Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
24 commits
Select commit Hold shift + click to select a range
8aece0a
chore(docker): restructure Dockerfile and helper scripts
floriancerizay Sep 14, 2026
373918d
chore(deps): upgrade to PHP 8.5, Symfony 7.4, Doctrine ORM 3 and JMS …
floriancerizay Sep 14, 2026
fa67072
chore(frontend): bump validator-api-client to v0.5.9 and rebuild assets
floriancerizay Sep 14, 2026
cea6fd2
feat(validation): expose document-info.json produced by the validator
floriancerizay Sep 14, 2026
a9ac1d8
fix(quality): resolve phpmd findings across the codebase (missing imp…
floriancerizay Sep 14, 2026
1f26303
refactor(api): split file-serving endpoints out of ValidationsController
floriancerizay Sep 14, 2026
c7ec4f8
refactor(validation): extract ValidationWorkspace from ValidationManager
floriancerizay Sep 14, 2026
cecf241
fix(demo): load runtime/vendors chunks for the code-split validator-c…
floriancerizay Sep 14, 2026
5f91c05
feat(security): disable source and normalized data downloads by defau…
floriancerizay Oct 1, 2026
9a1e1de
feat(security): validate zip archives before and during extraction
floriancerizay Oct 1, 2026
3efeaee
feat(api): flag disabled download routes in the OpenAPI specification
floriancerizay Oct 1, 2026
814b749
build(docker): install validator-cli.jar with checksum (bin/install-v…
floriancerizay Oct 1, 2026
9a1ea5a
fix(security): validate dataset name, restrict model url (SSRF), hard…
floriancerizay Oct 1, 2026
a4bf07c
fix(report): generate PDF report with dompdf instead of wkhtmltopdf
floriancerizay Oct 1, 2026
07808a9
build: build front assets in Dockerfile, fix docker-compose and scrip…
floriancerizay Oct 2, 2026
ed697da
feat(security): add rate limiting and security headers, version lock …
floriancerizay Oct 2, 2026
951dda8
feat(report): printable HTML report saved to PDF by the browser
floriancerizay Oct 2, 2026
6eb5ec3
feat(logs): log client IP from X-Forwarded-For and add audit channel
floriancerizay Oct 2, 2026
351e6b0
refactor: manage database with Doctrine migrations, type Validation e…
floriancerizay Oct 2, 2026
1ba4556
docs(api): update OpenAPI specification
floriancerizay Oct 2, 2026
5a7614b
chore(deps): bump validator-api-client to v0.6.0
floriancerizay Oct 2, 2026
b93a1db
style: fix coding style
floriancerizay Oct 2, 2026
c24373d
chore(deps): update lock files
floriancerizay Oct 2, 2026
29e37be
fix(demo): load the single validator-client bundle (v0.6.0).
floriancerizay Oct 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
145 changes: 0 additions & 145 deletions .docker/Dockerfile

This file was deleted.

10 changes: 9 additions & 1 deletion .docker/apache-vhost.conf
Original file line number Diff line number Diff line change
Expand Up @@ -9,6 +9,14 @@
Require all granted
</Directory>

# Client IP read from X-Forwarded-For when the request comes from a reverse proxy
# (ingress, traefik) on a private network, same ranges as TRUSTED_PROXIES=PRIVATE_SUBNETS.
RemoteIPHeader X-Forwarded-For
RemoteIPInternalProxy 127.0.0.0/8 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 169.254.0.0/16 ::1 fc00::/7 fe80::/10

# "combined" with the client IP (%a, set by mod_remoteip) instead of the proxy IP (%h)
LogFormat "%a %l %u %t \"%r\" %>s %O \"%{Referer}i\" \"%{User-Agent}i\"" combined_client_ip

ErrorLog ${APACHE_LOG_DIR}/error.log
CustomLog ${APACHE_LOG_DIR}/access.log combined
CustomLog ${APACHE_LOG_DIR}/access.log combined_client_ip
</VirtualHost>
7 changes: 7 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
Expand Up @@ -4,3 +4,10 @@ var
/node_modules/

/.env.*

# front assets are built in the Dockerfile
/public/build/
/public/vendor/
/public/css/
/public/font/
/public/img/
9 changes: 9 additions & 0 deletions .env
Original file line number Diff line number Diff line change
Expand Up @@ -19,6 +19,15 @@
VALIDATOR_PATH=%kernel.project_dir%/bin/validator-cli.jar
VALIDATOR_JAVA_OPTS='-Xms256m -Xmx2g'
DATA_DIR=%kernel.project_dir%/var/data
# Allow download of source and normalized data (/api/validations/{uid}/files/*), disabled by default for security reasons
DATA_DOWNLOAD_ENABLED=0
# Hosts (comma separated, subdomains included) allowed for the "model" argument (https only)
VALIDATOR_MODEL_ALLOWED_HOSTS=geoportail-urbanisme.gouv.fr,ignf.github.io
# Max number of validations created or updated per hour and per client IP
VALIDATION_RATE_LIMIT=100
# Reverse proxies (ex : PRIVATE_SUBNETS, REMOTE_ADDR, 10.0.0.0/8) whose X-Forwarded-For is trusted to get the client IP
# (required behind an ingress / traefik, otherwise all the clients share the rate limit of the proxy IP)
TRUSTED_PROXIES=PRIVATE_SUBNETS

#---------------------------------------------
# docker defaults
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/docker-publish.yml
Original file line number Diff line number Diff line change
Expand Up @@ -61,7 +61,7 @@ jobs:
uses: docker/build-push-action@v3
with:
context: .
file: .docker/Dockerfile
file: Dockerfile
push: ${{ github.event_name != 'pull_request' }}
tags: ${{ steps.meta.outputs.tags }}
labels: ${{ steps.meta.outputs.labels }}
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/php-ci.yml
Original file line number Diff line number Diff line change
Expand Up @@ -14,7 +14,7 @@ jobs:

strategy:
matrix:
php-version: [8.3]
php-version: [8.5]

runs-on: ubuntu-latest

Expand Down Expand Up @@ -65,7 +65,7 @@ jobs:
DATABASE_URL: postgresql://postgres:postgres@localhost:5432/validator_api?serverVersion=14&charset=utf8

- name: Upload coverage results to coveralls.io
if: github.ref == 'refs/heads/master' && matrix.php-version == '8.3'
if: github.ref == 'refs/heads/master' && matrix.php-version == '8.5'
run: |
vendor/bin/php-coveralls --coverage_clover=var/data/output/coverage.xml --json_path=var/data/output/coveralls.json -v
env:
Expand Down
11 changes: 7 additions & 4 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -18,16 +18,12 @@ validator-debug.log
/nbproject/

/tests/TempData/*
/*.lock
/package-lock.json

/.idea
/.vscode

validator-cli.jar

.scannerwork
sonar-scanner
node_modules

/output/
Expand All @@ -45,3 +41,10 @@ node_modules
/phpunit.xml
.phpunit.result.cache
###< phpunit/phpunit ###

# front assets built by webpack (npm ci && npm run build), see webpack.config.js
/public/build/
/public/vendor/
/public/css/
/public/font/
/public/img/
Loading
Loading