feat(chart): add security, scheduling, and network policy support - #912
Closed
bl4ko wants to merge 3 commits into
Closed
feat(chart): add security, scheduling, and network policy support#912bl4ko wants to merge 3 commits into
bl4ko wants to merge 3 commits into
Conversation
* chore: bump version to 3.0.0 [skip ci] * fix: resolve dead wiki links across install and config pages * fix(reservations): restore correct day assignment for non-transport bookings v3.0.0 switched the planner from rendering reservations by reservation_time to rendering them by day_id (commit 3f61e1c), but migration 110 only backfilled day_id for transport types. Tours, restaurants, events and 'other' bookings kept whatever day_id was stored in the DB — often the trip's first day, from older code paths that defaulted it there — so after the upgrade those rows all show up on day 1 regardless of their actual reservation_time. - Migration 122: for every non-hotel reservation, null out any day_id / end_day_id that does not match the reservation's time, then backfill it from reservation_time / reservation_end_time. Idempotent; leaves already-correct rows alone. - reservationService.createReservation / updateReservation now derive day_id / end_day_id from reservation_time / reservation_end_time when the client didn't send one explicitly, so the mismatch cannot reappear on new or edited bookings. Hotels are skipped because they store their date range on the linked day_accommodation. * chore: bump version to 3.0.1 [skip ci] * fix(oidc): normalize discovery doc issuer before comparison Trailing slash in doc.issuer (e.g. Authentik) caused a mismatch against the already-normalized configured issuer, breaking OIDC login entirely. Closes liketrek#834 * test(systemNotices): exclude v3 upgrade notices from login_count-only tests Tests that expect an empty notice list were using first_seen_version='0.0.0' (DB default), which matches the existingUserBeforeVersion('3.0.0') condition now that the app is at 3.0.1. Set first_seen_version='3.0.0' so only the firstLogin condition controls visibility in these tests. * chore: bump version to 3.0.2 [skip ci] * fix(oidc): normalize id_token iss claim before issuer comparison (liketrek#837) jwt.verify does an exact string match on the issuer. Providers like Authentik include a trailing slash in the id_token iss claim while the configured issuer is already normalized (no trailing slash), causing every login attempt to fail with jwt issuer invalid. Move the issuer check out of jwt.verify options and apply the same trailing-slash normalization used in the discovery doc validation. Also adds OIDC-SVC-033–036 unit tests covering exact match, trailing slash, wrong issuer, and wrong audience cases. Closes liketrek#834 * chore: bump version to 3.0.3 [skip ci] * fix(oidc,ui): restore Authentik login and fix mobile delete dialog (liketrek#845) OIDC: when OIDC_DISCOVERY_URL is explicitly set, trust the discovery doc's issuer for id_token comparison instead of rejecting a path mismatch as an error. Authentik (and similar realm-path providers) return a canonical issuer like /application/o/<slug>/ that differs from the operator's base OIDC_ISSUER. Strict equality blocked login in 3.x despite working in v2. Default discovery (no custom URL) keeps the strict check. Adds OIDC-SVC-037/038/039. UI: ConfirmDialog and CopyTripDialog lacked the --bottom-nav-h paddingBottom offset that other overlays already use. On mobile portrait the action buttons were hidden behind the sticky bottom nav bar. Closes liketrek#843 Closes liketrek#844 * chore: bump version to 3.0.4 [skip ci] * fix(files): open attachments only in new tab (liketrek#840) window.open with noreferrer returns null, which triggered the popup-blocked download fallback in addition to the new-tab open. Use a target=_blank anchor click instead. * chore: bump version to 3.0.5 [skip ci] * fix(journey,pdf): journey reorder sort_order + PDF multi-day transport (liketrek#848) * fix(journey): make sort_order authoritative for within-day entry ordering Reorder buttons appeared broken because the server ORDER BY put entry_time before sort_order, so entries synced from trip places with differing times would always sort by time regardless of sort_order writes. The client store mirrored the same comparator, making even the optimistic update invisible. - Change ORDER BY to (entry_date, sort_order, id) in getJourneyFull and listEntries - Fix syncTripPlaces and onPlaceCreated to assign MAX+1 sort_order per day instead of day_number/0 - Update client store comparator to match - Add DB migration to backfill sort_order using old effective key (entry_time, id) so existing journeys retain their visual order - Add tests: JOURNEY-SVC-089–093, FE-STORE-JOURNEY-018–019 Closes liketrek#846 * fix(pdf): include multi-day transport return/arrival in PDF itinerary (liketrek#847) Reservations were matched to days by pickup date only, so the end-day card (e.g. car Return, flight Arrival) was silently dropped from the PDF. Add span-aware helpers mirroring DayPlanSidebar logic: match by day_id/end_day_id span, show reservation_end_time on end days, prefix title with phase label (Return/Arrival/etc.), and use per-day position for sort order. * test(pdf): add missing day_id to transport reservation fixture * chore: bump version to 3.0.6 [skip ci] * [Snyk] Security upgrade uuid from 9.0.1 to 14.0.0 (liketrek#849) * fix: server/package.json & server/package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-UUID-16133035 * fix: bump fast-xml-parser version --------- Co-authored-by: snyk-bot <snyk-bot@snyk.io> Co-authored-by: jubnl <jgunther021@gmail.com> * chore: bump version to 3.0.7 [skip ci] * fix: hot fixes 23-04-2026 (liketrek#856) * fix(packing): resolve avatar URL path in bag and category assignees (liketrek#854) packingService was returning raw avatar filenames from the DB instead of the full /uploads/avatars/<filename> path, causing broken profile images for users with uploaded avatars. * fix(budget): use Map.get() to fix category rename no-op (liketrek#855) * fix(security): relax Referrer-Policy and document HSTS_INCLUDE_SUBDOMAINS (liketrek#862) (liketrek#863) - Change Helmet default from no-referrer to strict-origin-when-cross-origin so browsers send the origin on cross-origin requests, allowing Google Maps API key restrictions by HTTP referrer to work correctly - Document HSTS_INCLUDE_SUBDOMAINS in all deployment artifacts: .env.example, docker-compose.yml, README.md, unraid-template.xml, charts/values.yaml, charts/configmap.yaml, wiki/Environment-Variables.md * fix(planner): prefetch budget items on trip page mount (liketrek#864) Loads budgetItems alongside reservations when TripPlannerPage mounts so the Budget category dropdown in ReservationModal and TransportModal shows pre-existing categories on first open, regardless of whether the Budget tab has been visited. Closes liketrek#861 * fix(reservations): prevent Invalid Date when end time is set without end date (liketrek#866) When reservation_end_time held a bare time string ("HH:MM"), fmtDate() produced Invalid Date on the reservation card. - Modal: when end date is blank but end time is filled, construct a same-day ISO datetime using the start date (prevents time-only strings from ever being persisted) - Panel: derive endDatePart via regex so date-only end values ("YYYY-MM-DD") still show the multi-day range, while bare time strings are skipped and handled correctly by the existing time column logic Closes liketrek#860 * fix(planner): format reservation end time instead of rendering raw ISO string (liketrek#867) Closes liketrek#859 * fix(planner): wire Route toggle into mobile day sidebar (liketrek#850) (liketrek#868) The per-booking Route icon was missing on mobile because the mobile DayPlanSidebar invocation in TripPlannerPage didn't pass visibleConnectionIds or onToggleConnection. Mobile PWA users couldn't activate reservation map overlays without forcing desktop mode. Also corrects the Map-Features wiki: fixes the setting name ("Booking route labels" not "Show connection labels"), documents the route_calculation requirement for travel-time pills, and explains that overlays are off by default and must be toggled per reservation. * chore: bump version to 3.0.8 [skip ci] --------- Co-authored-by: Maurice <61554723+mauriceboe@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Maurice <mauriceboe@icloud.com> Co-authored-by: Xre0uS <36565320+Xre0uS@users.noreply.github.com> Co-authored-by: snyk-bot <snyk-bot@snyk.io>
* chore: bump version to 3.0.0 [skip ci] * fix: resolve dead wiki links across install and config pages * fix(reservations): restore correct day assignment for non-transport bookings v3.0.0 switched the planner from rendering reservations by reservation_time to rendering them by day_id (commit 3f61e1c), but migration 110 only backfilled day_id for transport types. Tours, restaurants, events and 'other' bookings kept whatever day_id was stored in the DB — often the trip's first day, from older code paths that defaulted it there — so after the upgrade those rows all show up on day 1 regardless of their actual reservation_time. - Migration 122: for every non-hotel reservation, null out any day_id / end_day_id that does not match the reservation's time, then backfill it from reservation_time / reservation_end_time. Idempotent; leaves already-correct rows alone. - reservationService.createReservation / updateReservation now derive day_id / end_day_id from reservation_time / reservation_end_time when the client didn't send one explicitly, so the mismatch cannot reappear on new or edited bookings. Hotels are skipped because they store their date range on the linked day_accommodation. * chore: bump version to 3.0.1 [skip ci] * fix(oidc): normalize discovery doc issuer before comparison Trailing slash in doc.issuer (e.g. Authentik) caused a mismatch against the already-normalized configured issuer, breaking OIDC login entirely. Closes liketrek#834 * test(systemNotices): exclude v3 upgrade notices from login_count-only tests Tests that expect an empty notice list were using first_seen_version='0.0.0' (DB default), which matches the existingUserBeforeVersion('3.0.0') condition now that the app is at 3.0.1. Set first_seen_version='3.0.0' so only the firstLogin condition controls visibility in these tests. * chore: bump version to 3.0.2 [skip ci] * fix(oidc): normalize id_token iss claim before issuer comparison (liketrek#837) jwt.verify does an exact string match on the issuer. Providers like Authentik include a trailing slash in the id_token iss claim while the configured issuer is already normalized (no trailing slash), causing every login attempt to fail with jwt issuer invalid. Move the issuer check out of jwt.verify options and apply the same trailing-slash normalization used in the discovery doc validation. Also adds OIDC-SVC-033–036 unit tests covering exact match, trailing slash, wrong issuer, and wrong audience cases. Closes liketrek#834 * chore: bump version to 3.0.3 [skip ci] * fix(oidc,ui): restore Authentik login and fix mobile delete dialog (liketrek#845) OIDC: when OIDC_DISCOVERY_URL is explicitly set, trust the discovery doc's issuer for id_token comparison instead of rejecting a path mismatch as an error. Authentik (and similar realm-path providers) return a canonical issuer like /application/o/<slug>/ that differs from the operator's base OIDC_ISSUER. Strict equality blocked login in 3.x despite working in v2. Default discovery (no custom URL) keeps the strict check. Adds OIDC-SVC-037/038/039. UI: ConfirmDialog and CopyTripDialog lacked the --bottom-nav-h paddingBottom offset that other overlays already use. On mobile portrait the action buttons were hidden behind the sticky bottom nav bar. Closes liketrek#843 Closes liketrek#844 * chore: bump version to 3.0.4 [skip ci] * fix(files): open attachments only in new tab (liketrek#840) window.open with noreferrer returns null, which triggered the popup-blocked download fallback in addition to the new-tab open. Use a target=_blank anchor click instead. * chore: bump version to 3.0.5 [skip ci] * fix(journey,pdf): journey reorder sort_order + PDF multi-day transport (liketrek#848) * fix(journey): make sort_order authoritative for within-day entry ordering Reorder buttons appeared broken because the server ORDER BY put entry_time before sort_order, so entries synced from trip places with differing times would always sort by time regardless of sort_order writes. The client store mirrored the same comparator, making even the optimistic update invisible. - Change ORDER BY to (entry_date, sort_order, id) in getJourneyFull and listEntries - Fix syncTripPlaces and onPlaceCreated to assign MAX+1 sort_order per day instead of day_number/0 - Update client store comparator to match - Add DB migration to backfill sort_order using old effective key (entry_time, id) so existing journeys retain their visual order - Add tests: JOURNEY-SVC-089–093, FE-STORE-JOURNEY-018–019 Closes liketrek#846 * fix(pdf): include multi-day transport return/arrival in PDF itinerary (liketrek#847) Reservations were matched to days by pickup date only, so the end-day card (e.g. car Return, flight Arrival) was silently dropped from the PDF. Add span-aware helpers mirroring DayPlanSidebar logic: match by day_id/end_day_id span, show reservation_end_time on end days, prefix title with phase label (Return/Arrival/etc.), and use per-day position for sort order. * test(pdf): add missing day_id to transport reservation fixture * chore: bump version to 3.0.6 [skip ci] * [Snyk] Security upgrade uuid from 9.0.1 to 14.0.0 (liketrek#849) * fix: server/package.json & server/package-lock.json to reduce vulnerabilities The following vulnerabilities are fixed with an upgrade: - https://snyk.io/vuln/SNYK-JS-UUID-16133035 * fix: bump fast-xml-parser version --------- Co-authored-by: snyk-bot <snyk-bot@snyk.io> Co-authored-by: jubnl <jgunther021@gmail.com> * chore: bump version to 3.0.7 [skip ci] * fix: hot fixes 23-04-2026 (liketrek#856) * fix(packing): resolve avatar URL path in bag and category assignees (liketrek#854) packingService was returning raw avatar filenames from the DB instead of the full /uploads/avatars/<filename> path, causing broken profile images for users with uploaded avatars. * fix(budget): use Map.get() to fix category rename no-op (liketrek#855) * fix(security): relax Referrer-Policy and document HSTS_INCLUDE_SUBDOMAINS (liketrek#862) (liketrek#863) - Change Helmet default from no-referrer to strict-origin-when-cross-origin so browsers send the origin on cross-origin requests, allowing Google Maps API key restrictions by HTTP referrer to work correctly - Document HSTS_INCLUDE_SUBDOMAINS in all deployment artifacts: .env.example, docker-compose.yml, README.md, unraid-template.xml, charts/values.yaml, charts/configmap.yaml, wiki/Environment-Variables.md * fix(planner): prefetch budget items on trip page mount (liketrek#864) Loads budgetItems alongside reservations when TripPlannerPage mounts so the Budget category dropdown in ReservationModal and TransportModal shows pre-existing categories on first open, regardless of whether the Budget tab has been visited. Closes liketrek#861 * fix(reservations): prevent Invalid Date when end time is set without end date (liketrek#866) When reservation_end_time held a bare time string ("HH:MM"), fmtDate() produced Invalid Date on the reservation card. - Modal: when end date is blank but end time is filled, construct a same-day ISO datetime using the start date (prevents time-only strings from ever being persisted) - Panel: derive endDatePart via regex so date-only end values ("YYYY-MM-DD") still show the multi-day range, while bare time strings are skipped and handled correctly by the existing time column logic Closes liketrek#860 * fix(planner): format reservation end time instead of rendering raw ISO string (liketrek#867) Closes liketrek#859 * fix(planner): wire Route toggle into mobile day sidebar (liketrek#850) (liketrek#868) The per-booking Route icon was missing on mobile because the mobile DayPlanSidebar invocation in TripPlannerPage didn't pass visibleConnectionIds or onToggleConnection. Mobile PWA users couldn't activate reservation map overlays without forcing desktop mode. Also corrects the Map-Features wiki: fixes the setting name ("Booking route labels" not "Show connection labels"), documents the route_calculation requirement for travel-time pills, and explains that overlays are off by default and must be toggled per reservation. * chore: bump version to 3.0.8 [skip ci] * docs(wiki): add MCP OAuth troubleshooting entry for missing APP_URL * Fix demo banner overlapping bottom tab bar on mobile The demo welcome modal extended below the mobile bottom tab bar, hiding the dismiss button so visitors couldn't close it. - Use dvh so mobile URL bar is accounted for correctly - Reserve ~80px of bottom padding for the tab bar - Make the footer sticky so the dismiss button stays visible while scrolling through the modal content - Bump z-index to ensure the overlay sits above the tab bar * Fix 500 on reservation edit after DB reinit (issue liketrek#883) saveEndpoints was bound at module load via db.transaction(...). When the demo-mode hourly reset (or a self-hoster's backup restore) closes the DB connection and reinitialises it, the bound transaction still references the now-closed connection — every subsequent reservation save with an endpoints field throws "The database connection is not open", which the client surfaces as "Internal server error". Bind the transaction lazily on each call so it always runs against the current connection. * Fix exit code 132 on old CPUs by replacing sharp with jimp (issue liketrek#888) (liketrek#895) sharp's prebuilt Linux x64 binary requires SSE4.2 (x86-64-v2), causing a SIGILL crash on older hardware (e.g. AMD A6-3420M). Replace with jimp, a pure-JS image library with no native binaries. Also skip thumbnail generation entirely when the Journey addon is disabled (the default), preventing the issue for most installs regardless of the image library used. * chore: Add Trademark policy * chore: Add Trademark policy * chore: bump version to 3.0.9 [skip ci] --------- Co-authored-by: Maurice <61554723+mauriceboe@users.noreply.github.com> Co-authored-by: github-actions[bot] <github-actions[bot]@users.noreply.github.com> Co-authored-by: Maurice <mauriceboe@icloud.com> Co-authored-by: Xre0uS <36565320+Xre0uS@users.noreply.github.com> Co-authored-by: snyk-bot <snyk-bot@snyk.io>
Contributor
Wrong target branchThis PR targets To fix this, click Edit next to the PR title and change the base branch to This PR will be automatically closed in 24 hours if the base branch has not been updated.
|
bl4ko
force-pushed
the
feat/chart-security-labels
branch
from
April 27, 2026 21:03
12f028d to
8bc2058
Compare
Add configurable Kubernetes best-practice fields to the Helm chart: Security: - podSecurityContext (default: fsGroup: 1000) - securityContext for container (default: empty) - Standard app.kubernetes.io/* labels on all resources Scheduling: - priorityClassName - nodeSelector - tolerations - affinity Networking: - NetworkPolicy (disabled by default, allows port 3000 when enabled) All fields default to empty/disabled — no behavioral change for existing installations. Deployment selector.matchLabels unchanged to avoid breaking rolling updates.
bl4ko
force-pushed
the
feat/chart-security-labels
branch
from
April 27, 2026 21:07
8bc2058 to
09bb89d
Compare
Collaborator
|
Closing this during a PR cleanup — it's had merge conflicts against |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Adds configurable Kubernetes best-practice fields to the Helm chart:
Security:
podSecurityContext— pod-level security context (default:fsGroup: 1000)securityContext— container-level security context (default:{})app.kubernetes.io/*labels on all resources via_helpers.tplScheduling:
priorityClassNamenodeSelectortolerationsaffinityNetworking:
networkPolicy.enabled— optional NetworkPolicy (disabled by default, allows port 3000 when enabled)ingressandegressrulesMotivation
Clusters with policy engines (Kyverno, OPA/Gatekeeper) or PodSecurity Standards enforcement flag the chart for:
securityContextapp.kubernetes.io/namelabelpriorityClassNamesupportAdditionally,
nodeSelector,tolerations, andaffinityare standard Helm chart fields that users expect for scheduling control.Container image compatibility note
The default entrypoint runs
chownas root before dropping to usernode(UID 1000) viasu-exec. SettingrunAsNonRoot: truewill prevent the container from starting unless the entrypoint is changed.Compatible subset for policy compliance:
Test plan
helm lintpasseshelm templateoutput — only new labels added, no behavioral changenodeSelector,tolerations,affinityrender correctlypriorityClassNamerenders when set, omitted when emptyrunAsNonRootincompatibility