mirror of
https://github.com/we-promise/sure.git
synced 2026-07-27 20:22:16 +00:00
* feat(settings): super-admin background jobs console Neither managed nor self-hosted production deployments have any view into background job state (/sidekiq is only mounted outside production), so a stuck sync, import, or export is invisible until a user complains — and even then there is no way to act on it. Adds /settings/background_jobs, gated by the same super-admin Admin::BaseController as /settings/debug: - Worker status header: Sidekiq processes, busy count, queue depths and latency, retry/scheduled/dead set sizes. Read through a fail-closed PORO (BackgroundJobConsole) — when Redis is unreachable the console says so and disables actions instead of pretending health (deliberate contrast to BackgroundJobHealth's fail-open). - In-flight operations across all families: incomplete Syncs, Imports importing/reverting, ImportSessions importing, FamilyExports pending/processing, each with a liveness verdict derived from Sidekiq::Workers (job GlobalIDs in running payloads). - One mutation: mark a presumed-lost operation as such (Sync → stale, Import → failed/revert_failed, PdfImport → claim released back to pending, ImportSession/FamilyExport → failed). Guard rails on the mutation, server-side re-checked: - refused while Redis state is unknown (fail closed) - refused while the record's job is visibly executing - refused until the record has been idle past 30 minutes, so a merely queued job cannot be shot down and then still run - refused for parent Syncs with children still in flight (a parent legitimately has no live job of its own while children run) - applied inside with_lock with a status re-check, so a job finishing between render and click wins - audited as a DebugLogEntry (actor, prior status, family) The cancel endpoint gets its own Rack Attack throttle since the console deliberately lives under /settings rather than the throttled /admin prefix (its 10 req/min limit would fight the page's polling). * fix(jobs-console): count waiting jobs as live and harden cancel paths Review feedback on #2682 (Codex, CodeRabbit): - Liveness now covers jobs sitting in queues, the retry set, and the scheduled set, not just visibly-executing workers — a job waiting out a backlog or retry backoff WILL run later, and most affected job classes don't abort on a flipped status, so cancelling invited duplicate work. The backlog scan is bounded (5k entries); a truncated scan fails closed like redis_error?. The liveness column shows "Queued" for these - find_record! resolves STI subclass names (TransactionImport, PdfImport, …) against a base-class whitelist via safe_constantize instead of a fixed name map, so non-UI callers naming the subclass don't 404 - A PdfImport stuck in reverting goes to revert_failed like every other import instead of being released to pending — pending presented a possibly half-reverted import as publishable again; only the AI extraction claim (importing) is released to pending - Redis-unreachable warning renders via DS::Alert; operation id cast to_s before splitting; admin-cancel error copy moved to i18n * fix(jobs-console): re-check the stuck window inside the cancel row lock CodeRabbit round-2: cancellable? evaluates Sidekiq liveness outside the with_lock transaction (re-running Redis calls under a row lock would be worse), so a worker picking the job up between the liveness check and the lock acquisition was invisible. Repeating the updated_at staleness check inside the lock closes that window — a freshly-started job touches the record, and the re-check refuses the cancel. * fix(jobs-console): resolve record_type without reflection, i18n nits Brakeman flagged safe_constantize on params[:record_type] as a High-confidence UnsafeReflection (ci/scan_ruby). Replace the constant lookup with a reverse lookup: find the id in each cancellable base table and require the claimed type to match the found record's class or its base class. STI subclass names still resolve; unknown types still 404. Also from DS Drift Patrol: - "Sync · " label in _operation.html.erb now goes through t(".sync_label", type:) - drop the redundant default: on background_jobs_label now that the key exists in the locale file
118 lines
5.4 KiB
Plaintext
118 lines
5.4 KiB
Plaintext
<%
|
|
nav_sections = [
|
|
{
|
|
header: t(".general_section_title"),
|
|
items: [
|
|
{ label: t(".accounts_label"), path: accounts_path, icon: "layers" },
|
|
{ label: t(".bank_sync_label"), path: settings_providers_path, icon: "banknote", if: Current.user&.admin? },
|
|
{ label: t(".preferences_label"), path: settings_preferences_path, icon: "bolt" },
|
|
{ label: t(".appearance_label"), path: settings_appearance_path, icon: "palette" },
|
|
{ label: t(".profile_label"), path: settings_profile_path, icon: "circle-user" },
|
|
{ label: t(".security_label"), path: settings_security_path, icon: "shield-check" },
|
|
{ label: t(".payment_label"), path: settings_payment_path, icon: "circle-dollar-sign", if: !self_hosted? && Current.family&.can_manage_subscription? }
|
|
]
|
|
},
|
|
{
|
|
header: t(".transactions_section_title"),
|
|
items: [
|
|
{ label: t(".categories_label"), path: categories_path, icon: "shapes" },
|
|
{ label: t(".tags_label"), path: tags_path, icon: "tags" },
|
|
{ label: t(".rules_label"), path: rules_path, icon: "git-branch" },
|
|
{ label: t(".merchants_label"), path: family_merchants_path, icon: "store" },
|
|
{ label: t(".recurring_transactions_label"), path: recurring_transactions_path, icon: "repeat" },
|
|
{ label: t(".statement_vault_label"), path: account_statements_path, icon: "archive", if: Current.user&.admin? }
|
|
]
|
|
},
|
|
(
|
|
Current.user&.admin? ? {
|
|
header: t(".advanced_section_title"),
|
|
items: [
|
|
{ label: t(".ai_prompts_label"), path: settings_ai_prompts_path, icon: "bot" },
|
|
{ label: t(".llm_usage_label"), path: settings_llm_usage_path, icon: "activity" },
|
|
{ label: t(".api_keys_label"), path: settings_api_keys_path, icon: "key" },
|
|
{ label: t(".mcp_label"), path: settings_mcp_path, icon: "plug" },
|
|
{ label: t(".debug_label", default: "Debug"), path: settings_debug_path, icon: "bug", if: Current.user&.super_admin? },
|
|
{ label: t(".background_jobs_label"), path: settings_background_jobs_path, icon: "list-checks", if: Current.user&.super_admin? },
|
|
{ label: t(".self_hosting_label"), path: settings_hosting_path, icon: "database", if: self_hosted? },
|
|
{ label: t(".imports_label"), path: imports_path, icon: "download" },
|
|
{ label: t(".exports_label"), path: family_exports_path, icon: "upload" },
|
|
{ label: t(".sso_providers_label"), path: admin_sso_providers_path, icon: "key-round", if: Current.user&.super_admin? },
|
|
{ label: t(".users_label"), path: admin_users_path, icon: "users", if: Current.user&.super_admin? }
|
|
]
|
|
} : nil
|
|
),
|
|
{
|
|
header: t(".other_section_title"),
|
|
items: [
|
|
{ label: t(".guides_label"), path: settings_guides_path, icon: "book-open" },
|
|
{ label: t(".whats_new_label"), path: changelog_path, icon: "box" },
|
|
{ label: t(".feedback_label"), path: feedback_path, icon: "megaphone" }
|
|
]
|
|
}
|
|
]
|
|
%>
|
|
|
|
<div class="space-y-4">
|
|
<div class="hidden lg:flex items-center gap-2 p-1.5">
|
|
<%= render DS::Link.new(
|
|
text: t("settings.settings_nav_link_large.previous"),
|
|
icon: "chevron-left",
|
|
href: previous_path,
|
|
variant: "ghost",
|
|
) %>
|
|
<%= link_to previous_path, class: "hidden md:block uppercase bg-surface-inset-hover rounded-sm px-1 py-0.5 text-xs text-secondary shadow-sm ml-1 pointer-events-none", data: { controller: "hotkey", hotkey: "Escape" } do %>
|
|
<kbd>esc</kbd>
|
|
<% end %>
|
|
</div>
|
|
<nav class="space-y-4 hidden md:block">
|
|
<% nav_sections.compact.each do |section| %>
|
|
<section class="space-y-2">
|
|
<div class="flex items-center gap-2 px-3">
|
|
<h3 class="uppercase text-secondary font-medium text-xs"><%= section[:header] %></h3>
|
|
<%= render "shared/ruler", classes: "w-full" %>
|
|
</div>
|
|
<ul class="space-y-1">
|
|
<% section[:items].each do |item| %>
|
|
<% next if item[:if] == false %>
|
|
<li>
|
|
<%= render "settings/settings_nav_item", name: item[:label], path: item[:path], icon: item[:icon] %>
|
|
</li>
|
|
<% end %>
|
|
</ul>
|
|
</section>
|
|
<% end %>
|
|
<section>
|
|
<%= button_to session_path(Current.session), method: :delete, class: "flex items-center gap-2 px-3 py-2 rounded-lg text-sm text-destructive hover:bg-surface-hover w-full" do %>
|
|
<%= icon("log-out", color: "current") %>
|
|
<span><%= t(".logout") %></span>
|
|
<% end %>
|
|
</section>
|
|
</nav>
|
|
<nav class="space-y-4 overflow-x-auto md:hidden no-scrollbar overscroll-none" id="mobile-settings-nav" data-controller="preserve-scroll scroll-on-connect">
|
|
<ul class="flex flex-nowrap space-x-1">
|
|
<li>
|
|
<%= render DS::Link.new(
|
|
text: t("settings.settings_nav_link_large.previous"),
|
|
icon: "chevron-left",
|
|
href: previous_path,
|
|
variant: "ghost",
|
|
) %>
|
|
</li>
|
|
<% nav_sections.compact.each do |section| %>
|
|
<% section[:items].each do |item| %>
|
|
<% next if item[:if] == false %>
|
|
<li>
|
|
<%= render "settings/settings_nav_item", name: item[:label], path: item[:path], icon: item[:icon] %>
|
|
</li>
|
|
<% end %>
|
|
<% end %>
|
|
<li>
|
|
<%= button_to session_path(Current.session), method: :delete, class: "flex items-center gap-2 px-3 py-2 rounded-lg text-sm text-destructive hover:bg-surface-hover w-full" do %>
|
|
<%= icon("log-out", color: "current") %>
|
|
<span><%= t(".logout") %></span>
|
|
<% end %>
|
|
</li>
|
|
</ul>
|
|
</nav>
|
|
</div>
|