view libervia/backend/plugins/plugin_app_manager_docker/libervia_app_weblate.yaml @ 4212:5f2d496c633f

core: get rid of `pickle`: Use of `pickle` to serialise data was a technical legacy that was causing trouble to store in database, to update (if a class was serialised, a change could break update), and to security (pickle can lead to code execution). This patch remove all use of Pickle in favour in JSON, notably: - for caching data, a Pydantic model is now used instead - for SQLAlchemy model, the LegacyPickle is replaced by JSON serialisation - in XEP-0373 a class `PublicKeyMetadata` was serialised. New method `from_dict` and `to_dict` method have been implemented to do serialisation. - new methods to (de)serialise data can now be specified with Identity data types. It is notably used to (de)serialise `path` of avatars. A migration script has been created to convert data (for upgrade or downgrade), with special care for XEP-0373 case. Depending of size of database, this migration script can be long to run. rel 443
author Goffi <goffi@goffi.org>
date Fri, 23 Feb 2024 13:31:04 +0100
parents c93b02000ae4
children 4aa62767f501
line wrap: on
line source

type: docker-compose
prepare:
  git: https://github.com/WeblateOrg/docker-compose.git
files:
  settings-override.py:
    content: |
      USE_X_FORWARDED_HOST = True
override:
  version: "3"
  services:
    weblate:
      ports:
        - "8080"
      environment:
        WEBLATE_DEBUG: 0
        WEBLATE_URL_PREFIX: !libervia_param [url_prefix, /weblate]
        WEBLATE_EMAIL_HOST: !libervia_conf ["", "email_server"]
        WEBLATE_EMAIL_HOST_USER: !libervia_conf ["", "email_username"]
        WEBLATE_EMAIL_HOST_PASSWORD: !libervia_conf ["", "email_password"]
        WEBLATE_SERVER_EMAIL: !libervia_conf ["", "email_from", "weblate@example.com"]
        WEBLATE_DEFAULT_FROM_EMAIL: !libervia_conf ["", "email_from", "weblate@example.com"]
        WEBLATE_SITE_DOMAIN: !libervia_conf ["", "public_url"]
        WEBLATE_ADMIN_PASSWORD: !libervia_generate_pwd
        WEBLATE_ADMIN_EMAIL: !libervia_conf ["", "email_admins_list", "", "first"]
        WEBLATE_ENABLE_HTTPS: !libervia_conf ["", "weblate_enable_https", "1"]
      volumes:
        - ./settings-override.py:/app/data/settings-override.py:ro
expose:
  url_prefix: [override, services, weblate, environment, WEBLATE_URL_PREFIX]
  front_url: !libervia_param [front_url, /translate]
  web_label: Translate
  ports:
    web:
      service: weblate
      private: 8080
  passwords:
    admin: [override, services, weblate, environment, WEBLATE_ADMIN_PASSWORD]