Compare commits

..
Author SHA1 Message Date
Typosaurus 8dde41b483 ticket #103 attempt 1 2026-07-19 19:58:16 +00:00
6 changed files with 105 additions and 79 deletions
+1 -18
View File
@@ -4,13 +4,12 @@ import asyncio
import fcntl
import logging
import os
import re
import time
from collections import defaultdict
from contextlib import asynccontextmanager, contextmanager
from pathlib import Path
from fastapi import FastAPI, Request
from fastapi.responses import HTMLResponse, RedirectResponse, Response
from fastapi.responses import HTMLResponse, RedirectResponse
from fastapi.staticfiles import StaticFiles
from fastapi.exceptions import RequestValidationError
from starlette.middleware.gzip import GZipMiddleware
@@ -612,22 +611,6 @@ async def response_timing(request: Request, call_next):
return response
_KNOWN_CRAWLERS = re.compile(
r"(google.*read.*aloud|googlebot|bingbot|slurp|duckduckbot|baiduspider|yandexbot)",
re.IGNORECASE,
)
_AUTH_GATED_PATHS = frozenset({"/messages", "/notifications", "/game", "/admin"})
@app.middleware("http")
async def crawler_detection(request: Request, call_next):
if request.method == "GET" and request.url.path in _AUTH_GATED_PATHS:
ua = request.headers.get("user-agent", "")
if _KNOWN_CRAWLERS.search(ua):
return Response(status_code=204)
return await call_next(request)
app.add_middleware(GZipMiddleware, minimum_size=512, compresslevel=5)
-1
View File
@@ -17,7 +17,6 @@ async def robots_txt(request: Request):
Disallow: /auth/
Disallow: /messages/
Disallow: /notifications/
Disallow: /game/
Disallow: /votes/
Disallow: /avatar/
Disallow: /follow/
+56 -3
View File
@@ -18,7 +18,9 @@ from devplacepy.services.openai_gateway.usage import (
usage_metric_cards,
)
from devplacepy.utils import generate_uid, make_combined_slug
from devplacepy.utils.notifications import create_notification
from devplacepy.services.audit import record as audit
from devplacepy.services.openai_gateway.reliability import retry_send
from devplacepy.services.seo_meta import schedule_seo_meta
from . import _get_ai_key
@@ -151,6 +153,32 @@ class NewsService(BaseService):
),
group="AI formatting",
),
ConfigField(
"news_fetch_retries",
"News API fetch retries",
type="int",
default=3,
minimum=0,
maximum=10,
help=(
"How many times to retry the upstream news API on failure. "
"Each retry waits longer (linear backoff). Set 0 for no retries."
),
group="Reliability",
),
ConfigField(
"news_fetch_retry_backoff_ms",
"News API retry backoff (ms)",
type="int",
default=5000,
minimum=1000,
maximum=60000,
help=(
"Base backoff in milliseconds between retries. The actual "
"delay is backoff * attempt number."
),
group="Reliability",
),
]
def __init__(self):
@@ -165,13 +193,38 @@ class NewsService(BaseService):
format_enabled = config["news_format_enabled"]
self.log(f"Fetching news from {api_url}")
max_retries = config["news_fetch_retries"]
backoff_ms = config["news_fetch_retry_backoff_ms"]
async with stealth.stealth_async_client(timeout=30.0) as client:
try:
resp = await client.get(api_url)
resp.raise_for_status()
resp, exc, attempts = await retry_send(
do_call=lambda: client.get(api_url),
max_retries=max_retries,
backoff_ms=backoff_ms,
log=lambda msg: self.log(msg),
)
if exc is not None:
raise exc
if resp is None or resp.status_code >= 400:
raise httpx.HTTPError(f"status {resp.status_code if resp else 0}")
data = resp.json()
except Exception as e:
self.log(f"Failed to fetch news API: {e}")
self.log(f"Failed to fetch news API after {attempts} attempts: {e}")
audit.record_system(
"news.service.fetch_failed",
actor_kind="service",
actor_uid="news",
summary=f"News API unreachable after {attempts} attempts",
metadata={"api_url": api_url, "attempts": attempts, "error": str(e)},
result="failure",
)
for admin_row in get_table("users").find(role="Admin"):
create_notification(
admin_row["uid"],
"system",
f"News API unreachable after {attempts} attempts",
related_uid="",
)
return
articles = data.get("articles", [])
+3 -4
View File
@@ -196,8 +196,7 @@ def test_robots_txt_exists(app_server):
assert "Sitemap:" in r.text
def test_robots_disallows_auth_gated_paths(app_server):
def test_robots_disallows_admin_and_uploads(app_server):
r = requests.get(f"{BASE_URL}/robots.txt")
required = ["/auth/", "/game/", "/messages/", "/notifications/", "/admin/", "/uploads/"]
for path in required:
assert f"Disallow: {path}" in r.text, f"Missing Disallow: {path}"
assert "Disallow: /admin/" in r.text
assert "Disallow: /uploads/" in r.text
-50
View File
@@ -1,50 +0,0 @@
# retoor <retoor@molodetz.nl>
import requests
from tests.conftest import BASE_URL
def test_bot_blocked_on_auth_path(app_server):
headers = {"User-Agent": "Google-Read-Aloud"}
r = requests.get(f"{BASE_URL}/messages", headers=headers)
assert r.status_code == 204
assert r.content == b""
def test_bot_blocked_on_game_path(app_server):
headers = {"User-Agent": "Google-Read-Aloud"}
r = requests.get(f"{BASE_URL}/game", headers=headers)
assert r.status_code == 204
assert r.content == b""
def test_bot_blocked_on_admin_path(app_server):
headers = {"User-Agent": "Google-Read-Aloud"}
r = requests.get(f"{BASE_URL}/admin", headers=headers)
assert r.status_code == 204
assert r.content == b""
def test_bot_not_blocked_on_public_path(app_server):
headers = {"User-Agent": "Google-Read-Aloud"}
r = requests.get(f"{BASE_URL}/", headers=headers)
assert r.status_code == 200
def test_normal_user_not_blocked(app_server):
r = requests.get(f"{BASE_URL}/messages", allow_redirects=False)
assert r.status_code == 303
def test_known_crawler_user_agent_variants(app_server):
ua_list = [
"Googlebot",
"Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)",
"bingbot/2.0; +http://www.bing.com/bingbot.htm",
"Mozilla/5.0 (compatible; DuckDuckBot-Https/1.1; ...)",
"Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)",
]
for ua in ua_list:
headers = {"User-Agent": ua}
r = requests.get(f"{BASE_URL}/admin", headers=headers)
assert r.status_code == 204, f"Expected 204 for UA: {ua}"
+45 -3
View File
@@ -67,9 +67,14 @@ class FakeClient_news_service:
grade = "9" if "HighArticle" in prompt else "3"
return FakeResp_news_service(json_data={"choices": [{"message": {"content": grade}}]})
class FailingApiClient(FakeClient_news_service):
def __init__(self, *args, **kwargs):
super().__init__(*args, **kwargs)
self.call_count = 0
async def get(self, url, timeout=None):
self.call_count += 1
if url == API_URL:
raise httpx.HTTPError("api down")
raise httpx.RequestError("api down")
return FakeResp_news_service(text="")
GATEWAY_HEADERS = {
"X-Gateway-Cost-USD": "0.00010000",
@@ -98,7 +103,7 @@ class UsageClient(FakeClient_news_service):
json_data={"choices": [{"message": {"content": grade}}]},
headers=GATEWAY_HEADERS,
)
def _settings_stub(threshold="7"):
def _settings_stub(threshold="7", retries="3", backoff="5"):
def fake_get_setting(key, default=None):
return {
"news_api_url": API_URL,
@@ -106,6 +111,8 @@ def _settings_stub(threshold="7"):
"news_ai_model": "test-model",
"news_grade_threshold": threshold,
"news_ai_key": "",
"news_fetch_retries": retries,
"news_fetch_retry_backoff_ms": backoff,
}.get(key, default)
return fake_get_setting
@@ -171,12 +178,47 @@ def test_grade_article_unparseable_returns_none(local_db, monkeypatch):
def test_run_once_handles_api_failure(local_db, monkeypatch):
admin_uid = generate_uid()
get_table("users").insert({
"uid": admin_uid,
"username": "testadmin",
"role": "Admin",
"email": "admin@test.test",
"password": "hash",
"api_key": generate_uid(),
"created_at": "2025-01-01T00:00:00Z",
})
monkeypatch.setattr(news_mod, "get_setting", _settings_stub())
monkeypatch.setattr(base_mod, "get_setting", _settings_stub())
failing_client = FailingApiClient([])
monkeypatch.setattr(
news_mod.httpx, "AsyncClient", lambda *a, **k: FailingApiClient([])
news_mod.stealth, "stealth_async_client",
lambda *a, **k: failing_client,
)
notifications = []
monkeypatch.setattr(
news_mod, "create_notification",
lambda user_uid, notification_type, message, related_uid, target_url=None: (
notifications.append((user_uid, message))
),
)
run_async(NewsService().run_once())
assert failing_client.call_count == 4
assert len(notifications) == 1
assert notifications[0][0] == admin_uid
assert "News API unreachable" in notifications[0][1]
def test_run_once_handles_api_failure_zero_retries(local_db, monkeypatch):
monkeypatch.setattr(news_mod, "get_setting", _settings_stub(retries="0"))
monkeypatch.setattr(base_mod, "get_setting", _settings_stub(retries="0"))
failing_client = FailingApiClient([])
monkeypatch.setattr(
news_mod.stealth, "stealth_async_client",
lambda *a, **k: failing_client,
)
run_async(NewsService().run_once())
assert failing_client.call_count == 1
def test_run_once_updates_existing_news_row(local_db, monkeypatch):