* Keep Rack::Attack counters in process memory
Rack::Attack was storing its request counters in Rails.cache, which is
memcached in production. On 2026-09-19, memcached calls were timing out
in the production logs. When that happens, the counters stop working.
In the same log window, one IP made 753 requests. 717 of them
succeeded. The 15 per minute throttle and the 500 per day ban did not
stop it.
Rack::Attack now uses its own in-memory store, capped at 8 MB. Each
Puma worker keeps its own counters, so the limits apply per worker.
Refs #1640
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Add BLOCKED_IPS list to Rack::Attack
When one crawler overloads the site, we need a fast way to block it.
Rack::Attack now blocks every IP listed in the BLOCKED_IPS environment
variable. The list is comma separated.
Setting the variable does not need a code change. It also keeps IP
addresses out of the repository.
Refs #1640
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
* Lower the memcached socket timeout to 0.5 seconds
The production cache store waited up to 1.5 seconds for each memcached
call. Dalli's own default is 1 second. Dalli also retries after a
failure, so one bad cache call can block a Puma thread for longer than
the timeout.
On 2026-09-19, the production logs showed memcached timeouts every few
seconds. With only 5 threads per Puma worker, blocked threads make the
site slow. Slow requests hold memory for longer.
The timeout is now 0.5 seconds. A healthy memcached call takes a few
milliseconds. A call that takes 0.5 seconds has failed in practice, so the
request is better off skipping the cache.
Refs #1640
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Sonnet 5 <noreply@anthropic.com>
- Configure Allow2Ban in Rack::Attack to ban IPs requesting >500 pages per day for 1 week (7 days).
- Add honeypot route /dont-crawl-me disallowed in robots.txt and configure Fail2Ban in Rack::Attack to ban IPs visiting it for 7 days upon 1 hit.
- Update PhotosController#index to raise ActiveRecord::RecordNotFound when page parameter is out of bounds, returning 404 Not Found to crawlers instead of 200 OK.
- Add request and controller specs for Rack::Attack rules and pagination 404 responses.
Co-authored-by: CloCkWeRX <365751+CloCkWeRX@users.noreply.github.com>
* Upgrade application to Rails 8.1
- Update rails gem to ~> 8.1.0
- Set config.load_defaults 8.1 in application.rb
- Add gem 'csv' for Ruby 3.4+ compatibility
- Replace deprecated 'render text:' with 'render plain:' in PagesController
- Add compatibility patch for jsonapi-resources routing in Rails 8.1
- Add compatibility patch for Faraday 2.x error constants
- Add Searchkick test stubs for environments without Elasticsearch
- Include required Active Storage update migrations
Co-authored-by: CloCkWeRX <365751+CloCkWeRX@users.noreply.github.com>
* Remove disabled searchkick
* Apply suggestion from @CloCkWeRX
* Delete config/initializers/faraday_patch.rb
* Apply suggestions from code review
Co-authored-by: Daniel O'Connor <daniel.oconnor@gmail.com>
* Remove modifications for tests without elasticsearch
* Remove psych gem and its dependencies
Removed psych gem version 5.4.0 and its dependencies.
---------
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
* Replace Sidekiq with Solid Queue
This commit transitions the background job processing from Sidekiq to
Solid Queue.
Changes:
- Replaced `sidekiq` gem with `solid_queue` in Gemfile.
- Updated `development.rb` and `production.rb` to use `:solid_queue` as
the queue adapter.
- Added Solid Queue database tables via a new migration.
- Configured Solid Queue in `config/queue.yml` and `config/recurring.yml`.
- Integrated Solid Queue supervisor as a Puma plugin in `config/puma.rb`.
- Removed separate worker process from `Procfile`.
- Removed Sidekiq-specific configuration files.
- Updated Gemfile.lock to support both `ruby` and `x86_64-linux` platforms.
Co-authored-by: CloCkWeRX <365751+CloCkWeRX@users.noreply.github.com>
* Fix regression in gemfiles
---------
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
* feat: Add API token generation and authentication
This commit introduces API token generation and authentication for write operations.
- Adds a section to the user's profile edit page to generate and display an API token.
- Reuses the `authentications` table to store the API token, avoiding the need for a database migration.
- Implements token-based authentication for the API using the `Authorization: Token token=...` header.
- Enables write operations for all API resources and ensures they are protected by the new authentication mechanism.
- Adds feature and request specs to test the new functionality.
* feat: Add API token generation and authentication
This commit introduces API token generation and authentication for write operations.
- Adds a section to the user's profile edit page to generate and display an API token.
- Reuses the `authentications` table to store the API token, avoiding the need for a database migration.
- Implements token-based authentication for the API using the `Authorization: Token token=...` header.
- Enables write operations for all API resources and ensures they are protected by the new authentication mechanism.
- Adds feature and request specs to test the new functionality.
* Mark as editable
* Refactor
* WIP - Authentication
* Implement more test coverage
* Split 401 and 403
* Before Create hooks
* Update harvest specs, defaulting to the first plant part - this may not be right
* Update coverage
* Update coverage
* Rubocop
* Rubocop
* Rubocop
* Fix coverage
* For now, mark photos immutable again
* Fix specs
* Fix specs
* Rubocop
* Fix specs
---------
Co-authored-by: google-labs-jules[bot] <161369871+google-labs-jules[bot]@users.noreply.github.com>
Co-authored-by: Daniel O'Connor <daniel.oconnor@gmail.com>
This change removes the twitter authentication feature from the application.
It removes the `omniauth-twitter` gem and all related code from controllers, views, and tests. It also removes the twitter icon and environment variable settings.
* Register mime type
* Add rough first pass
* Index predictions, and add links
* Trailing space
* Fix implementation
* Fix names, make public
* Fix names, make public
* Fix
* Fix tyyos
* Add date
* If there are no predictions, keep growing
* Add a todo
* Fix factories
* Specs