collin/anvil · 21f74794
Create the admin cache table under the name Toasty queries
Collin Richards · 2026-08-18 14:40 UTC · 21f74794eb6ddf38f223f63f7f573f69e138ff8b · parent 18e442f7 · browse files
modifiedcrates/anvil-core/src/db.rs+6 −1
| ⋯ 137 unchanged lines | |||
| 138 | 138 | "created_at" BIGINT NOT NULL, | |
| 139 | 139 | "updated_at" BIGINT NOT NULL )"#; | |
| 140 | 140 | ||
| 141 | - | const ADMIN_CACHE_DDL: &str = r#"CREATE TABLE IF NOT EXISTS "admin_cache" ( | |
| 141 | + | // `admin_caches`, plural, is what Toasty names the `AdminCache` model's table. | |
| 142 | + | // This shim said `admin_cache` for its whole life, so every database created | |
| 143 | + | // before the model existed was missing the table the code actually queries, and | |
| 144 | + | // each disk-usage refresh panicked its worker. `SHIMMED_TABLES` now covers it. | |
| 145 | + | const ADMIN_CACHE_DDL: &str = r#"CREATE TABLE IF NOT EXISTS "admin_caches" ( | |
| 142 | 146 | "id" INTEGER NOT NULL PRIMARY KEY AUTOINCREMENT, | |
| 143 | 147 | "key" TEXT NOT NULL, | |
| 144 | 148 | "value" TEXT NOT NULL, | |
| ⋯ 69 unchanged lines | |||
| 214 | 218 | "issue_comments", | |
| 215 | 219 | "attachments", | |
| 216 | 220 | "api_tokens", | |
| 221 | + | "admin_caches", | |
| 217 | 222 | "repo_secrets", | |
| 218 | 223 | ]; | |
| 219 | 224 | ||
| ⋯ 130 unchanged lines | |||
modifieddeploy/run.sh+19 −4
| ⋯ 18 unchanged lines | |||
| 19 | 19 | SOCK_GID="$(stat -c '%g' "$DOCKER_SOCK")" | |
| 20 | 20 | ||
| 21 | 21 | # Single sign-on's client secret, if this instance uses one (docs/oidc.md). | |
| 22 | - | # Passed only when set: an empty value would override the config file with | |
| 23 | - | # "no secret" and turn a confidential client into a public one. | |
| 22 | + | # | |
| 23 | + | # Read from a file on the host by default, because deploy/deploy.sh pipes this | |
| 24 | + | # script over ssh (`ssh host 'bash -s' < run.sh`) and no environment travels | |
| 25 | + | # with it — an env var alone would silently vanish on exactly the path that | |
| 26 | + | # matters. ANVIL_OIDC_CLIENT_SECRET still wins when running this by hand. | |
| 27 | + | # | |
| 28 | + | # Passed only when non-empty: an empty value would override the baked config | |
| 29 | + | # with "no secret" and turn a confidential client into a public one. | |
| 30 | + | OIDC_SECRET_FILE="${ANVIL_OIDC_SECRET_FILE:-$HOME/.config/anvil/oidc-client-secret}" | |
| 31 | + | OIDC_SECRET="${ANVIL_OIDC_CLIENT_SECRET:-}" | |
| 32 | + | if [[ -z "$OIDC_SECRET" && -r "$OIDC_SECRET_FILE" ]]; then | |
| 33 | + | OIDC_SECRET="$(tr -d '[:space:]' <"$OIDC_SECRET_FILE")" | |
| 34 | + | fi | |
| 35 | + | ||
| 24 | 36 | OIDC_ENV=() | |
| 25 | - | if [[ -n "${ANVIL_OIDC_CLIENT_SECRET:-}" ]]; then | |
| 26 | - | OIDC_ENV=(-e "ANVIL_OIDC_CLIENT_SECRET=${ANVIL_OIDC_CLIENT_SECRET}") | |
| 37 | + | if [[ -n "$OIDC_SECRET" ]]; then | |
| 38 | + | OIDC_ENV=(-e "ANVIL_OIDC_CLIENT_SECRET=${OIDC_SECRET}") | |
| 39 | + | echo "==> single sign-on: client secret loaded" | |
| 40 | + | else | |
| 41 | + | echo "==> single sign-on: no client secret found (${OIDC_SECRET_FILE})" | |
| 27 | 42 | fi | |
| 28 | 43 | ||
| 29 | 44 | docker rm -f anvil 2>/dev/null || true | |
| ⋯ 12 unchanged lines | |||