80, 40), (10, 10))
cases = {
# (page /Rotate, placement rotation, mirrored) -> TL, TR, BL, BR as drawn
'plain': (self.pdf('plain.pdf'), 0, False, (RED, GREEN, BLUE, YELLOW)),
# CropBox trims the white frame, exactly as pdf.js shows the page.
'cropped': (self.pdf('crop.pdf', image=framed, crop=[10, 10, 90, 50]), 0, False,
(RED, GREEN, BLUE, YELLOW)),
# An inherited /Rotate 90 is displayed turned clockwise.
'rotated page': (self.pdf('rot.pdf', rotate=90), 0, False, (BLUE, RED, YELLOW, GREEN)),
'placement turn': (self.pdf('turn.pdf'), 90, False, (BLUE, RED, YELLOW, GREEN)),
'mirrored': (self.pdf('mirror.pdf'), 0, True, (GREEN, RED, YELLOW, BLUE)),
}
for label, (path, turn, mirrored, expected) in cases.items():
displayed_portrait = label == 'rotated page'
portrait = displayed_portrait != (turn == 90)
width, length = (10, 20) if portrait else (20, 10)
src = (10, 20) if displayed_portrait else (20, 10)
spec = item([placement(12, 5, width, length, turn, mirrored)],
[source(*src, rotation=0, mirrored=mirrored)], 30)
pdf, _ = self.render(spec, [path])
page = fitz.open(stream=pdf, filetype='pdf')[0]
dpi = 40
pixmap = page.get_pixmap(dpi=dpi, alpha=False)
def sample(x_cm, y_cm):
return pixmap.pixel(int(x_cm / 2.54 * dpi), int(y_cm / 2.54 * dpi))
got = (sample(12 + width * .25, 5 + length * .25), sample(12 + width * .75, 5 + length * .25),
sample(12 + width * .25, 5 + length * .75), sample(12 + width * .75, 5 + length * .75))
for actual, wanted in zip(got, expected):
self.assertTrue(all(abs(a - w) < 40 for a, w in zip(actual, wanted)),
f'{label}: {got} != {expected}')
self.assertEqual(sample(2, 2), (255, 255, 255), label)
if __name__ == '__main__':
unittest.main()