mirror of
https://github.com/MacRimi/ProxMenux.git
synced 2026-10-02 03:29:12 +00:00
feat(oci): run official container images as native LXC containers
Adds the OCI manager: an engine that turns a Docker Compose file into an LXC definition, a catalog of 365 applications drawn from LinuxServer.io and other container image sources, and a per-instance registry recording what each container was built from. Reachable from the main menu. Catalog text is translated like every other string in the project: the taglines go through translate() and land in lang/*.json, so the entries read in all eight languages instead of only English. Translation cache builder: - a failed translation leaves the key absent rather than writing English, which previously made the string count as translated forever - a result identical to a 3+ word source is rejected, catching a provider that silently returns the text it was given - strings that are nothing but glossary terms keep their source spelling instead of being discarded as failures - no backoff between attempts when the provider is deterministic - application names are protected so "HAOS One" survives translation - argos joins the provider list, and the workflow reads the OCI sources Audit & Report: - findings that moved in the wrong direction between runs are reported alongside the ones that improved - an accepted risk can carry a review date and is flagged when it falls due - backup checks explain in plain language what they looked at and what to do next Monitor: - disks can be excluded from periodic reads, and an idle disk says so instead of showing a stale temperature - per-disk identity survives a controller or enclosure change - scheduled Borg backups resolve their SSH key from the repository entry - PVE upgrades log the package list and the resulting dpkg changes The web build no longer copies scripts/ into public/: the documentation links to GitHub, so nothing read that folder. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -309,22 +309,29 @@ def accept_exception():
|
||||
finding.get('incomplete') or not finding.get('scope')):
|
||||
return jsonify(success=False, message="This finding cannot be accepted"), 400
|
||||
|
||||
expires_at = None
|
||||
days = data.get('expires_in_days')
|
||||
if days is not None:
|
||||
try:
|
||||
if isinstance(days, bool) or int(days) != float(days) or not 1 <= int(days) <= 3650:
|
||||
raise ValueError("invalid expiry")
|
||||
expires_at = int(time.time()) + int(days) * 86400
|
||||
except (TypeError, ValueError):
|
||||
return jsonify({"success": False,
|
||||
"message": "Invalid expiry"}), 400
|
||||
def _in_days(value, label):
|
||||
"""A day count from now, or None. Same bounds as the expiry so a
|
||||
reminder cannot be set further out than a decision can last."""
|
||||
if value is None:
|
||||
return None
|
||||
if isinstance(value, bool) or int(value) != float(value) or not 1 <= int(value) <= 3650:
|
||||
raise ValueError(f"invalid {label}")
|
||||
return int(time.time()) + int(value) * 86400
|
||||
|
||||
try:
|
||||
expires_at = _in_days(data.get('expires_in_days'), 'expiry')
|
||||
# Independent of the expiry: it brings the decision back to the
|
||||
# reader on that date without withdrawing it.
|
||||
review_at = _in_days(data.get('review_in_days'), 'review date')
|
||||
except (TypeError, ValueError) as e:
|
||||
return jsonify({"success": False, "message": str(e)}), 400
|
||||
|
||||
audit_store.accept_risk(
|
||||
check_id, reason,
|
||||
accepted_by=_actor(),
|
||||
expires_at=expires_at,
|
||||
scope=finding['scope'],
|
||||
review_at=review_at,
|
||||
)
|
||||
return jsonify({"success": True})
|
||||
except ValueError as e:
|
||||
|
||||
Reference in New Issue
Block a user