Skip to content

chore: sync develop with main - #524

Merged
chodeus merged 1 commit into
developfrom
main
Aug 13, 2026
Merged

chore: sync develop with main#524
chodeus merged 1 commit into
developfrom
main

Conversation

@github-actions

Copy link
Copy Markdown
Contributor

@coderabbitai ignore

develop has drifted behind main (releases, fixes, dependency bumps). Do not merge this PR — it reports the drift, it does not fix it.

develop requires branches be up to date, and head:main can never satisfy that without pulling develop's extension files into main, which the branch invariant forbids. Squash or rebase would also leave main unreachable from develop, so this workflow would just open another PR next push.

Sync locally instead:

git checkout develop && git merge origin/main && git push

Then verify git diff main develop is added extension files plus deploy/docker/Dockerfile only. GitHub marks this PR merged on its own once develop contains main's tip. Opened by the sync-develop workflow.

…523)

* refactor(api): media_api queries move behind named interface methods

All 11 raw-SQL sites route through domain-named owners (12 new methods;
media_edit_history and poster_collections gain their owning interfaces),
restoring the DBWorker table allowlist these calls bypassed. Genuine-only
non-200 response docs ride along. path_safety.resolve_confined() gives path
confinement one documented owner (the recurring py/path-injection FP anchor)
and the regression-test import is single-style again.

* fix(codeql): normalize resolve_confined via os.path.realpath

py/path-injection models Path.resolve() as a filesystem sink, so the
confinement owner minted alert 312 itself; os.path.realpath is the same
normalization outside the sink model. Docstring to the one-line cap.
Alert 313: pass ChubConfig directly instead of a lambda wrapper.

* fix(review): collection key, id recovery, purge truth, deterministic pages

get_by_title_and_instance carries library_name (unique-key member; IS ?
matches the NULL-library row). create_collection returns its insert id so
the tag flow can't adopt a concurrent namesake's row. delete_by_ids chunks
at 500 and the purge route reports rows actually deleted. Shared
is_missing_value predicate owns the empty-field rule. find_low_rated,
find_incomplete_metadata and get_edit_history gain unique tiebreakers
(one metadata PUT writes several rows with one timestamp). find_by_tag
matches the quoted JSON element, not any substring. Chunk test reads the
build's real variable limit instead of assuming the compile default.
@chodeus
chodeus merged commit be3b9f4 into develop Aug 13, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant