CI & Build / Python lint (push) Successful in 3s
CI & Build / Plugin hooks (push) Successful in 13s
CI & Build / integration (push) Successful in 52s
CI & Build / TypeScript typecheck (push) Successful in 54s
CI & Build / Python tests (push) Successful in 1m36s
CI & Build / Build & push image (push) Successful in 32s
The shape ledger's divergence readout flagged _gate_setting (#4385). Reading it turned up a family with no canon: floor_for, get_duplicate_threshold, get_plan_match_threshold and _gate_setting each parsed a stored string, fell back to the default (never 0) and clamped into [lo, 1]. - services/settings.bounded_float(raw, default, lo=0, hi=1) is the pure parse, fallback and clamp. Each caller keeps its own get_setting read, so tests patching get_setting per module still take effect, and _gate_setting still fails open on an unreadable setting. - SettingsView.saveKbInject: eleven inline Math.min/Math.max clamps and the local gateAt become one asBar(v, d, lo = 0), mirroring the server. No behaviour change. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
122 lines
4.7 KiB
Python
122 lines
4.7 KiB
Python
import logging
|
|
|
|
from sqlalchemy import delete as sa_delete, select
|
|
|
|
from scribe.models import async_session
|
|
from scribe.models.setting import Setting
|
|
from scribe.models.user import User
|
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
# What a stored credential looks like on the wire. Every surface that READS a
|
|
# secret (smtp_password, forge_webhook_secret, a forge token) returns this
|
|
# when one is set; every surface that WRITES one treats this value coming back
|
|
# as "unchanged", never as a request to store eight asterisks over the real
|
|
# credential. One constant so the read and write halves cannot disagree.
|
|
SECRET_MASK = "********"
|
|
|
|
|
|
def bounded_float(raw: str | None, default: float, lo: float = 0.0, hi: float = 1.0) -> float:
|
|
"""A numeric setting as stored text, parsed and clamped to [lo, hi].
|
|
|
|
Every similarity bar and retrieval floor is kept as a string and read the
|
|
same way: an unparseable value falls back to the DEFAULT, never to 0 (a
|
|
floor of 0 admits everything), and a value out of range is pulled back
|
|
into it. Pure on purpose: each caller keeps its own `get_setting` read, so
|
|
what can fail there — and whether that fails open — stays the caller's.
|
|
"""
|
|
try:
|
|
value = float(raw)
|
|
except (TypeError, ValueError):
|
|
value = default
|
|
return min(hi, max(lo, value))
|
|
|
|
|
|
async def get_admin_setting(key: str, default: str = "") -> str:
|
|
"""Read an instance-global setting (one stored on an admin account).
|
|
|
|
Used for settings that aren't per-user — e.g. the plugin marketplace URL
|
|
shown to everyone in Settings. Mirrors the admin-scoped lookup used for
|
|
the application base URL.
|
|
"""
|
|
async with async_session() as session:
|
|
result = await session.execute(
|
|
select(Setting)
|
|
.join(User, Setting.user_id == User.id)
|
|
.where(User.role == "admin", Setting.key == key)
|
|
)
|
|
setting = result.scalars().first()
|
|
return setting.value if setting and setting.value else default
|
|
|
|
|
|
async def set_admin_setting(key: str, value: str) -> None:
|
|
"""Write an instance-global setting onto the first admin account.
|
|
|
|
The write-side counterpart to get_admin_setting, for non-per-user settings
|
|
written outside a request context (e.g. a scheduler persisting its last-run
|
|
summary) where get_current_user_id() isn't available.
|
|
"""
|
|
async with async_session() as session:
|
|
admin_id = (
|
|
await session.execute(
|
|
select(User.id).where(User.role == "admin").order_by(User.id)
|
|
)
|
|
).scalars().first()
|
|
if admin_id is not None:
|
|
await set_setting(admin_id, key, value)
|
|
|
|
|
|
async def get_setting(user_id: int, key: str, default: str = "") -> str:
|
|
async with async_session() as session:
|
|
result = await session.execute(
|
|
select(Setting).where(Setting.user_id == user_id, Setting.key == key)
|
|
)
|
|
setting = result.scalar_one_or_none()
|
|
return setting.value if setting else default
|
|
|
|
|
|
async def set_setting(user_id: int, key: str, value: str) -> None:
|
|
async with async_session() as session:
|
|
result = await session.execute(
|
|
select(Setting).where(Setting.user_id == user_id, Setting.key == key)
|
|
)
|
|
setting = result.scalar_one_or_none()
|
|
if setting:
|
|
setting.value = value
|
|
else:
|
|
session.add(Setting(user_id=user_id, key=key, value=value))
|
|
await session.commit()
|
|
|
|
|
|
async def set_settings_batch(user_id: int, settings: dict[str, str]) -> None:
|
|
"""Update multiple settings in a single transaction."""
|
|
async with async_session() as session:
|
|
for key, value in settings.items():
|
|
result = await session.execute(
|
|
select(Setting).where(Setting.user_id == user_id, Setting.key == key)
|
|
)
|
|
setting = result.scalar_one_or_none()
|
|
if setting:
|
|
setting.value = value
|
|
else:
|
|
session.add(Setting(user_id=user_id, key=key, value=value))
|
|
await session.commit()
|
|
logger.info("Batch-updated %d settings for user %d", len(settings), user_id)
|
|
|
|
|
|
async def delete_setting(user_id: int, key: str) -> None:
|
|
"""Remove a setting row so get_setting() returns its hardcoded default instead."""
|
|
async with async_session() as session:
|
|
await session.execute(
|
|
sa_delete(Setting).where(Setting.user_id == user_id, Setting.key == key)
|
|
)
|
|
await session.commit()
|
|
|
|
|
|
async def get_all_settings(user_id: int) -> dict[str, str]:
|
|
async with async_session() as session:
|
|
result = await session.execute(
|
|
select(Setting).where(Setting.user_id == user_id)
|
|
)
|
|
return {s.key: s.value for s in result.scalars().all()}
|