Skip to content

refactor: remove OIDC discovery cache and support HS256 - #896

Merged
arabcoders merged 6 commits into
masterfrom
dev
Sep 28, 2026
Merged

arabcoders merged 6 commits into
masterfrom
dev

Conversation

@arabcoders

Copy link
Copy Markdown
Owner

This pull request introduces several improvements and changes to configuration, OIDC authentication, and CI workflow. The most significant updates are the switch to integer-based log and backup retention settings, expanded OIDC algorithm support (including HS256 with stricter secret validation), and enhancements to the build pipeline for better artifact handling and Docker caching.

Configuration and Retention Policy Changes:

  • Changed WS_LOGS_PRUNE_AFTER from a relative time string (e.g., "-7 DAYS") to an integer number of days (minimum 1), and introduced WS_BACKUP_PRUNE_AFTER for backup retention (must be greater than 7 days). The corresponding config validation and usage logic were updated in config/config.php, config/env.spec.php, and src/Libs/Prune/FilePruner.php. [1] [2] [3] [4] [5]

OIDC Authentication Improvements:

  • Added support for HS256-signed OIDC ID tokens in src/Libs/OidcService.php, with enforcement of a minimum 32-byte client secret for HS256. Documentation was updated to reflect supported algorithms and provide guidance for HS256 usage. [1] [2] [3] [4] [5]

CI/CD Workflow Enhancements:

  • Updated .github/workflows/build.yml to add a container for the test job, include the redis PHP extension, improve Python setup and script execution, and handle frontend build artifact upload/download for both GitHub and Gitea. [1] [2] [3] [4] [5]
  • Improved Docker build caching by scoping to container-${{ github.ref_name }}-${{ env.ARCH }} for both AMD64 and ARM64 builds. [1] [2]

Other Technical Fixes:

  • Escaped branch names for use in sed replacements during Docker build, ensuring correct version metadata injection. [1] [2] [3] [4]
  • Removed unused OIDC discovery cache logic for simplification.

These changes improve reliability, clarity, and maintainability across configuration, authentication, and CI/CD processes.

arabcoders and others added 6 commits September 18, 2026 18:49
Follow up to #886. Plex and jellyfin both document a range as sXXeYY-eZZ, so a
bare number is only taken after a hyphen. S01E01.50, S01E01.2.0 and S01E01_02
are release tags now, not ranges. An E prefix is still honoured after any
separator, so S01E01-E02, S01E01.S01E02 and E1001-E1002 keep working.

Fixes names such as s05e07.10.chefs.compete.avi, where the episode title starts
with a number. That parsed as episodes 7-10, which fits under the range limit,
so the importer silently fabricated three episodes that do not exist.
Hoisting the tail shapes stopped one step short. Three things still restated
what the tails had already decided.
fix: only treat the documented episode range syntax as a range
@arabcoders arabcoders linked an issue Sep 28, 2026 that may be closed by this pull request
@arabcoders
arabcoders merged commit 7034ac5 into master Sep 28, 2026
12 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] Wrong OIDC configuration gets cached unnecessarily

2 participants