Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
658 commits
Select commit Hold shift + click to select a range
938fb94
Merge pull request #1807 from RCOSDP/fix/issue57254
ivis-miyachi Jun 11, 2026
1ef13e4
Merge pull request #1861 from KotaroInoue1448/fix_58215
ivis-miyachi Jun 11, 2026
833b077
Merge pull request #1866 from RCOSDP/fix/issue60332
ivis-miyachi Jun 11, 2026
56590ae
Merge branch 'develop_v2.1.0' into develop_W2025-16-1.3
ivis-miyachi Jun 12, 2026
9ce078a
Merge pull request #1865 from ivis-weko3-dev/develop_W2025-16-1.3
ivis-miyachi Jun 12, 2026
847b37e
Compile multilingual files(#60737)
ivis-miyachi Jun 18, 2026
ffce295
Merge pull request #1869 from RCOSDP/fix/issue60737
ivis-miyachi Jun 18, 2026
d8a1ff3
fix/60919
KotaroInoue1448 Jun 19, 2026
ee246e7
Merge pull request #1871 from ivis-weko3-dev/fix/site_license_downloa…
ivis-miyachi Jun 19, 2026
fdc62ce
fix migrate tool(#61275)
ivis-miyachi Jun 24, 2026
fb804ba
fix migrate tool(#61275)
ivis-miyachi Jun 25, 2026
612906a
Merge pull request #1874 from RCOSDP/fix/issue61275
ivis-miyachi Jun 25, 2026
071e930
Merge pull request #1872 from RCOSDP/feature/issue58577
ivis-miyachi Jun 25, 2026
189b33c
Create SQL migration for item_type_mapping constraints(#61275)
ivis-miyachi Jun 26, 2026
210868b
refactor(db): remove legacy Alembic revisions and establish a new bas…
ivis-miyachi Jul 3, 2026
428aceb
Merge pull request #1875 from RCOSDP/fix/issue61275
ivis-miyachi Jul 8, 2026
f7e4575
Merge pull request #1870 from KotaroInoue1448/fix/60919
ivis-miyachi Jul 8, 2026
d6d92a5
fix build error
mhaya Jul 17, 2026
b19e39d
fix
mhaya Jul 17, 2026
3de23b2
fix build error
mhaya Jul 20, 2026
1288154
perf: reduce redundant get_search_setting() DB queries on page render
mhaya Jul 22, 2026
71cc1a7
test: fix pre-existing test fixture failures in theme and records-ui
mhaya Jul 22, 2026
4cde4e0
perf: memoize index lookups in item landing page (3-2)
mhaya Jul 22, 2026
a76f6c5
perf: cache widget design lookup per request (common-C)
mhaya Jul 22, 2026
b63d08a
perf: cache get_search_detail_keyword() with a short TTL (common-B)
mhaya Jul 22, 2026
3a6530b
test: create partition and init InvenioCache in weko-items-ui fixtures
mhaya Jul 22, 2026
b412eda
perf: cache get_ranking() with a short TTL (2-1)
mhaya Jul 22, 2026
723ecb7
perf: memoize item-type data per request in sort_meta_data_by_options…
mhaya Jul 22, 2026
6d8e7e2
perf: cache rebuilt JPCOAR OAI XML on item landing page (3-1)
mhaya Jul 22, 2026
406859f
test: fix item_type_mapping FK ordering in invenio-records-rest fixture
mhaya Jul 22, 2026
93eab88
perf: speed up search-result per-item formatting, drop dead executor …
mhaya Jul 22, 2026
38051e8
docs: add performance issues analysis with implementation status
mhaya Jul 22, 2026
18da884
docs: add function-level spec and unit test results for perf fixes
mhaya Jul 22, 2026
c55963e
test: add E2E performance measurement harness and before/after results
mhaya Jul 23, 2026
8ad80e3
docs: note that after-vs-before max spikes are environmental outliers
mhaya Jul 23, 2026
6d567b2
test: re-measure on a clean host (k8s stopped) and document load depe…
mhaya Jul 23, 2026
8cde084
fix_61565
KotaroInoue1448 Jul 23, 2026
771072a
test: add concurrent load test showing ~2.2x search throughput gain
mhaya Jul 23, 2026
f6af085
docs: add TL;DR summary of all three performance measurements
mhaya Jul 23, 2026
a1ace7f
test: measure browser E2E under parallel load; update before/after_br…
mhaya Jul 23, 2026
5b21acf
test: harden load runner (scratch output, marker verify, concurrency …
mhaya Jul 23, 2026
c3faf8f
test: run perf scripts from a stable out-of-repo path
mhaya Jul 23, 2026
7530970
test: add concurrency=20 n=100 load + parallel-browser results
mhaya Jul 23, 2026
628dd0b
docs: add final consolidated results table across all measurements
mhaya Jul 23, 2026
dfa22ca
fix(review): close cache-key leaks in common-B and 2-1 found in review
mhaya Jul 23, 2026
e858c70
test(review): add coverage for the perf fixes flagged as untested
mhaya Jul 23, 2026
7798b22
test: re-measure perf after review fixes (concurrency=20, n=100)
mhaya Jul 23, 2026
aa7e5f2
test: add concurrency=40 n=100 measurement
mhaya Jul 23, 2026
5fa31fe
perf: short-TTL cache for get_search_setting() and AdminSettings.get()
mhaya Jul 23, 2026
4c76d19
test: load-test top/detail pages; record settings-cache (B/D) evaluation
mhaya Jul 23, 2026
ad4ce51
test: browser E2E at concurrency 5 (warm) + document client-bound beh…
mhaya Jul 23, 2026
bdec394
fix: repair nginx image build on amd64 and stale apt index
mhaya Jul 24, 2026
fc73edb
fix build error
mhaya Jul 24, 2026
5714b5a
Merge pull request #1883 from RCOSDP/release_v2.0.3
ivis-miyachi Jul 24, 2026
8397bbd
Merge pull request #1880 from KotaroInoue1448/fix/61565
ivis-miyachi Jul 24, 2026
e918b38
fix_61297
KotaroInoue1448 Jul 27, 2026
ea489ec
weko#61684 fix import issue
wei-kuochen Jul 28, 2026
525c1ff
Merge pull request #1881 from RCOSDP/fix/issues61802
Ooka-Masashi Jul 28, 2026
28ea524
Merge pull request #1884 from KotaroInoue1448/fix_61297
Ooka-Masashi Jul 28, 2026
6442aaa
Merge pull request #1885 from RCOSDP/fix/issue61684
Ooka-Masashi Jul 28, 2026
a829b3d
refactor: update role and group filtering logic using map conditions
ivis-futagami Jul 28, 2026
1167e36
fix: add group_keyword to Gakunin group pattern dictionary
ivis-futagami Jul 28, 2026
044a437
fix: improve role mapping logic and handle missing configuration
ivis-futagami Jul 30, 2026
93678d6
fix: unit tests for map roles
ivis-futagami Jul 30, 2026
82abefa
add unit test for sword
mhaya Aug 2, 2026
889585d
remove unused change
ivis-futagami Aug 5, 2026
069c4d7
fix: update test cases
ivis-futagami Aug 5, 2026
9ebd549
fix: add unit test
ivis-futagami Aug 6, 2026
4b08671
Merge pull request #1889 from RCOSDP/main
ivis-miyachi Aug 7, 2026
cd31fca
Merge pull request #1891 from ivis-weko3-dev/feature/fix_map_role_con…
ivis-miyachi Aug 20, 2026
3bfc0a2
Merge tag 'v2.0.4' into develop_v2.1.0
ivis-miyachi Sep 4, 2026
e3ab9af
fix(records-ui): 認可デコレータが位置引数の recid を見ていない (issue62807)
mhaya Sep 7, 2026
4039b4c
feat(api-inventory): ビューの in-process 呼び出しを台帳に載せる (issue62807)
mhaya Sep 7, 2026
0e1e426
docs(ci): Claudeレビューを他レビュー統合型に変える設計を追加
mhaya Sep 1, 2026
dfbd7f8
docs(ci): Claudeレビュー統合の実装計画を追加
mhaya Sep 1, 2026
c729726
test(ci): Claudeレビュー統合のテスト基盤とPR#1905のfixtureを追加
mhaya Sep 1, 2026
9866bb4
docs(ci): 実装計画のfixture期待値を実データに合わせる
mhaya Sep 1, 2026
1842b62
feat(ci): PRの既存レビューをGraphQLで収集するスクリプトを追加
mhaya Sep 1, 2026
49ef5dc
fix(ci): レビュー出力のテストと pagination limit 検出を追加
mhaya Sep 1, 2026
3971c87
docs(ci): 設計のGraphQLクエリをlast:100に修正
mhaya Sep 1, 2026
1920c5a
feat(ci): 既存レビューを外部データ枠に入れた入力とプロンプトを追加
mhaya Sep 1, 2026
8ddbbb0
fix(ci): 外部レビュー本文からの囲み偽造をnonceと記号無害化で防ぐ
mhaya Sep 1, 2026
511b8cd
feat(ci): Claude出力の和集合と検証を行う集約スクリプトを追加
mhaya Sep 1, 2026
eff491e
fix(ci): 集約スクリプトのパス内重複排除と行番号検証を実装
mhaya Sep 1, 2026
a8daf0f
fix(ci): 行番号正規化による鍵衝突を解決
mhaya Sep 1, 2026
2676d97
feat(ci): 裁定結果を集約コメントのMarkdownに描画する処理を追加
mhaya Sep 1, 2026
5b69087
fix(ci): render.py の Markdown 注入を防ぐ
mhaya Sep 1, 2026
eebc44d
fix(ci): _cell() のバックスラッシュ回帰と改行によるブロック注入を修正
mhaya Sep 1, 2026
0037c00
docs(ci): 設計に出力側のMarkdown注入対策を追記
mhaya Sep 1, 2026
6fed892
feat(ci): 確度の高い修正案をinline suggestionとして投稿する処理を追加
mhaya Sep 1, 2026
fcba506
fix(ci): claude-fix マーカーの偽造対策と kind ガードの回帰テストを追加
mhaya Sep 1, 2026
7a65b18
fix(ci): claude-fixマーカーをreplacement経由で偽造できる穴を塞ぐ
mhaya Sep 1, 2026
dc388bf
feat(ci): Claudeレビューを他レビュー統合型に変更
mhaya Sep 1, 2026
eed7d46
fix(ci): レビュー配線のレビュー指摘3件を修正
mhaya Sep 1, 2026
18039e7
refactor(claude-review): _esc/_cell/_fence を mdsafe.py に集約
mhaya Sep 1, 2026
7b652e9
fix(claude-review): 行頭の構造記号を無害化する(所見1/2)
mhaya Sep 1, 2026
f8e69b2
fix(claude-review): 壊れたパスを passes の分母に数えない(所見3)
mhaya Sep 1, 2026
898a2dd
fix(claude-review): inline suggestion が無いとき「あり(inline)」と言わない(所見4)
mhaya Sep 1, 2026
ac7c7fb
fix(claude-review): pull_request_review系トリガに投稿者ガードを追加(所見7)
mhaya Sep 1, 2026
d37f173
fix(claude-review): SELF 判定が [bot] 表記のログインを見逃す穴を塞ぐ(所見8)
mhaya Sep 1, 2026
ec97bd5
fix(claude-review): clean_adj も空の title を弾く(所見11)
mhaya Sep 1, 2026
3ddb302
fix(claude-review): @ メンションを無害化する(所見12)
mhaya Sep 1, 2026
d050edf
docs(claude-review): 計画・設計書の陳腐化した記述を修正(所見5/6)
mhaya Sep 1, 2026
aedf9a0
add operations.md
mhaya Sep 1, 2026
30ffff9
fix(claude-review): PR #1907 のレビュー指摘に対応する
mhaya Sep 1, 2026
0abf5f2
chore(claude-review): api-inventory 側のワークフロー複製を消す
mhaya Sep 1, 2026
d9c2f09
fix
mhaya Sep 2, 2026
16bcc28
fix(tools): enrich_git.py を列名対応にし、更新手順へ組み込む
mhaya Sep 2, 2026
bef273c
fix(tools): snapshot.py / fixtures.py が $WEKO_WEB_CONTAINER を見ていない
mhaya Sep 2, 2026
b5db8a4
feat(api-inventory): ソース由来の経路検知を足し、ツールの単体テストを置く
mhaya Sep 2, 2026
8bc6bff
ci: GitHub で回っていなかったユニットテストを回す
mhaya Sep 2, 2026
a0d1dc0
ci: ローカルと CI で同じ経路を通す仕組みを入れる
mhaya Sep 2, 2026
e3c2709
ci: ローカル実行を CPU アーキで分岐させない
mhaya Sep 2, 2026
186965c
test: CI で初めて走ったユニットテストの失敗を直す (第1弾)
mhaya Sep 3, 2026
9b275e7
test: CI で初めて走ったユニットテストの失敗を直す (第2弾)
mhaya Sep 3, 2026
25b8441
test: weko-itemtypes-ui の register ACL / 重複マッピング判定を直す
mhaya Sep 3, 2026
4739b9f
test: CI で初めて走ったユニットテストの失敗を直す (第3弾)
mhaya Sep 3, 2026
c376d3d
test: CI で初めて走ったユニットテストの失敗を直す (第4弾)
mhaya Sep 3, 2026
a977b71
test: CI で初めて走ったユニットテストの失敗を直す (第5弾)
mhaya Sep 3, 2026
2dcbf6a
test: CI で初めて走ったユニットテストの失敗を直す (第6弾)
mhaya Sep 3, 2026
dc6cb9a
test: CI で初めて走ったユニットテストの失敗を直す (第7弾)
mhaya Sep 3, 2026
60f77b3
test: CI で初めて走ったユニットテストの失敗を直す (第8弾)
mhaya Sep 3, 2026
43163f7
test: CI で初めて走ったユニットテストの失敗を直す (第9弾)
mhaya Sep 3, 2026
73cc411
test: 残りのユニットテスト失敗を直し、ジョブの制限時間を実測に合わせる
mhaya Sep 3, 2026
029cd9c
ci: 5時間かかるモジュールをテスト本数で分割して回す
mhaya Sep 3, 2026
932b822
ci: 分割の偏りに合わせて分割数と制限時間を見直す
mhaya Sep 4, 2026
66fc1d8
test: weko-search-ui の NDL JaLC まわりの期待値を実挙動に合わせる
mhaya Sep 4, 2026
fdb8688
test: weko-workflow の残り 15 本を直す
mhaya Sep 4, 2026
413212a
test: weko-workflow [8/8] が 120 分で打ち切られていた原因を潰す
mhaya Sep 5, 2026
4666e2c
test: weko-deposit [8/8] が 120 分で打ち切られていた原因を潰す
mhaya Sep 5, 2026
de4c4de
ci: テストのタイムアウトを実際に効かせる
mhaya Sep 5, 2026
bda3865
test: weko-deposit の失敗を直す (1/2)
mhaya Sep 5, 2026
a526ab6
test: weko-deposit の失敗を直す (2/2)
mhaya Sep 5, 2026
cbca401
test: weko-deposit の残り 3 本を直す
mhaya Sep 5, 2026
bdb83b2
test: weko-records-ui の 5 本を直す
mhaya Sep 5, 2026
10f0e74
test: weko-search-ui の 10 本を直す
mhaya Sep 5, 2026
4429780
test: weko-search-ui の最後の1本 (test_check_jsonld_import_items) を直す
mhaya Sep 5, 2026
2e15e48
test: CI に残っていた5本を直す
mhaya Sep 5, 2026
82baabf
test: test_function_issue35902 の比較を並び順に依存させない
mhaya Sep 5, 2026
b8c8110
test: weko-search-ui [6/6] の 3 本を直す
mhaya Sep 5, 2026
2869ce2
test: 時刻依存と werkzeug 依存の2本を直す
mhaya Sep 5, 2026
2dd1dcc
test: 共有された WEKO_SEARCH_KEYWORDS_DICT の破壊を止める
mhaya Sep 5, 2026
0d076a9
test: create_export_all_data のレコード数を減らす
mhaya Sep 5, 2026
235f472
docs: issues.md を Redmine Textile に変換する
mhaya Sep 6, 2026
a4c050d
f
mhaya Sep 6, 2026
8dcaa1e
test: xfail のうち2件がテスト側の問題だったので直す
mhaya Sep 6, 2026
b4f5ac8
test: 各モジュールの tox 依存に pypdfium2 を足す
mhaya Sep 7, 2026
2916a9b
test: v2.1.0 の変更で壊れた fixture を直す
mhaya Sep 7, 2026
63d24b9
test: invenio-communities のキャッシュ先に CACHE_REDIS_URL を指定する
mhaya Sep 7, 2026
8b67e7d
test: weko-records に残った v2.1.0 由来の失敗を直す
mhaya Sep 7, 2026
bb24d13
test: weko-workspace の Mapping.create を create_or_update に直す
mhaya Sep 8, 2026
635d8f4
test: Mapping の delete / revert を v2.1.0 の挙動に合わせる
mhaya Sep 8, 2026
6feaee6
test: v2.1.0 由来の残り41件を xfail で受け止め、棚卸しを残す
mhaya Sep 8, 2026
179ffc2
fix(demo): item_type.sql をデータのみのダンプに変え、生成方法を直す
mhaya Sep 8, 2026
d0a4d10
fix(demo): setval を「ID のリザーブ」として扱う
mhaya Sep 8, 2026
15f5242
test(ui): インデックス更新の完了を DOM のアラートで待つ
mhaya Sep 8, 2026
5c18b41
test(ui): アイテム登録で開くのは File セクション (File Information ではない)
mhaya Sep 9, 2026
165f745
test(ui): 配列型の File セクションは入れ子の2枚を開く
mhaya Sep 9, 2026
8d006a5
test(ui): File パネルは開閉状態を見て段階的に開く
mhaya Sep 9, 2026
e979cef
test(ui): GakuNin RDM の URL を設定から読む
mhaya Sep 9, 2026
247fae3
test(ui): インデックス公開設定が反映されたことまで確認する
mhaya Sep 9, 2026
b4f8e6d
test(ui): 匿名取得が失敗したとき遷移先と本文を出す
mhaya Sep 9, 2026
fd5747a
test(ui): グループ未設定のインデックスが誰にも見えない件を xfail で記録する
mhaya Sep 9, 2026
d67021b
docs: 棚卸し文書を Redmine Textile に変換する
mhaya Sep 9, 2026
8fa8860
Merge pull request #1911 from RCOSDP/fix/issue62764
mhaya Sep 9, 2026
6065e94
Merge remote-tracking branch 'origin/develop_v2.1.0' into hotfix/issu…
mhaya Sep 10, 2026
2898a5d
update doc
Sep 12, 2026
d8b6244
tools(release): 前提チェックと PR 作成のスクリプトを追加
Sep 12, 2026
78dbf99
docs: ルールを RULE.md に分け、手順に事前準備を集約する
Sep 12, 2026
760b843
docs: 実機の場所を環境変数にまとめ、手順からリテラルを外す
Sep 12, 2026
b8f4dd9
docs: add_row.py の対象指定を --endpoint / --uri に直す
Sep 12, 2026
b572c44
fix(tools): 接続できないときの案内を実態に合わせる
Sep 12, 2026
24ac3a3
docs: 実行して詰まる箇所を潰す(手順の再レビュー)
Sep 12, 2026
c762f9a
feat(tools): 入口より深い認可の欠陥を検査する audit_authz.py を置く
mhaya Sep 15, 2026
894f524
feat(tools): inproc_callers を引き直す refresh_callers.py を置き、列を 63 に確定する
mhaya Sep 15, 2026
04a1118
docs(tools): バージョン更新でつまずいた実機側の前提をケース3に足す
mhaya Sep 15, 2026
89e4cc8
docs(rule): public に書いてよい範囲を「ファイル」から「内容」の判断に改める
mhaya Sep 15, 2026
8a46d93
test(tools): docs/RULE.md も schema.py と突き合わせる
mhaya Sep 15, 2026
c69ed4c
Merge remote-tracking branch 'origin/develop_v2.1.0' into hotfix/issu…
mhaya Sep 16, 2026
ebcbb3b
Merge pull request #1914 from RCOSDP/hotfix/issue62807
mhaya Sep 16, 2026
87c65f6
fix(tools): 非公開情報の露出は、無認証なら P1・認証経由なら P2 に分ける
mhaya Sep 23, 2026
a484819
feat(tools): 応答に非公開判定が効いているかを見る audit_masking.py を置く
mhaya Sep 23, 2026
103b676
Merge branch 'chore/api-inventory-tools' into develop_v2.1.0
mhaya Sep 23, 2026
af07837
refactor(tools): inproc_callers の実装を refresh_callers.py に一本化する
mhaya Sep 23, 2026
59383a0
feat(tools): 未解消の指摘をチケット番号だけ public 側に出せるようにする
mhaya Sep 23, 2026
4fa4e27
docs(ops): 台帳まわりの手順を、増えたツールとゲートに追随させる
mhaya Sep 23, 2026
c6ced16
docs: 例に使うチケット番号を、実在しえない形に置き換える
mhaya Sep 23, 2026
04fced0
fix(tools): 状態変更系を HTTP メソッドだけで決めるのをやめる
mhaya Sep 24, 2026
2b703a4
feat(tools): 台帳の中身をソースと突き合わせる検査を足す
mhaya Sep 24, 2026
c7b807b
fix(tools): CI で解析対象を台帳の測定リビジョンに固定し、手順書を追随させる
mhaya Sep 24, 2026
91a34ca
fix: add missing auth/authz checks to several API endpoints
asuzuki1 Sep 25, 2026
cf13495
Delete unnecessary instance.cfg (#63281)
ivis-miyachi Sep 25, 2026
609fa8f
fix(tools): add_row.py が廃止した no を使い回さないようにする
mhaya Sep 25, 2026
fe16743
docs(ops): 台帳の検査を手元で回す運用と、no を主キーとして扱う手順を書く
mhaya Sep 25, 2026
7ea3eb8
fix(tools): add_row.py の追記を排他にし、払い出し記録を先に書く
mhaya Sep 25, 2026
75af0d8
fix(tools): add_row.py が存在しない台帳を作らないようにする
mhaya Sep 25, 2026
8bcd5be
Merge pull request #1917 from RCOSDP/fix/api-inventory-no-registry
mhaya Sep 25, 2026
ffb8aed
fix(ci): drift ワークフローの実体にソース由来の経路検知を入れる
mhaya Sep 26, 2026
01a2a9b
style(tools): test_workflows.py の行長を flake8 に合わせる
mhaya Sep 26, 2026
26466c3
Merge pull request #1919 from RCOSDP/fix/api-inventory-drift-detect-r…
mhaya Sep 27, 2026
761d173
fix(nginx): HTTP/1.0 で転送されたリクエストにも gzip を効かせる
mhaya Sep 27, 2026
0966dc6
fix(nginx): バイナリのダウンロードを gzip の対象から外す
mhaya Sep 27, 2026
01ec93e
fix(nginx): 非推奨の ssl on を listen の ssl 指定に置き換える
mhaya Sep 28, 2026
aba24d0
fix(weko-deposit): デポジット更新系の権限判定を編集権限で有効にする
mhaya Sep 27, 2026
9bb19ec
fix(weko-deposit): 更新系の既定の権限判定を deny_all に戻す
mhaya Sep 27, 2026
57ce864
fix(tools): 測定用インデックスに閲覧・投稿グループの既定値を入れる
mhaya Sep 28, 2026
8887f79
Merge pull request #1922 from RCOSDP/fix/api-inventory-fixture-no-group
mhaya Sep 28, 2026
73fcb85
fix(weko-items-ui): BibTeX 出力の検証で閲覧できないレコードを存在しないものと同じに扱う
mhaya Sep 27, 2026
8608a75
fix(invenio-resourcesyncserver): 配信対象を公開アイテムに限る
mhaya Sep 27, 2026
84897aa
fix(invenio-resourcesyncserver): manifest に列挙するファイルをダウンロード可能なものに限る
mhaya Sep 27, 2026
bc50425
fix(weko-records-ui): ファイル権限の判定でコミュニティ管理者の管轄を確認する
mhaya Sep 27, 2026
a82314e
fix(weko-sitemap): サイトマップに載せるアイテムを公開アイテムに限る
mhaya Sep 27, 2026
6aa5c50
fix(weko-records-ui): プレビューでファイルの権限を確認する
mhaya Sep 27, 2026
5f2820e
fix(invenio-stats): 閲覧数・ファイル統計の取得をレコードの閲覧権限に揃える
mhaya Sep 27, 2026
67bb31e
fix(invenio-files-rest): ゲストトークンでのファイル操作を当該アクティビティのバケットに限定する
mhaya Sep 27, 2026
d4b0ef5
fix(weko-admin): サイトライセンスメール手動送信で対象リポジトリの権限を確認する
mhaya Sep 27, 2026
d908598
fix(weko-signposting): signposting の応答に詳細画面と同じ閲覧権限を適用する
mhaya Sep 27, 2026
3768aef
fix(invenio-iiif): 画像配信でファイルの権限判定を行う
mhaya Sep 27, 2026
7f681e2
fix(weko-admin): 検索設定用のインデックス取得 API を管理者に限定する
mhaya Sep 27, 2026
e0b7f00
fix(weko-search-ui): インデックス名の取得を閲覧可能なインデックスに限る
mhaya Sep 27, 2026
e90be8e
fix(invenio-iiif): マニフェストでレコードとファイルの権限判定を行う
mhaya Sep 27, 2026
3ab80eb
fix(weko-accounts): ログイン API の失敗応答を揃え、レート制限を有効にする
mhaya Sep 27, 2026
229ad77
fix(weko-swordserver): 登録可能ロールの設定を実行時に参照する
mhaya Sep 27, 2026
233be5e
fix: validate repository scope on widget save API
asuzuki1 Sep 28, 2026
99995a8
test: 追加したテストのフィクスチャの扱いを直す
mhaya Sep 28, 2026
97e5e4c
test(weko-records-ui): プレビューの権限テストでファイルのメタデータを実体に書き込む
mhaya Sep 28, 2026
0a463b8
fix(invenio-iiif): サムネイル作成タスクでは利用者の権限を確かめずに対象を解決する
mhaya Sep 28, 2026
59fa15d
fix(weko-accounts): 回数制限をログイン API だけにかける
mhaya Sep 28, 2026
cf2cfa6
fix(weko-accounts): Shibboleth SP の属性の受け付け元を SP のログインスクリプトに限る
mhaya Sep 28, 2026
8c2ab33
fix(nginx): SP の属性の受け付け判定を、real_ip で書き換える前の接続元で行う
mhaya Sep 28, 2026
facd5ab
fix widget permission issue (No. 290, 303, 304)
wei-kuochen Sep 29, 2026
894f70f
add test code
wei-kuochen Sep 29, 2026
11b0527
fix group permission issue (No.306, 307, 312~326)
wei-kuochen Sep 29, 2026
297905d
add test code
wei-kuochen Sep 29, 2026
121eb34
fix 62782, 62796
KotaroInoue1448 Sep 29, 2026
23ccdf7
Merge pull request #1931 from RCOSDP/fix/issue62771
ivis-miyachi Sep 29, 2026
f9c49c9
Merge pull request #1930 from RCOSDP/fix/issue62770
ivis-miyachi Sep 29, 2026
c0ecb36
Merge pull request #1929 from RCOSDP/fix/shib-sp-login-source
ivis-miyachi Sep 29, 2026
2fedd81
Merge pull request #1928 from RCOSDP/fix/login-api-response
ivis-miyachi Sep 29, 2026
2059066
Merge pull request #1927 from RCOSDP/fix/admin-scope-and-sword-roles
ivis-miyachi Sep 29, 2026
be0abe2
Merge pull request #1926 from RCOSDP/fix/public-visibility-check
ivis-miyachi Sep 29, 2026
b37cad1
Merge pull request #1925 from RCOSDP/fix/file-access-permission
ivis-miyachi Sep 29, 2026
c85aa24
Merge pull request #1924 from RCOSDP/fix/deposit-update-permission
ivis-miyachi Sep 29, 2026
8740ed6
exclude No.560
KotaroInoue1448 Sep 29, 2026
bc24b58
Merge pull request #1923 from ivis-weko3-dev/fix/issue62783
ivis-miyachi Sep 29, 2026
af5a201
Merge pull request #1920 from RCOSDP/fix/nginx-gzip
ivis-miyachi Sep 29, 2026
27b3c1e
exclude No.560_unit_test
KotaroInoue1448 Sep 29, 2026
7d5ea54
Merge branch 'develop_v2.1.0' into fix/issue62782/issue62796
ivis-miyachi Sep 29, 2026
fa824f5
Merge pull request #1932 from KotaroInoue1448/fix/issue62782/issue62796
ivis-miyachi Sep 29, 2026
2614af9
Merge pull request #1918 from RCOSDP/fix/issue63281
ivis-miyachi Sep 29, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
78 changes: 78 additions & 0 deletions .github/workflows/api-inventory-drift.yml
Original file line number Diff line number Diff line change
Expand Up @@ -17,6 +17,13 @@
# 個人アカウントに紐づかないため(PAT より事故時の影響が小さい)。
# 未設定なら、このジョブは何もせずスキップする(fork からの PR でも安全)。
#
# 網羅性は二段で見る:
# reconcile.py 実機 url_map ↔ 台帳(この環境で登録されている経路)
# detect_routes.py ソース(AST) ↔ 台帳(config で無効な経路まで含む)
# 前者だけだと、config で無効・プラグイン未導入の経路が台帳から落ちても気付けない。
#
# ツールそのものの単体テストは api-inventory-tests.yml(Secret も Docker も不要)。
#
# 設置手順: tools/api-inventory/ci/README.md

name: API Inventory Drift
Expand Down Expand Up @@ -106,6 +113,68 @@ jobs:
with:
python-version: '3.11'

# 台帳は「どのリビジョンを測ったか」とセットでしか意味を持たない
# (docs/RULE.md 規則 2-3)。inproc_callers と sec_evidence は
# `ファイル:行番号` を持つので、PR の HEAD と突き合わせると
# **中身の問題ではなくバージョン違いだけで落ちる**。実測では、版を1つ
# 上げるだけで台帳の位置参照 410 箇所のうち 250 箇所が変更ファイルを指す。
# 台帳が測ったリビジョンを worktree に出して、そこを解析対象にする。
- name: Pin analysis source to the measured revision
id: pin
if: steps.cfg.outputs.enabled == 'true'
run: |
set -eu
REV=$(python3 -c "import json;print(json.load(open('.api-inventory-data/api_snapshot.json'))['meta'].get('revision') or '')" 2>/dev/null || echo '')
if [ -z "$REV" ]; then
echo "::warning::台帳に meta.revision がありません。位置参照と inproc_callers の検査をスキップします。スキップを PASS と読まないこと。"
echo "weko_root=" >> "$GITHUB_OUTPUT"
exit 0
fi
git cat-file -e "${REV}^{commit}" 2>/dev/null || git fetch --no-tags origin "$REV" 2>/dev/null || true
if git cat-file -e "${REV}^{commit}" 2>/dev/null; then
git worktree add --detach .ledger-src "$REV" >/dev/null
echo "測定リビジョン ${REV} を .ledger-src に展開した"
echo "weko_root=${GITHUB_WORKSPACE}/.ledger-src" >> "$GITHUB_OUTPUT"
else
echo "::warning::台帳の測定リビジョン ${REV} をこのリポジトリで解決できません。位置参照と inproc_callers の検査をスキップします。スキップを PASS と読まないこと。"
echo "weko_root=" >> "$GITHUB_OUTPUT"
fi

# ソース(AST)と台帳だけで済むので、コンテナを立てる前に流す。
# ビュー関数が HTTP を通らず別モジュールから直接呼ばれる「第二の入口」は
# ルート単位の台帳に現れず、認可を足す作業で素通りする(issue62807)。
# 台帳の inproc_callers に無い呼び出し元が現れたら止める。
- name: Check in-process view callers
if: steps.cfg.outputs.enabled == 'true' && steps.pin.outputs.weko_root != ''
env:
WEKO_API_INVENTORY_DIR: ${{ github.workspace }}/.api-inventory-data
WEKO_ROOT: ${{ steps.pin.outputs.weko_root }}
run: |
python3 tools/api-inventory/scripts/refresh_callers.py \
--summary-only --gate

# 所見は private 側にしか書けないぶん、未修正が台帳の中だけで滞留して
# 忘れられる。ここが出すのは**チケット番号と件数だけ**で、経路名も所見も
# 出さない(docs/RULE.md §1)。記入漏れと、未起票の増加で落とす。
- name: Check open findings
if: steps.cfg.outputs.enabled == 'true'
env:
WEKO_API_INVENTORY_DIR: ${{ github.workspace }}/.api-inventory-data
run: |
python3 tools/api-inventory/scripts/open_findings.py \
--summary-only --gate

# 台帳の検査(private 側)は形と語彙しか見ない。sec_evidence の行番号を
# 実在しない値にしても data_op を誤った値にしても全部通る。ここで突き合わせる。
- name: Check ledger evidence against source
if: steps.cfg.outputs.enabled == 'true' && steps.pin.outputs.weko_root != ''
env:
WEKO_API_INVENTORY_DIR: ${{ github.workspace }}/.api-inventory-data
WEKO_ROOT: ${{ steps.pin.outputs.weko_root }}
run: |
python3 tools/api-inventory/scripts/audit_evidence.py \
--summary-only --gate

- name: Start WEKO containers
if: steps.cfg.outputs.enabled == 'true'
run: |
Expand Down Expand Up @@ -147,6 +216,13 @@ jobs:
--snapshot /tmp/api_snapshot.new.json \
--summary-only --gate --out /tmp/reconcile.md

# 実機 url_map は「この環境で登録された経路」しか映さない。config で無効・
# プラグイン未導入・設定値が真のときだけ登録される経路は、API として
# 存在するのに reconcile では見えない。ソースからの検知で二段目を張る。
python3 $T/detect_routes.py \
--weko-root "$PWD" --cross-check \
--summary-only --gate --out /tmp/detect.md

- name: Probe changed endpoints
if: always() && steps.cfg.outputs.enabled == 'true'
env:
Expand Down Expand Up @@ -175,6 +251,7 @@ jobs:
path: |
/tmp/drift.md
/tmp/reconcile.md
/tmp/detect.md

- name: Comment on PR (counts only)
if: always() && steps.cfg.outputs.enabled == 'true' && github.event_name == 'pull_request'
Expand Down Expand Up @@ -206,6 +283,7 @@ jobs:
+ '該当箇所はプライベートリポジトリ側の台帳・レポートで確認してください。';
body += read('/tmp/drift.md', 'ベースラインとの差分');
body += read('/tmp/reconcile.md', '台帳との突き合わせ');
body += read('/tmp/detect.md', 'ソース由来の経路検知');
await github.rest.issues.createComment({
issue_number: context.issue.number,
owner: context.repo.owner,
Expand Down
60 changes: 60 additions & 0 deletions .github/workflows/api-inventory-tests.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,60 @@
# WEKO3 リポジトリ(RCOSDP/weko)の .github/workflows/ に配置する。
#
# 台帳ツールの単体テスト。**Docker も実機も台帳も要らない**ので数秒で終わる。
# api-inventory-drift.yml(実機を起こして突き合わせる。60分枠)とは役割が違う:
#
# このワークフロー … 台帳を作る側(スクリプト・手順書)が壊れていないか
# drift ワークフロー … 台帳の中身が実機とずれていないか
#
# ツールが壊れたまま drift だけ回すと、検知器が黙って死んでいても緑で通る。
# 先にこちらを通すこと。Secret も不要なので fork からの PR でも動く。

name: API Inventory Tests

# 対象は tools/api-inventory/ だけなので、そこを触ったときだけ回す。
# push と pull_request でパスの並びを揃えること(片方だけ古びると、
# 「PR では回るが push では回らない」といった説明のつかない差になる)。
on:
pull_request:
paths: &paths
- 'tools/api-inventory/**'
- '.github/workflows/api-inventory-tests.yml'
- '.github/workflows/api-inventory-drift.yml'
push:
branches: ['**']
paths: *paths
workflow_dispatch:

jobs:
unit:
runs-on: ubuntu-latest
timeout-minutes: 10
steps:
- uses: actions/checkout@v4

- uses: actions/setup-python@v5
with:
python-version: '3.11'

- name: Install pytest
run: python3 -m pip install --disable-pip-version-check pytest

- name: Run unit tests
working-directory: tools/api-inventory
run: python3 -m pytest -q

# 台帳が無くても、ソースからの経路検知そのものは動く。
# 検知件数が 0 に落ちていれば、検知器が壊れている。
- name: Smoke check the static detector
run: |
set -o pipefail
python3 tools/api-inventory/scripts/detect_routes.py \
--weko-root "$PWD" --summary-only | tee /tmp/detect.md
python3 - <<'PY'
import re, sys
text = open('/tmp/detect.md', encoding='utf-8').read()
total = int(re.search(r'\*\*計\*\* \| \*\*(\d+)\*\*', text).group(1))
print(f'detections={total}')
# 経路が数百ある前提のリポジトリ。2桁に落ちたら検知器の故障を疑う。
sys.exit(0 if total >= 300 else 1)
PY
Loading
Loading