Quentin BEY
3379d6d499
🔧 (git) set LF line endings for all text files
...
Windows users are by default using CRLF line endings,
which can cause issues with some tools and
environments. This commit sets the `.gitattributes`
file to enforce LF line endings for all text
files in the repository.
Based on the same commit on docs
2025-06-21 00:15:16 +02:00
Quentin BEY
213656fc2e
🧑💻 (docker) split frontend to another file
...
This commit aims at improving the user experience:
- Use a dedicated `Dockerfile` for the frontend
- Run the backend and frontend in "watch"/dev mode in Docker
- Do not start all Docker instances for small tasks
2025-06-21 00:15:16 +02:00
Quentin BEY
4dfd682cb6
✨ (resource-server) add SCIM /Me endpoint
...
This provide a "self-care" SCIM endpoint, authenticated with OIDC token
introspection. This endpoint will be use by services to fetch the user's
team list.
We chose to use the SCIM format (even if this is not a SCIM context) to
make it easier to understand/maintain/plug.
2025-06-21 00:15:16 +02:00
Quentin BEY and Marie
95f63fa56d
🔒 ️(frontend) hide Nginx server version in error responses
...
Remove version disclosure in /assets/ error pages identified by security
auditor to prevent information leakage vulnerability.
2025-06-05 19:27:24 +02:00
Quentin BEY
8fed2606d6
🧑💻 (frontend) add makefile lint --fix
...
Add a Makefile command to easily run the automatic fixup for frontend
files.
2025-05-20 15:00:14 +02:00
Quentin BEY
8e85f303ec
🌐 (frontend) update some translated messages
...
Slight cleanup of translations.
2025-05-16 11:55:32 +02:00
Quentin BEY
ee564ff6ba
🎨 (front) fix mail domain list display
...
The first implementation was using `div` instead of the proper
components.
2025-05-16 11:55:32 +02:00
Quentin BEY
fe9fb67fed
🔒 ️(docker) patch libxml to address CVE
...
Trivy scan detects some issue:
┌─────────┬────────────────┬──────────┬────────┬───────────────────┬───────────────┬───────────────────────────────────────────────────────────┐
│ Library │ Vulnerability │ Severity │ Status │ Installed Version │ Fixed Version │ Title │
├─────────┼────────────────┼──────────┼────────┼───────────────────┼───────────────┼───────────────────────────────────────────────────────────┤
│ libxml2 │ CVE-2025-32414 │ HIGH │ fixed │ 2.13.4-r5 │ 2.13.4-r6 │ libxml2: Out-of-Bounds Read in libxml2 │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2025-32414 │
│ ├────────────────┤ │ │ │ ├───────────────────────────────────────────────────────────┤
│ │ CVE-2025-32415 │ │ │ │ │ libxml2: Out-of-bounds Read in xmlSchemaIDCFillNodeTables │
│ │ │ │ │ │ │ https://avd.aquasec.com/nvd/cve-2025-32415 │
└─────────┴────────────────┴──────────┴────────┴───────────────────┴───────────────┴───────────────────────────────────────────────────────────┘
2025-05-16 10:03:52 +02:00
Quentin BEY
91fbef9066
🎨 (front) rewrite the team main page
...
The first rewrite I made was using `div` instead of the proper
components.
2025-05-14 18:46:49 +02:00
Quentin BEY
4f3c9abe62
🐛 (front) improve domain "return" button
...
The button to return to domain list was reloading the whole page which
was quite long (and somehow failing on staging).
2025-05-14 17:57:29 +02:00
Quentin BEY
bd43e4620d
💄 (teams) update team list page to match new UI
...
This is an attempt to quick fix the team page to match the new UI.
2025-05-14 17:57:29 +02:00
Quentin BEY
8c67d4a004
✅ (e2e) add mailboxe (dis/en)able check
...
This provides a new test to check the action on the mailbox item.
For now we can only enable or disable a mailbox.
We need to create the mailbox in the test, so it exists on Dimail side.
2025-05-14 17:46:26 +02:00
Quentin BEY
78cb3e693c
💚 (e2e) remove useless test on "tabs"
...
This is supposed to be a validation test on accessibility but in fact
it's just a flaky test which does not provide any information. We need
to replace this with something smarter.
2025-05-14 17:46:26 +02:00
Quentin BEY
cec8e87edd
🐛 (front-mail) dynamically display org name
...
The organization is not always DINUM.
2025-05-14 17:46:26 +02:00
Quentin BEY
35a700d522
💄 (cunningham) fix style for display
...
Some CSS were not found (like color gold-500).
2025-05-14 17:46:26 +02:00
Quentin BEY
c786ddbb82
🐛 (frontend) re-enable mailbox actions
...
This code was commented but seems to work properly.
2025-05-14 17:46:26 +02:00
Quentin BEY
cb198a9d04
💩 (frontend) restore user name / org header
...
This was added previously and while the organization is not displayed
elsewhere it's better to keep the information displayed somewhere.
2025-05-14 17:43:37 +02:00
Quentin BEY
3d9645b561
⚰️ (i18n) utils module is not used anymore
...
The use of this module has been removed during the UI refacto.
2025-05-14 17:43:37 +02:00
Quentin BEY
21cbeded18
✅ (frontend) fix end-to-end tests after refacto
...
Some test were broken other were flaky: fix them.
All tests are not worthy but since it was easy to fix, we keep them
until we write better tests...
2025-05-14 17:43:37 +02:00
Quentin BEY
f0c609ef0b
🐛 (frontend) fix create team button
...
The button to create a new team was not displayed properly anymore.
2025-05-14 17:43:37 +02:00
Quentin BEY
aa3d90b686
🐛 (frontend) fix browser language detection
...
The `Default language` E2E test detected the browser language was not
automatically detected when user does not have any cookie, it was always
falling back on the defaut language (en).
2025-05-14 17:43:37 +02:00
Quentin BEY
4a08a9ec92
⚰️ (front) remove unused code after UI v2
...
The linter was unhappy, so I removed the unused variables or code.
2025-05-14 17:43:37 +02:00
Quentin BEY
5544a40f5f
🎨 (front) fix linter issues with --fix
...
Simply run the lint command with "autofix" to format files.
2025-05-14 17:43:37 +02:00
Quentin BEY
889291c7f3
🔒 ️(drf) disable browsable HTML API renderer
...
The `BrowsableAPIRenderer` generates a form to test POST/PUT/... actions
and fill the FK fields with unfiltered data. This issue has been spoted
on visio and fixed https://github.com/suitenumerique/meet/pull/508
2025-04-30 15:58:21 +02:00
Quentin BEY
a8d20bacb0
⚡ ️(back) use redis as session backend in dev
...
We want to persist the session during development. Otherwise the session
is reset everytime the server is restart. This behavior make developing
bot a front and back feature a nigthmare, we spend our time login again
and again.
Shamelessly copy/pasted from @lunika 's work
suitenumerique/docs@007854a
2025-04-30 15:11:40 +02:00
Quentin BEY
0a241f0e03
🔧 (sentry) add Celery beat task integration
...
This should provide "cron" monitoring in Sentry.
2025-04-28 15:51:34 +02:00
Quentin BEY
6721328b2d
⬆️ (django-lasuite) bump version to v0.0.7
...
This fixes the userinfo OIDC endpoint format autodetection.
2025-04-23 10:23:09 +02:00
Quentin BEY
ab5d8c74d8
✅ (e2e) fix keycloak user email address
...
Django >= 5.2 add a verification on email address
2025-04-22 17:59:55 +02:00
Quentin BEY
4c14f967b6
✅ (backend) fix test after dependencies update
...
The queries needs update to manage save/release in database, this should
be improved, but considered ok for now.
2025-04-22 17:59:55 +02:00
Quentin BEY
0220875c70
⬆️ (django-lasuite) bump to version 0.0.5
...
Bump the lib to the latest version:
- update the post_get_or_create_user method signature
- allow silent login for OIDC (will require frontend implementation)
2025-04-10 15:00:03 +02:00
Quentin BEY
140d099fce
⬆️ (backend) bump django-lasuite to v0.0.2
...
This will allow the introspected token to not contain the `iss` claim.
2025-04-07 13:55:19 +02:00
Quentin BEY
e2d362bc77
➕ (backend) add django-lasuite dependency
...
Use the OIDC backends from the new library.
2025-04-04 09:57:12 +02:00
Quentin BEY and Sabrina Demagny
a009f3ccb7
🐛 (plugin) allow simple application name
...
This allows to use the application name, instead of the full path to the
application configuration in the INSTALLED_PLUGINS setting.
2025-04-03 15:17:53 +02:00
Quentin BEY
3a044e6b02
📝 (helm) update missing documentation
...
Seems like the readme was not updated after adding the celery beat
worker configuration.
2025-04-03 10:33:47 +02:00
Quentin BEY
7c569a3ca3
🧱 (helm) disable createsuperuser job by setting
...
This provides the way to disable the admin user creation at each
deployment. In production we don't want to persist a generic admin user:
it should be created once, at first deployment then replaced by
nominative accounts.
2025-04-03 10:33:23 +02:00
Quentin BEY
e23d236614
✅ (pytest) fail on tests external calls
...
The backend tests must not try to call the real world.
2025-04-03 09:39:15 +02:00
Quentin BEY and BEY Quentin
1eb9dffa48
🐛 (contacts) add missing select_related
...
The new DRF version (3.16.0) adds a check on unique together and needs
more fields to be loaded. To prevent an extra query, we select the owner
value in the DB query.
2025-04-01 10:58:49 +02:00
Quentin BEY and BEY Quentin
dd43483ce6
🔒 ️(passwords) add validators for production
...
This enabled various password validators to enforce password complexity.
2025-03-28 15:43:45 +01:00
Quentin BEY
fbe3aa54d0
🐛 (ci) use sha256 to sign argocd webhook call
...
The argocd webhook call needs now to use sha256 digest now to sign
Copy from docs project commit by @lunika
2025-03-28 11:09:04 +01:00
Quentin BEY and Sabrina Demagny
28fdee868d
♻️ (plugins) rewrite plugin system as django app
...
This allow more flexibility around the installed plugins, this will
allow to add models in plugins if needed.
2025-03-26 19:56:23 +01:00
Quentin BEY and Sabrina Demagny
4ced342062
♻️ (core) move app ready code to functions
...
For readability, we move the code block from the `ready` method to a
dedicated function.
This will allow to add more things to do in the `ready` with more focus.
2025-03-26 19:56:23 +01:00
Quentin BEY and BEY Quentin
6b2ca88ff2
✨ (oidc) add simple introspection backend
...
This provides a configurable OIDC introspection backend to be able to
call introspection endpoints which returns JSON data instead of an
encrypted JWT.
Two backends are currently defined:
- ResourceServerBackend` which expect a JSON response
- JWTResourceServerBackend which implements RFC 9701 and expects
JWE reponse.
There might be other cases (eg: ResourceServerBackend with JWT, JWS or
JWE, etc. but for now we don't use it, so we follow YAGNI).
This also allow to configure the claim to determine the "audience":
- client_id: for our Keycloak implementation
- aud: used by ProConnect
2025-03-20 09:30:18 +01:00
Quentin BEY and BEY Quentin
b771f614e2
🧑💻 (tilt) setup resource server with kc
...
This configures the settings to be able to call people as a resource
server when using Keycloak deployment.
2025-03-20 09:30:18 +01:00
Quentin BEY and BEY Quentin
1ec98f0948
🧑💻 (tasks) run management commands
...
This allows to run management commands from a celery task.
2025-03-18 18:02:53 +01:00
Quentin BEY and BEY Quentin
46ef6eca78
👷 (release) download translations from crowdin
...
When making a release, automatically download translations from Crowdin.
2025-03-14 16:45:41 +01:00
Quentin BEY and BEY Quentin
9439f454de
📝 (release) initiate documentation
...
This documentation is highly inspired from the `docs` project and
provide details for our project, like using the make command.
2025-03-14 16:45:41 +01:00
Quentin BEY
03600f243e
🧑💻 (makefile) fix mails-clean-templates
...
Fix the `no rule for mails-clean-templates` error when running
`make bootsrap`.
2025-03-14 10:46:17 +01:00
Quentin BEY and BEY Quentin
9f1c1ea7dd
🧑💻 (makefile) enforce generated mail clean
...
When used locally, you may have removed templates staying and
generarting old translations.
2025-03-13 16:26:32 +01:00
Quentin BEY
803b2c1930
🐛 (oauth2) remove ProConnect unknown claims
...
When we don't have information about the requested claims, they must be
ignored.
2025-03-13 14:52:00 +01:00
Quentin BEY and BEY Quentin
285647a8a9
✅ (ci) fix false print detection in commit
...
The method call `.thumbprint(...)` was detected as a print statement.
Restrict detection to words `print` and `pprint`.
2025-03-13 14:27:26 +01:00
Quentin BEY and BEY Quentin
c4dd4ae3fd
🐛 (oauth2) force JWT signed for /userinfo
...
ProConnect requires the userinfo endpoint to return a signed JWT.
2025-03-13 14:27:26 +01:00
Quentin BEY and BEY Quentin
34783d0557
🐛 (oauth2) add ProConnect scopes
...
Add missing scopes required by ProConnect evenif we don't fill them.
2025-03-13 11:33:07 +01:00
Quentin BEY and BEY Quentin
5cc8108e7b
🐛 (oauth2) disable PKCE for Proconnect
...
The PKCE is not available for Proconnect, security is made otherwise.
2025-03-13 10:23:43 +01:00
Quentin BEY and Sabrina Demagny
59633d6543
🐛 (i18n) force mail build before translation
...
This prevent the backend translation file to miss the mail translated
content.
I guess this should be managed otherwise, like asking django to look
into the mail template instead of the generated result.
2025-03-12 17:46:21 +01:00
Quentin BEY and Sabrina Demagny
a6f7c07052
🐛 (i18n) fix i18n-generate make command
...
The `i18n-generate` make command was not downloading the pot from
crowdin before the Django `makemessages` resulting in a pot file never
updated.
2025-03-12 17:46:21 +01:00
Quentin BEY and BEY Quentin
e3bf1d76fa
✅ (json) add a test for declared schema
...
This checks all the defined schema are properly defined.
2025-03-12 15:45:47 +01:00
Quentin BEY and BEY Quentin
f64a592648
✨ (organization) add metadata update command
...
This allows to update the Organization metadata with default values.
2025-03-12 15:45:47 +01:00
Quentin BEY and BEY Quentin
7ce5b28af4
✨ (organization) add metadata field
...
This allows to store custom values which can be reused along the
organization lifetime.
2025-03-12 15:45:47 +01:00
Quentin BEY and BEY Quentin
3aaddc0493
👷 (crowdin) upload main translations to crowdin
...
This will send the translations to crowdin everytime the main branch is
updated.
2025-03-12 15:14:44 +01:00
Quentin BEY and BEY Quentin
07ff093b18
👷 (github) move dependencies to a separated file
...
This is inspired from the https://github.com/suitenumerique/docs
project to allow reuse accross several workflows.
2025-03-12 15:14:44 +01:00
Quentin BEY and BEY Quentin
319a9b18d8
⬆️ (nginx) bump nginx-unprivileged to 1.27
...
Bump nginx-unprivileged to the latest version
2025-03-12 13:25:59 +01:00
Quentin BEY and BEY Quentin
403fea94bb
✨ (teams) allow broadly available teams
...
This adds `is_visible_all_services` field to `Teams` to make them
visible to all service providers
2025-03-11 19:15:03 +01:00
Quentin BEY
7f75efacf8
⚰️ (secrets) remove submodule
...
This submodule is no longer used, as all passwords are now on
vaultwarden.
2025-03-11 13:29:48 +01:00
Quentin BEY and BEY Quentin
b063f690f6
✨ (resource-server) add team invitation endpoint
...
This allows a service provider to add new members to a team.
2025-03-06 15:17:33 +01:00
Quentin BEY and Sabrina Demagny
7ea381c88a
📝 (i18n) describe process for translations
...
This explains the command to run to be able to translate our project.
2025-03-04 16:20:10 +01:00
Quentin BEY and BEY Quentin
b4ab36fc0e
📝 (oidc) describe the IdP aspect of people
...
This provides a light documentation about the way to
configure people as an IdentityProvider.
2025-03-03 12:24:43 +01:00
Quentin BEY and BEY Quentin
160ce92e54
✅ (oidc) add IdP e2e test for login
...
This is a simple test to assert a user can login via people when setup
as an identity provider.
2025-03-03 12:24:43 +01:00
Quentin BEY and BEY Quentin
a7ab2142f9
🔇 (helm) disable sentry on local stack
...
This is making too much noise when developing using the tilt stack...
2025-03-03 12:24:43 +01:00
Quentin BEY and BEY Quentin
cf4b435c63
🧑💻 (tilt) allow use of people as an IdP
...
Few fixes to allow the keycloak dev stack to use people
as an Identity Provider.
This requires the update of the bitnami keycloak chart we
use.
2025-03-03 12:24:43 +01:00
Quentin BEY and BEY Quentin
fd8e0e08c3
💄 (oidc) add login page in the frontend
...
To have a better user experience, we want the login page
to in the frontend.
2025-03-03 12:24:43 +01:00
Quentin BEY and BEY Quentin
68550f6f7e
🧑💻 (demo) configure people as an IdP
...
This configures local environment to test login through people:
- Keycloak configuration of the IdP (people)
- Add Keycloak Application in people
The only user who can login for now is "admin".
2025-03-03 12:24:43 +01:00
Quentin BEY and BEY Quentin
db6cdadd72
✨ (oidc) add django-oauth-toolkit w/ configuration
...
This allows to use `people` as an identity provider using
OIDC and local users.
This commit is partial, because it does not manage a way to
create "local" users and the login page is the admin one, which
can't be used for non staff users or login with email.
2025-03-03 12:24:43 +01:00
Quentin BEY and BEY Quentin
8faa049046
🗃️ (mailbox_manager) add organization to domain
...
To be able to provide a SIRET in the ProConnect IdP process
we need to be able to link a mail domain to its organization.
For now this is not mandatory, as we can't detect the organization
and need a frontend process to clarify it.
2025-03-03 12:24:43 +01:00
Quentin BEY
7ccd8e3035
🧱 (helm) remove extras from helmchart release
...
The local helm chart provides templates for local use only.
2025-02-21 11:29:20 +01:00
Quentin BEY and BEY Quentin
8d0fbdfecd
🧱 (helm) add resource-server ingress path
...
The route was added but not declared in the ingress.
2025-02-21 11:17:44 +01:00
Quentin BEY and BEY Quentin
a811431070
🧑💻 (tilt) use maildev for local kube
...
Switch from mailcatcher to maildev for local work purpose.
2025-02-13 15:12:45 +01:00
Quentin BEY and BEY Quentin
d23ac76f36
🧑💻 (dev) use maildev for local developments
...
Switch from mailcatcher to maildev for local work purpose.
2025-02-13 15:12:45 +01:00
Quentin BEY
351c696ef8
🐛 (tilt) fix the dev-keycloak configuration
...
The mailcatcher configuration was missing from the
configuration file when using keycloak.
2025-02-06 10:38:46 +01:00
Quentin BEY and BEY Quentin
b4a877381a
🐛 (teams) disable creation endpoint from abilities
...
When we don't allow the user to see the team creation button,
we also want to disable the corresponding API.
2025-02-04 15:20:48 +01:00
Quentin BEY and BEY Quentin
92753082c7
🚑 ️(teams) hide display add button when disallowed
...
The frontend should not display "add team" actions when the
user has not the ability.
2025-02-04 15:20:48 +01:00
Quentin BEY
7dd9eae5d9
💚 (argocd) humble try to fix the webhook call
...
This is an attempt to fix:
`Webhook processing failed: HMAC verification failed`
2025-02-03 13:12:42 +01:00
Quentin BEY
914319c366
💚 (argocd) fix deployment command
...
The command should use organization variables.
2025-02-03 12:48:50 +01:00
Quentin BEY
c34ad00fae
💚 (docker) fix docker login command
...
Use the secret from github organization.
2025-02-03 12:35:12 +01:00
Quentin BEY and BEY Quentin
289879962b
🧑💻 (tilt) add mailcatcher to the stack
...
This allows to start a mailcatcher for local developments.
2025-02-03 12:21:34 +01:00
Quentin BEY and BEY Quentin
cd88799943
💚 (github) remove secret fetch
...
The secrets are not managed in the folder anymore.
2025-01-30 15:55:58 +01:00
Quentin BEY and BEY Quentin
4011c8e8ed
🚑 ️(plugins) fix name from SIRET specific case
...
For some SIRET, there are no "liste_enseignes" (null), in such
cases we fallback on the global "company" name.
2025-01-30 15:55:58 +01:00
Quentin BEY and BEY Quentin
4ccea4655b
✨ (teams) add treebeard data to serializers
...
This will allow the frontend to represent teams as a
tree if needed.
2025-01-17 19:00:14 +01:00
Quentin BEY and BEY Quentin
45fd10fd2d
✨ (teams) return parent teams in resource server
...
Also return the parent teams in the user's team endpoints.
2025-01-17 19:00:14 +01:00
Quentin BEY and BEY Quentin
201864db3a
✨ (teams) return parent teams in API
...
Also return the parent teams in the user's team endpoints.
This is a first implementation which returns a flat list
of teams (not a tree). This is not really helpful, but
it allows to create hierarchical teams manually (via
admin) if an organization needs it.
2025-01-17 19:00:14 +01:00
Quentin BEY and BEY Quentin
182f9c1d17
🗃️ (teams) add Team dependencies as a tree
...
This provides the technical way to create Team trees.
The implementation is quite naive.
2025-01-17 19:00:14 +01:00
Quentin BEY
cff3d5c123
🐛 (tilt) add missing file after previous commit
...
My previous PR was merged to quickly, I forgot to add
the file to create the secret for Tilt.
2025-01-17 18:11:51 +01:00
Quentin BEY
32a576bbe9
🧑💻 (tilt) add sync dimail from people btn
...
Add a button to force sync of dimail accounts from
the people database.
2025-01-17 17:53:14 +01:00
Quentin BEY
010d3674de
🧑💻 (tilt) add dimail
...
This adds dimail to the tilt kube deployment
2025-01-17 17:53:14 +01:00
Quentin BEY and BEY Quentin
76fc789eb6
✨ (organization) add admin action for plugin
...
This allows admin user to run the post creation plugins
from the organization list.
2025-01-16 09:28:38 +01:00
Quentin BEY and BEY Quentin
469014ac41
🧑💻 (user) fix the User.language
...
The use of a lazy function here make the Django migration
detector to generate a migration every time we run `makemigrations`.
This is not mandatory to have a lazy here as the settings are loaded
once at runtime beginning.
As the choices makes noop migrations, we directly use the setting in
the initial migration.
2024-12-19 22:16:08 +01:00
Quentin BEY and BEY Quentin
fa80edfaa8
🔧 (helm) add organization name from siret plugin
...
This declares the use of the `NameFromSiretOrganizationPlugin`
to allow automatic SIRET -> Name guess when creating an
organization
2024-12-16 16:08:08 +01:00
Quentin BEY and BEY Quentin
38a5f158b5
✨ (organizations) add siret to name conversion
...
This adds the plugin system to easily manage
Organization related customizations. This first
plugin tries (best effort) to get a proper name
for the Organization, using its SIRET. This
is French specificities but another plugin can
be defined for other cases.
2024-12-16 16:08:08 +01:00
Quentin BEY and BEY Quentin
6e14c2e61f
✅ (e2e) fix flaky test
...
The URL may or may not include the "page" query parameter.
2024-12-16 15:51:25 +01:00
Quentin BEY and BEY Quentin
dd9a905dc0
📝 (tilt) add startup guide to Tilt use
...
This provides an "how-to" to deploy a local dev
Kubernetes environment.
2024-12-16 12:35:48 +01:00
Quentin BEY and BEY Quentin
2f380b49d0
🧑💻 (dimail) allow account populate from DB
...
Allow the dimail account creation command to create
accounts from the data in people's database.
2024-12-16 12:18:18 +01:00