anvilsign in

collin/anvil · 21f74794

Create the admin cache table under the name Toasty queries

Collin Richards · 2026-08-18 14:40 UTC · 21f74794eb6ddf38f223f63f7f573f69e138ff8b · parent 18e442f7 · browse files

modifiedcrates/anvil-core/src/db.rs+6 −1
⋯ 137 unchanged lines
138138 "created_at" BIGINT NOT NULL,
139139 "updated_at" BIGINT NOT NULL )"#;
140140
141-const ADMIN_CACHE_DDL: &str = r#"CREATE TABLE IF NOT EXISTS "admin_cache" (
141+// `admin_caches`, plural, is what Toasty names the `AdminCache` model's table.
142+// This shim said `admin_cache` for its whole life, so every database created
143+// before the model existed was missing the table the code actually queries, and
144+// each disk-usage refresh panicked its worker. `SHIMMED_TABLES` now covers it.
145+const ADMIN_CACHE_DDL: &str = r#"CREATE TABLE IF NOT EXISTS "admin_caches" (
142146 "id" INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT,
143147 "key" TEXT NOT NULL,
144148 "value" TEXT NOT NULL,
⋯ 69 unchanged lines
214218 "issue_comments",
215219 "attachments",
216220 "api_tokens",
221+ "admin_caches",
217222 "repo_secrets",
218223 ];
219224
⋯ 130 unchanged lines
modifieddeploy/run.sh+19 −4
⋯ 18 unchanged lines
1919 SOCK_GID="$(stat -c '%g' "$DOCKER_SOCK")"
2020
2121 # Single sign-on's client secret, if this instance uses one (docs/oidc.md).
22-# Passed only when set: an empty value would override the config file with
23-# "no secret" and turn a confidential client into a public one.
22+#
23+# Read from a file on the host by default, because deploy/deploy.sh pipes this
24+# script over ssh (`ssh host 'bash -s' < run.sh`) and no environment travels
25+# with it — an env var alone would silently vanish on exactly the path that
26+# matters. ANVIL_OIDC_CLIENT_SECRET still wins when running this by hand.
27+#
28+# Passed only when non-empty: an empty value would override the baked config
29+# with "no secret" and turn a confidential client into a public one.
30+OIDC_SECRET_FILE="${ANVIL_OIDC_SECRET_FILE:-$HOME/.config/anvil/oidc-client-secret}"
31+OIDC_SECRET="${ANVIL_OIDC_CLIENT_SECRET:-}"
32+if [[ -z "$OIDC_SECRET" && -r "$OIDC_SECRET_FILE" ]]; then
33+ OIDC_SECRET="$(tr -d '[:space:]' <"$OIDC_SECRET_FILE")"
34+fi
35+
2436 OIDC_ENV=()
25-if [[ -n "${ANVIL_OIDC_CLIENT_SECRET:-}" ]]; then
26- OIDC_ENV=(-e "ANVIL_OIDC_CLIENT_SECRET=${ANVIL_OIDC_CLIENT_SECRET}")
37+if [[ -n "$OIDC_SECRET" ]]; then
38+ OIDC_ENV=(-e "ANVIL_OIDC_CLIENT_SECRET=${OIDC_SECRET}")
39+ echo "==> single sign-on: client secret loaded"
40+else
41+ echo "==> single sign-on: no client secret found (${OIDC_SECRET_FILE})"
2742 fi
2843
2944 docker rm -f anvil 2>/dev/null || true
⋯ 12 unchanged lines