Repository navigation
Upgrade Executor to v1.6.10 - #4
Merged
Merged
Conversation
v1.6.10 retries an OAuth refresh without `scope` when the authorization server answers invalid_scope (UsefulSoftwareCo/executor#1982). Everhour refuses our v1.6.8 refreshes that way, so every Everhour connection stops working once its first access token expires. Matches upstream's self-host build: Bun is pinned to 1.3.11 and the build stage gets python3, make and g++. Upstream's runtime image now also runs as UID 65532; that isn't adopted here because our existing /data volume is owned by root.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Bumps the upstream Executor version from v1.6.8 to v1.6.10.
Why
Everhour refuses Executor's token refreshes with
invalid_scope, because v1.6.8 re-sends the recorded scope on every refresh. Each Everhour connection stops working once its first access token expires. v1.6.10 includes UsefulSoftwareCo/executor#1982, which retries the refresh once withoutscopewhen it's refused that way.Changes
EXECUTOR_VERSIONis nowv1.6.10.1.3.11by digest, and the build stage installspython3,makeandg++, matching upstream's self-host Dockerfile in this release.v1.6.10-bnb.1.Upstream's runtime image now runs as UID
65532. That isn't adopted here: our/datavolume was written by the root-running image, and switching would need its ownership changed first.Testing
Built the
runtimetarget locally and ran it with an empty data directory. It started with the 1Password plugin loaded, and/api/healthand/api/setup-statusreturned 200.After merging
Tag
v1.6.10-bnb.1to deploy, then reconnect Everhour once. The current connection's refresh has already been refused.