Commit Graph
137 Commits
Author SHA1 Message Date
Brenda WallaceandClaude Sonnet 5 571405a840 Stop Rack::Attack depending on memcached, and cut the memcached timeout (#4800)
* Keep Rack::Attack counters in process memory

Rack::Attack was storing its request counters in Rails.cache, which is
memcached in production. On 2026-09-19, memcached calls were timing out
in the production logs. When that happens, the counters stop working.

In the same log window, one IP made 753 requests. 717 of them
succeeded. The 15 per minute throttle and the 500 per day ban did not
stop it.

Rack::Attack now uses its own in-memory store, capped at 8 MB. Each
Puma worker keeps its own counters, so the limits apply per worker.

Refs #1640

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* Add BLOCKED_IPS list to Rack::Attack

When one crawler overloads the site, we need a fast way to block it.
Rack::Attack now blocks every IP listed in the BLOCKED_IPS environment
variable. The list is comma separated.

Setting the variable does not need a code change. It also keeps IP
addresses out of the repository.

Refs #1640

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

* Lower the memcached socket timeout to 0.5 seconds

The production cache store waited up to 1.5 seconds for each memcached
call. Dalli's own default is 1 second. Dalli also retries after a
failure, so one bad cache call can block a Puma thread for longer than
the timeout.

On 2026-09-19, the production logs showed memcached timeouts every few
seconds. With only 5 threads per Puma worker, blocked threads make the
site slow. Slow requests hold memory for longer.

The timeout is now 0.5 seconds. A healthy memcached call takes a few
milliseconds. A call that takes 0.5 seconds has failed in practice, so the
request is better off skipping the cache.

Refs #1640

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>

---------

Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
2026-09-20 13:36:25 +09:30
Daniel O'Connorandgoogle-labs-jules[bot] 4dee371b34 Optimize CanCan abilities using declarative hash conditions (#4797)
Refactor block-based CanCan ability definitions for ScientificName, AlternateName, Planting, Activity, and Harvest into declarative hash conditions to eliminate per-record SQL queries and N+1 evaluation overhead.

Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
2026-09-19 18:19:00 +09:30
google-labs-jules[bot]andCloCkWeRX 9ebd98de2d Harden Rack::Attack and pagination against aggressive web crawlers
- Configure Allow2Ban in Rack::Attack to ban IPs requesting >500 pages per day for 1 week (7 days).
- Add honeypot route /dont-crawl-me disallowed in robots.txt and configure Fail2Ban in Rack::Attack to ban IPs visiting it for 7 days upon 1 hit.
- Update PhotosController#index to raise ActiveRecord::RecordNotFound when page parameter is out of bounds, returning 404 Not Found to crawlers instead of 200 OK.
- Add request and controller specs for Rack::Attack rules and pagination 404 responses.

Co-authored-by: CloCkWeRX <365751+CloCkWeRX@users.noreply.github.com>
2026-09-16 18:50:30 +12:00
Daniel O'Connor d103bdf23b Update throttle limit for restricted routes 2026-08-23 18:22:29 +09:30
4563df45d0 Upgrade to Rails 8.1 (#4685)
* Upgrade application to Rails 8.1

- Update rails gem to ~> 8.1.0
- Set config.load_defaults 8.1 in application.rb
- Add gem 'csv' for Ruby 3.4+ compatibility
- Replace deprecated 'render text:' with 'render plain:' in PagesController
- Add compatibility patch for jsonapi-resources routing in Rails 8.1
- Add compatibility patch for Faraday 2.x error constants
- Add Searchkick test stubs for environments without Elasticsearch
- Include required Active Storage update migrations

Co-authored-by: CloCkWeRX <365751+CloCkWeRX@users.noreply.github.com>

* Remove disabled searchkick

* Apply suggestion from @CloCkWeRX

* Delete config/initializers/faraday_patch.rb

* Apply suggestions from code review

Co-authored-by: Daniel O'Connor <daniel.oconnor@gmail.com>

* Remove modifications for tests without elasticsearch

* Remove psych gem and its dependencies

Removed psych gem version 5.4.0 and its dependencies.

---------

Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
2026-08-09 22:53:15 +09:30
Daniel O'Connor 67da779381 Block Semrush crawler in Rack Attack initializer
Added a blocklist entry for the Semrush crawler to prevent abusive requests.
2026-06-25 21:11:43 +09:30
Daniel O'Connor 555d5ddf15 Revert "Replace Sidekiq with Solid Queue (#4619)" (#4620)
This reverts commit 4659ac5464.
2026-05-04 18:15:17 +09:30
4659ac5464 Replace Sidekiq with Solid Queue (#4619)
* Replace Sidekiq with Solid Queue

This commit transitions the background job processing from Sidekiq to
Solid Queue.

Changes:
- Replaced `sidekiq` gem with `solid_queue` in Gemfile.
- Updated `development.rb` and `production.rb` to use `:solid_queue` as
  the queue adapter.
- Added Solid Queue database tables via a new migration.
- Configured Solid Queue in `config/queue.yml` and `config/recurring.yml`.
- Integrated Solid Queue supervisor as a Puma plugin in `config/puma.rb`.
- Removed separate worker process from `Procfile`.
- Removed Sidekiq-specific configuration files.
- Updated Gemfile.lock to support both `ruby` and `x86_64-linux` platforms.

Co-authored-by: CloCkWeRX <365751+CloCkWeRX@users.noreply.github.com>

* Fix regression in gemfiles

---------

Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
2026-05-03 15:29:03 +09:30
Daniel O'Connor 6ac438a07f Namespaces no longer supported in sidekiq 2026-05-02 06:35:23 +00:00
Daniel O'Connor 9abb0d02b9 Merge pull request #4581 from Growstuff/add-rack-attack-protection-3014929071908440304
Add Rack::Attack rate limiting and Fail2Ban protection
2026-04-27 13:23:17 +09:30
Daniel O'Connor d625eb2dbd Rubocop: Style/FrozenStringLiteralComment 2026-04-23 14:30:02 +00:00
Daniel O'Connor 04680b196a Rubocop 2025-09-20 10:15:41 +00:00
google-labs-jules[bot]andDaniel O'Connor 02db5b8130 Add API token generation, authentication, and CRUD for a number of the API resources (#4237)
* feat: Add API token generation and authentication

This commit introduces API token generation and authentication for write operations.

- Adds a section to the user's profile edit page to generate and display an API token.
- Reuses the `authentications` table to store the API token, avoiding the need for a database migration.
- Implements token-based authentication for the API using the `Authorization: Token token=...` header.
- Enables write operations for all API resources and ensures they are protected by the new authentication mechanism.
- Adds feature and request specs to test the new functionality.

* feat: Add API token generation and authentication

This commit introduces API token generation and authentication for write operations.

- Adds a section to the user's profile edit page to generate and display an API token.
- Reuses the `authentications` table to store the API token, avoiding the need for a database migration.
- Implements token-based authentication for the API using the `Authorization: Token token=...` header.
- Enables write operations for all API resources and ensures they are protected by the new authentication mechanism.
- Adds feature and request specs to test the new functionality.

* Mark as editable

* Refactor

* WIP - Authentication

* Implement more test coverage

* Split 401 and 403

* Before Create hooks

* Update harvest specs, defaulting to the first plant part - this may not be right

* Update coverage

* Update coverage

* Rubocop

* Rubocop

* Rubocop

* Fix coverage

* For now, mark photos immutable again

* Fix specs

* Fix specs

* Rubocop

* Fix specs

---------

Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
Co-authored-by: Daniel O'Connor <daniel.oconnor@gmail.com>
2025-09-10 19:50:06 +09:30
google-labs-jules[bot] 0b639d5940 Remove twitter authentication
This change removes the twitter authentication feature from the application.

It removes the `omniauth-twitter` gem and all related code from controllers, views, and tests. It also removes the twitter icon and environment variable settings.
2025-08-24 07:03:20 +00:00
Daniel O'Connor 6ae2de7e47 Merge pull request #4086 from Growstuff/mailboxer-translations
Mailboxer translations
2025-08-10 14:57:39 +09:30
Daniel O'Connor 81060cccf7 Ruby 3.2: Rubocop - Lint/* and Style/* (#3786)
* Rubocop - Layout/*
* Rubocop - Lint and Style
2024-07-13 15:38:37 +09:30
Daniel O'Connor 4f5c47ba58 Ruby 3.2: Rubocop - Layout/* (#3785)
* Rubocop - Layout/*

* Regenerate
2024-07-13 15:19:09 +09:30
Daniel O'Connor ad4a6e17e2 iCalendar feed of plantings (#3588)
* Register mime type

* Add rough first pass

* Index predictions, and add links

* Trailing space

* Fix implementation

* Fix names, make public

* Fix names, make public

* Fix

* Fix tyyos

* Add date

* If there are no predictions, keep growing

* Add a todo

* Fix factories

* Specs
2024-01-27 00:38:33 +10:30
Daniel O'Connor 235109ccee Fix deprecation 2024-01-07 01:57:19 +00:00
Daniel O'Connor 28d550d67f Drop test 2022-12-10 15:55:57 +10:30
Daniel O'Connor d3df63912c Typo 2022-11-07 23:56:37 +10:30
Daniel O'Connor b24b9f82e6 Rubocop - auto corrections 2022-11-06 16:34:36 +10:30
Brenda Wallace 60c74ddff3 Reconnecting stale flickr auth tokens 2021-01-05 19:46:07 +13:00
Brenda Wallace 9dbf8b7c8f New robocops 2020-08-26 12:36:58 +12:00
Brenda Wallace 59efe92648 Upgrade to rails 6 2020-08-26 12:36:58 +12:00
Brenda Wallace 048ec7791f Increase max records on jsonapi to 100 2020-06-01 14:02:34 +12:00
Awesome Code 8cd0628ba6 Auto corrected by following Lint Ruby Layout/EmptyLineAfterMagicComment 2020-04-16 13:59:48 +12:00
Awesome Code f570557ddb Auto corrected by following Lint Ruby Lint/RedundantCopEnableDirective 2020-04-16 13:59:32 +12:00
Awesome Code c764b0a28f Auto corrected by following Lint Ruby Lint/RedundantCopDisableDirective 2020-04-14 10:49:54 +12:00
codefactor-io 4ff95fbac9 [CodeFactor] Apply fixes 2020-01-21 22:26:08 +13:00
Brenda 7257b2ada1 Update with frozen literals 2020-01-10 16:50:52 +13:00
Brenda Wallace 04fd1a343a Rubocop update (#2334)
* Update rubocop config

* Rubocop update - for rubocop 0.77

* [CodeFactor] Apply fixes

* rubocop fixes

* [CodeFactor] Apply fixes to commit 2826c2e
2019-12-16 22:35:33 +13:00
Brenda Wallace be4a250c63 renamed files to please rubocop 2019-11-18 11:08:23 +13:00
Brenda Wallace 4f8830676e Swagger docs 2019-11-18 10:15:06 +13:00
Brenda Wallace c4b33db495 Mark read notifications as read after migrating to conversations 2019-08-11 15:50:36 +12:00
Brenda Wallace b3807100d1 fixes email sending 2019-08-10 11:47:45 +12:00
Brenda Wallace d91a5bf55f Rewriting messages functionality to use mail boxer 2019-07-20 19:43:29 +12:00
Brenda Wallace 26839acf01 Turn off message sending until errors are fixed 2019-07-20 13:21:26 +12:00
Brenda Wallace c50556221c TRying to get mailboxxer working 2019-07-11 22:28:51 +12:00
Brenda Wallace def17e020e New line at end of file 2019-07-08 21:28:39 +12:00
Brenda Wallace 05ed9de8b6 Add leaflet initializer 2019-07-08 20:51:14 +12:00
Brenda Wallace d89c8f0fbc Merge branch 'dev' into upgrade/rails-5-2 2019-01-03 12:31:37 +13:00
Brenda Wallace a76f5d3a22 More locations with production email addresses 2019-01-01 13:56:08 +13:00
Brenda Wallace a43c235423 Upgrade to Rails 5.2 2019-01-01 10:31:53 +13:00
Brenda Wallace 0330809e4b Re-enable rubocop cops 2018-12-30 15:17:22 +13:00
Brenda Wallace 3fec343f2c Rubocop for hash alignment 2018-12-30 15:13:59 +13:00
Brenda Wallace 276accc314 Merge remote-tracking branch 'upstream/dev' into upgrade/rails-5
Conflicts:
	Gemfile.lock
2018-12-30 13:02:02 +13:00
Brandon Baker 7b15ae319d corrects more inflections 2018-12-12 09:37:31 +13:00
Brandon Baker 2c0746073e removes extra empty line detected at block body end 2018-12-12 09:37:31 +13:00
Brandon Baker c0450477c6 adds plural form of words with māori origin 2018-12-12 09:37:31 +13:00