mirror of
https://github.com/Studio-Saelix/sencho.git
synced 2026-09-04 06:35:29 +00:00
feat: ordered multi-file Compose for Git sources (#1380)
* feat: ordered multi-file Compose for Git sources
Extend Git sources to deploy an ordered list of compose files merged with
docker compose -f base.yaml -f override.yaml ..., plus an optional project
directory.
- Pick and reorder compose files from the repository tree (drag to reorder on
desktop, up/down arrows on phones); manual path entry is also supported.
- The ordered set drives every stack-scoped compose command (deploy, update,
start/stop/restart/down, image scans, Compose Doctor) and the container
lookup, so a service or image declared only in an override is handled too.
- Runtime keys off the materialized set, not the saved configuration: saving a
source does not change deploy args until the pull is applied, and apply
materializes from the pending snapshot rather than live config.
- The project directory is passed as --project-directory, with -p <stack>
pinning the Compose project so container labels stay stable.
- The Mesh override is layered last; single-file sources are byte-identical to
before, and existing rows keep working via the single-path fallback.
Docs cover the picker, ordering, project directory, and the new troubleshooting
and limitations (referenced files are not materialized; the dependency graph,
drift, and networking views read the primary file).
* fix: harden multi-file Git source (hash, unlink, collisions, node id)
- hashContent folds ordered file CONTENTS (not paths) so a clean multi-file
stack is not flagged as locally edited: create/apply hash the fetched files
(repo paths) while pull hashes the on-disk files (materialized paths), which
previously disagreed and showed a false "local edits detected".
- Block unlinking a multi-file or project-directory Git source (409): the deploy
spec lives on the source row, so removing it would silently revert deploys to
root compose.yaml. Single-file sources still unlink.
- Reject materialized-path collisions in the selection validator: an additional
file equal to or nested under compose.yaml, an ancestor/descendant overlap
between selected files, and a project directory nested under a compose file
(previously a 500 at materialization).
- DockerController.getContainersByStack uses the controller's node compose dir
and passes its node id to the authored prefix, instead of the process default.
* fix: CI failures on multi-file Git source (test crash, aria query, path barrier)
- GitSourceFields no longer crashes when repoUrl/branch are falsy: the canBrowse
trim() is optional-chained, so a reusable field component tolerates partial
props. Fixes the apply-binding panel test, which feeds a minimal source object.
- GitSourcePanel tests query the footer Remove button by its exact name, so the
picker's per-file "Remove <path>" buttons no longer collide with the broad
/remove/i match (the test intent, footer Remove present/absent, is unchanged).
- validateCompose uses an inline resolve + startsWith barrier at the context-dir
mkdir sink (CodeQL does not credit the wrapped isPathWithinBase helper),
clearing the js/path-injection alert. The containment check is equivalent and
contextDir is also validated upstream.
* test: update Git source E2E spec for the multi-file compose picker
The compose-file picker replaced the single #git-source-path input and added
per-file Remove buttons, so the E2E spec drove selectors that no longer exist:
- Drop the redundant compose.yaml fills (the picker defaults to compose.yaml).
- Select the footer Remove button by exact name so the picker's per-file
"Remove <path>" buttons no longer make the locator ambiguous.
- Set a custom compose path through the picker (add via the manual input, press
Enter, then remove the default compose.yaml).
* test: match the footer Remove button with an exact Playwright name
Playwright's getByRole name option is a substring match by default, so
{ name: 'Remove' } also matched the picker's "Remove <path>" buttons. Require an
exact match so only the footer Remove button is selected.
This commit is contained in:
@@ -26,6 +26,8 @@ function seedGitSource(stackName: string): void {
|
||||
repo_url: 'https://github.com/example/repo.git',
|
||||
branch: 'main',
|
||||
compose_path: 'compose.yaml',
|
||||
compose_paths: ['compose.yaml'],
|
||||
context_dir: null,
|
||||
sync_env: false,
|
||||
env_path: null,
|
||||
auth_type: 'none',
|
||||
@@ -132,7 +134,7 @@ describe('PUT /api/stacks/:stackName/git-source — max-length caps', () => {
|
||||
compose_path: 'c'.repeat(1100),
|
||||
});
|
||||
expect(res.status).toBe(400);
|
||||
expect(res.body.error).toMatch(/compose_path/i);
|
||||
expect(res.body.error).toMatch(/compose path/i);
|
||||
});
|
||||
|
||||
it('rejects oversized env_path', async () => {
|
||||
@@ -191,7 +193,7 @@ describe('git-source routes — repository path validation', () => {
|
||||
auth_type: 'none',
|
||||
});
|
||||
expect(res.status).toBe(400);
|
||||
expect(res.body.error).toMatch(/compose_path/i);
|
||||
expect(res.body.error).toMatch(/compose path/i);
|
||||
});
|
||||
|
||||
it('rejects absolute env_path on create-from-git', async () => {
|
||||
@@ -288,6 +290,97 @@ describe('GET /api/stacks/:stackName/git-source', () => {
|
||||
});
|
||||
});
|
||||
|
||||
describe('PUT /api/stacks/:stackName/git-source: multi-file selection', () => {
|
||||
// The success-path tests forward a parsed selection to upsert(), whose dry-run
|
||||
// fetch would clone a real repo. Stub upsert so the assertion stays at the
|
||||
// route layer (parse + forward) without network. Rejection-path tests hit the
|
||||
// parseComposeSelection 400 before upsert is ever reached, so they need no stub.
|
||||
it('persists a compose_paths array and forwards it to the service', async () => {
|
||||
const upsertSpy = vi.spyOn(GitSourceService.getInstance(), 'upsert')
|
||||
.mockResolvedValue({} as Awaited<ReturnType<typeof GitSourceService.prototype.upsert>>);
|
||||
const res = await request(app)
|
||||
.put('/api/stacks/existing-stack/git-source')
|
||||
.set('Authorization', `Bearer ${adminToken()}`)
|
||||
.send({
|
||||
repo_url: 'https://github.com/example/repo.git',
|
||||
branch: 'main',
|
||||
compose_paths: ['infra/base.yml', 'infra/prod.yml'],
|
||||
context_dir: 'app',
|
||||
auth_type: 'none',
|
||||
});
|
||||
expect(res.status).toBe(200);
|
||||
expect(upsertSpy).toHaveBeenCalledWith(expect.objectContaining({
|
||||
composePaths: ['infra/base.yml', 'infra/prod.yml'],
|
||||
contextDir: 'app',
|
||||
}));
|
||||
upsertSpy.mockRestore();
|
||||
});
|
||||
|
||||
it('still accepts the legacy compose_path string and maps it to a one-element array', async () => {
|
||||
const upsertSpy = vi.spyOn(GitSourceService.getInstance(), 'upsert')
|
||||
.mockResolvedValue({} as Awaited<ReturnType<typeof GitSourceService.prototype.upsert>>);
|
||||
const res = await request(app)
|
||||
.put('/api/stacks/existing-stack/git-source')
|
||||
.set('Authorization', `Bearer ${adminToken()}`)
|
||||
.send({
|
||||
repo_url: 'https://github.com/example/repo.git',
|
||||
branch: 'main',
|
||||
compose_path: 'stacks/web/compose.yaml',
|
||||
auth_type: 'none',
|
||||
});
|
||||
expect(res.status).toBe(200);
|
||||
expect(upsertSpy).toHaveBeenCalledWith(expect.objectContaining({
|
||||
composePaths: ['stacks/web/compose.yaml'],
|
||||
contextDir: null,
|
||||
}));
|
||||
upsertSpy.mockRestore();
|
||||
});
|
||||
|
||||
it('rejects a compose_paths array with more than 10 files (400)', async () => {
|
||||
const tooMany = Array.from({ length: 11 }, (_, i) => `f${i}.yml`);
|
||||
const res = await request(app)
|
||||
.put('/api/stacks/existing-stack/git-source')
|
||||
.set('Authorization', `Bearer ${adminToken()}`)
|
||||
.send({
|
||||
repo_url: 'https://github.com/example/repo.git',
|
||||
branch: 'main',
|
||||
compose_paths: tooMany,
|
||||
auth_type: 'none',
|
||||
});
|
||||
expect(res.status).toBe(400);
|
||||
expect(res.body.error).toMatch(/exceed/i);
|
||||
});
|
||||
|
||||
it('rejects duplicate entries in compose_paths (400)', async () => {
|
||||
const res = await request(app)
|
||||
.put('/api/stacks/existing-stack/git-source')
|
||||
.set('Authorization', `Bearer ${adminToken()}`)
|
||||
.send({
|
||||
repo_url: 'https://github.com/example/repo.git',
|
||||
branch: 'main',
|
||||
compose_paths: ['compose.yaml', 'infra/prod.yml', 'infra/prod.yml'],
|
||||
auth_type: 'none',
|
||||
});
|
||||
expect(res.status).toBe(400);
|
||||
expect(res.body.error).toMatch(/duplicate/i);
|
||||
});
|
||||
|
||||
it('rejects a context_dir that collides with the primary compose.yaml (400)', async () => {
|
||||
const res = await request(app)
|
||||
.put('/api/stacks/existing-stack/git-source')
|
||||
.set('Authorization', `Bearer ${adminToken()}`)
|
||||
.send({
|
||||
repo_url: 'https://github.com/example/repo.git',
|
||||
branch: 'main',
|
||||
compose_paths: ['compose.yaml'],
|
||||
context_dir: 'compose.yaml',
|
||||
auth_type: 'none',
|
||||
});
|
||||
expect(res.status).toBe(400);
|
||||
expect(res.body.error).toMatch(/context_dir/i);
|
||||
});
|
||||
});
|
||||
|
||||
describe('POST /api/stacks/from-git', () => {
|
||||
const validBody = {
|
||||
stack_name: 'route-from-git',
|
||||
@@ -399,6 +492,38 @@ describe('POST /api/stacks/:stackName/git-source/webhook-pull status codes', ()
|
||||
});
|
||||
});
|
||||
|
||||
describe('DELETE /api/stacks/:stackName/git-source — multi-file unlink guard', () => {
|
||||
it('blocks unlinking a multi-file source with 409 and keeps the row', async () => {
|
||||
seedGitSource('mf-unlink');
|
||||
DatabaseService.getInstance().setGitSourceAppliedSpec('mf-unlink', { files: ['compose.yaml', 'infra/prod.yml'], contextDir: null });
|
||||
const res = await request(app)
|
||||
.delete('/api/stacks/mf-unlink/git-source')
|
||||
.set('Authorization', `Bearer ${adminToken()}`);
|
||||
expect(res.status).toBe(409);
|
||||
expect(res.body.error).toMatch(/multiple compose files/i);
|
||||
expect(DatabaseService.getInstance().getGitSource('mf-unlink')).toBeTruthy();
|
||||
});
|
||||
|
||||
it('blocks unlinking a context-dir source with 409', async () => {
|
||||
seedGitSource('ctx-unlink');
|
||||
DatabaseService.getInstance().setGitSourceAppliedSpec('ctx-unlink', { files: ['compose.yaml'], contextDir: 'app' });
|
||||
const res = await request(app)
|
||||
.delete('/api/stacks/ctx-unlink/git-source')
|
||||
.set('Authorization', `Bearer ${adminToken()}`);
|
||||
expect(res.status).toBe(409);
|
||||
expect(DatabaseService.getInstance().getGitSource('ctx-unlink')).toBeTruthy();
|
||||
});
|
||||
|
||||
it('allows unlinking a single-file source', async () => {
|
||||
seedGitSource('sf-unlink');
|
||||
const res = await request(app)
|
||||
.delete('/api/stacks/sf-unlink/git-source')
|
||||
.set('Authorization', `Bearer ${adminToken()}`);
|
||||
expect(res.status).toBe(200);
|
||||
expect(DatabaseService.getInstance().getGitSource('sf-unlink')).toBeUndefined();
|
||||
});
|
||||
});
|
||||
|
||||
describe('GET /api/git-sources', () => {
|
||||
it('returns 200 and a JSON array for an authenticated admin', async () => {
|
||||
const res = await request(app)
|
||||
|
||||
Reference in New Issue
Block a user