Dependency review 2021.06 #375
Closed
opened 2021-02-14 21:12:31 +01:00 by nik
·
82 comments
No Branch/Tag specified
master
3960-extend-slideiterator
1625-migrate-to-vuetify-4
remove-vite-legacy-plugin
weblate-frontend
weblate
renovate/selenium-4.x
1644-dahsboard-widget-creation-broken
renovate/node-26.x
renovate/django-health-check-4.x
renovate/django-countries-9.x
1643-calendar-dashboardwidgets-throw-500er-error
renovate/django-dbbackup-5.x
1064-backchannel-logout
sis2-with-sl
fix/adapt-some-urls
1533-notifications-reminders-for-events-todos
1294-expose-free-busy-state-in-ui-for-personal-events
1303-correctly-implement-recurring-todos-with-amends-recurrence-id
1345-introduce-annotate-methods-for-more-person-related-rules
1603-search-index-is-deleted-on-cache-flush
1068-oidc-rp-initiated-registration
1065-oidc-device-code-grant-flow
1599-vite-build-fails-with-too-many-apps
fix/sort-models
1066-oidc-dynamic-client-registration
tmp-ticdesk-dev
ticdesk-search-map
cherry-pick-2b8d2e01
643-one-time-login-links
1461-birthday-calendar-oom
tmp-ticdesk-related-names-for-paweljong
1459-manifest-json-not-found
integrate-disable-into-usecrud
update-container-image-base-to-trixie
check/update-pyproject-toml
check/update-builddeps-package-json
check/update-prettier-ignore
1445-todo-list-broken
1364-track-date-of-beginning-and-end-of-group-membership
1259-generalise-places
use-object-form-reactivity
1435-cruddaylist-does-not-detect-changes-in-existing-intervals
tmp-ticdesk
stable/4.0.0
1366-frontend-for-creating-and-modifying-generic-personrelationships
master-without-vue-3
1376-expand-row-feature-of-v-data-table-doesn-t-work-when-items-include-date-time-objects
release/4.1.0.dev2
1372-fix-import-of-crudlist
1353-adapt-chipselectfield
check/update-eslint-rc-js
check/update-tox-ini
improve-selenium-startup
1268-add-specific-availability-planning-frontend
1343-fix-person-related-permissions
newer-and-rebased-migrate-crud-to-vue-3-and-generalize
1314-fix-handling-of-end-datetime-in-calendar-events-query
migrate-to-uv
tmp-ticdesk-4-0
fix-inline-crud-list-is-create
tmp-split-calendar-event-dialog
release/4.1.0
1260-refactor-account-registration-form-and-generalize-parts-of-it
add-datacheck-fix-in-changelog
1232-group-calendars
1251-registryobjects-are-their-own-parent-registries
1209-introduce-django-rest-framework-serializers
1162-strange-behaviour-with-personal-events
revert-7fe8b8b1
check/delete-eslint-rc-js
check/update-gitignore
stable-3.2
stable-3.1
update/eslint
1158-add-sorting-functionality-to-get_single_events
1055-introduce-sub-school-terms
1082-colorfield-sometimes-returns-8-digit-alpha-color-hex-code
test-build
emit-extracted-items-from-save-event
886-prevent-graphql-query-mutation-name-collisions
release/3.2.1
1038-make-dialogobjectform-send-a-diff-on-edit-instead-of-the-whole-object
release/3.1.6
fix/counter-chip
1021-allow-matching-of-social-accounts-to-local-accounts-by-email
991-set-title-attribute-for-all-unclear-frontend-spots
update-docs-without-release-distribution
850-do-not-restart-vite-serve-on-every-uwsgi-reload
991-use-tooltips-for-all-unclear-frontend-spots
983-add-groups-by-person-query
826-otp-token-emails-don-t-contain-anything-besides-the-token
781-error-if-creating-a-new-school-term-without-a-start-and-end-date
966-allow-setting-of-custom-queryset-when-creating-calendar-feeds
tmp-for-add-simple-course-book-list
release/3.2.0
868-introduce-uuid-field-for-extensiblemodel
958-introduce-parent-model-resource
954-evaluate-strawberry-and-strawberry-django
948-error-handling-with-personal-event-creation-is-not-usable
fix-custom-events-fss
923-introduce-vue-styleguidist
899-move-person-type-fields-into-constant
892-remove-model-extension-api
manage-holidays
831-data-management-for-the-model-room
fix/oauth-toolkit-migration
release-3.0
stable-2.12
819-fix-some-minor-issues-in-graphql-queries
fix-container-image
stable-2.11
stable-2.10
stable-2.13
806-expose-string-representation-of-models-via-graphql-api
800-move-generic-components-from-aleksis-app-plank-to-core
debug-foo
oidc-docs
migrate-to-vue3
789-remove-syncable-fields
remove/ical-feed
194-enable-async-framework-channels
726-dynamically-build-vue-forms
766-selfclosing-components-in-vue_base-html-break-the-page
492-follow-up-view_persons_rule-not-usable-due-to-use-of-queryset_rules_filter
751-include-fields-of-non-extensible-model-in-syncable-fields
kort-core
feature/vuejs
717-docker-improve-image-size-by-fixing-cleanup-layer
build-improvements
697-3-0-meta-issue-for-graphql-back-end-and-vue-js-frontend
185-create-notifications-for-announcement
stable-2.7
update/translation-files-13
update/translation-files-12
599-add-oauth-oidc-tests
i10n-ru-ua
tmp/cbes
do-release-2.9
docs/notifications
180-add-template-management
fix-import
653-remove-cachalot
635-test-e-mail-button
397-dedicated-public-dashboard
396-external-link-widet-auto-discovery
511-allow-custom-redirect-uri-schemes
update/translation-files-8
585-barcode-widget-for-person-fields
dot-1.6.2
281-corporate-design-for-html-mails
592-oauth2-broken-in-2-4
574-rewrite-password-change-templates
reduce-docker-steps
571-age-calculation-broken
559-oauth-add-feature-to-limit-apps-to-groups
feature/push-notifications
feature/i18n-maintenance
fix/oauth-skip-auth-detail
523-integrate-sentry-for-performance-and-error-tracing
prepare-release-2.1.dev0
release/2.0
387-jwt-provider-consumer-support
update/translation-files
496-service-worker-safari-does-not-support-broadcastchannel-api
group-members-permissions
prepare-release-2.0b2
fix/trans-conflicts
bp-2.0-use-importlib-instead-of-pkg-resources
update/translation-files-2.0b0-1
test-migration-test
376-prevent-deep-linking-to-media-files
feature/build-icons-automatically
421-update-to-django-3-2
set-sast-config-1
feature/test-selenium-capabilities
arg-apps
feature/review-app
test-docker-app-version
feature/allow-app-source
fix-ci-config
feature/curlylint
feature/gin-index-on-ext-data
backup-over-ssh
feature/keep_local_password_ldap
340-correctly-implement-the-ckeditor
143-mark-menu-entries-as-active-with-sub-sub-menu-entries
feature/django-notifs
2021-update-copyright
catch-error
update/poetry
selenium
269-photo-cropping-broken-2
269-photo-cropping-broken
fix-docker-build
has-person
update-poetry-lockfile
pages-staging
mix/conn-dne
236-support-saml-and-oauth2-logins-as-consumer
feature/custom-auth-backends-dev
dev
fix-isort
214-add-notification-dashboard-widget-anything-to-notify-of-upcoming-birthdays
157-include-django-letsagree
215-add-geolocation-of-persons
267-lint-add-spell-check
291-rename-template-references
270-ci-replace-kaniko-with-buildah
217-add-support-for-defining-group-types
feature/docker-extras
153-use-complex-name-field-with-i18n-support
debug-docker-build
feature/material-admin
pages-jonglieren
179-group-contact
169-support-nextcloud-talk-for-notifications
develop-dashboard-feeds
134-merge-dashboard-ajax
5.3.0
5.2.0
5.1.0
5.0.3
5.0.2
5.0.1
5.0.0
5.0.0b3
5.0.0b2
5.0.0b1
5.0.0b0
4.1.0.dev2
4.0.4
4.1.0.dev1
4.1.0.dev0
4.0.3
4.0.2
4.0.1
4.0.0
4.0.0.dev16
3.2.2
3.1.7
4.0.0.dev15
4.0.0.dev14
4.0.0.dev13
4.0.0.dev12
4.0.0.dev11
3.1.6
3.2.1
4.0.0.dev10
4.0.0.dev9
4.0.0.dev8
4.0.0.dev7
4.0.0.dev6
4.0.0.dev5
4.0.0.dev4
4.0.0.dev3
4.0.0.dev2
4.0.0.dev1
3.2.0
3.1.5
3.1.4
3.1.3
3.1.2
3.1.1
3.1
3.0
2.12.4
3.0b3
3.0b2
2.10.3
2.11.2
2.12.3
3.0b1
3.0b0
3.0.dev3
2.12.2
3.0.dev2
2.12.1
2.12
2.11.1
2.11
2.10.2
3.0.dev1
2.10.2.dev0
3.0.dev0
2.10.1
2.10
2.7.6
2.7.5
2.9
2.8.2.dev2
2.8.2.dev1
2.8.2.dev0
2.8.1
2.8.1.dev0
2.8
2.7.4
2.7.3
2.7.2
2.7.1
2.7
2.6
2.5
2.4
2.3.2
2.3.1
2.3
2.2.1
2.2
2.1.1
2.1
2.1.dev0
2.0
2.0rc7
2.0rc6
2.0rc5
2.0rc4
2.0rc3
2.0rc2
2.0rc1
2.0b2
2.0b1
2.0b0
2.0a4
2.0a3
2.0a2
2.0a1
1.0a3.1
1.0a3
1.0a2
1.0a1
1.0a0
0.1
Labels
Clear labels
Security
TeX
Needs LaTeX template
auto-update
board
done
board
ready
board
todo
check
delete-eslint-rc-js
check
update-builddeps-package-json
check
update-eslint-rc-js
check
update-gitignore
check
update-merge-request-template
check
update-prettier-ignore
check
update-pyproject-toml
check
update-renovate-json
check
update-tox-ini
part
backend
Backend (view code, models, logic, etc.)
part
ci
part
docs
Issue or addition to the documentation
part
frontend
Frontend (templates, etc.)
part
i18n
Translation or internationalisation issue
part
non-technical
Non-technical (policy, maintenance, etc.) issue or discussion
part
packaging
Issue concerning the packaging of AlekSIS and components
prio
1
Priority High
prio
2
Priority Medium
prio
3
Priority Low
release-mr-5.x
size
large
size
medium
size
small
source
customer
Requested by a customer or affiliated user
source
customer::fsmw
source
customer::fss
source
customer::teckids
source
downstream
Issue or merge request from other projects using AlekSIS or parts of it
type
breaking
type
bug
Bug
type
feature
New feature
type
refactoring
workflow
blocked
Issue is blocked by another issue
workflow
confirmed
The bug is reproducible and will be fixed
workflow
current-todo
workflow
discussing
Needs to be discussed before implementation
workflow
new-app
Requires new AlekSIS app, which has to be created
workflow
wontfix
The bug is not reproducible or the feature was decided against
No labels
Security
TeX
auto-update
board
done
board
ready
board
todo
check
delete-eslint-rc-js
check
update-builddeps-package-json
check
update-eslint-rc-js
check
update-gitignore
check
update-merge-request-template
check
update-prettier-ignore
check
update-pyproject-toml
check
update-renovate-json
check
update-tox-ini
part
backend
part
ci
part
docs
part
frontend
part
i18n
part
non-technical
part
packaging
prio
1
prio
2
prio
3
release-mr-5.x
size
large
size
medium
size
small
source
customer
source
customer::fsmw
source
customer::fss
source
customer::teckids
source
downstream
type
breaking
type
bug
type
feature
type
refactoring
workflow
blocked
workflow
confirmed
workflow
current-todo
workflow
discussing
workflow
new-app
workflow
wontfix
Milestone
Clear milestone
No items
No milestone
Projects
Clear projects
No items
No project
Assignees
Clear assignees
No assignees
3 participants
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".
No due date set.
Dependencies
No dependencies set.
Reference
aleksis/AlekSIS-Core#375
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Synopsis
I am revieweing all direct dependencies of AlekSIS-Core. Priorities:
Dependencies
django-any-js
Reason
Helps keeping JS/CSS asset paths in settings so users are enabled to use their own locally hosted versions, or packagers in e.g. Debian to use the scripts from distribution packages
Recommendations
django-debug-toolbar
Reason
Helps with tracing issues and doing performance analysis. Really necessary in development, but helpful on production sites for support reasons.
Recommendations
django-middleware-global-request
Reason
Anti-pattern library to get a request object in places where there shouldn't be one; thus in the course of getting removed.
Recommendations
django-menu-generator-ng
Reason
Dynamic definition of menues, not perfect, with some todos. But for this release, we do not have anything better.
Recommendations
django-tables2
Reason
Class-based table creation, absolutely necessary.
Recommendations
Pillow
Reason
Image processing library; probably used by some other dependency.
Recommendations
django-phonenumber-field
Reason
Used in the
Personobject for phone number validation.Recommendations
django-sass-processor, libsass and colour
Reason
Dynamic re-generation of CSS after changes to theme preferences.
Recommendations
None
Dynaconf
Reason
Settings generation from environment and config files.
Recommendations
django-settings-context-processor
Reason
Adds configured settings values to the template context; currently used for
ADMINSandDEBUG.Recommendations
Too trivial to have a dependency for it. Also, seems like an anti-pattern. The
ADMINSlist is used in error templates and could be injected from the error views; theDEBUGis only used on the status page and could be injected there.If wer want to make things like ocnfigured admins availlable as a template API for apps, we should provide selective templatetags for it.
django-auth-ldap
Reason
LDAP authentication, optional dependency.
Recommendations
None
django-maintenance-mode
Reason
Show a static page when a maintenance flag is set
Recommendations
None
ipware
Reason
Used by the maintenance mode to determine client IP address independent of proxies, etc.
Recommendations
django-impersonate
Reason
Used in support to see AlekSIS from the view of another user, if superuser privileges are available
Recommendations
python-memcached
Reason
Caching backend memcached; not used by default.
Recommendations
django-hattori
Reason
Pseudonymisation of data via management command
Recommendations
psycopg2
Reason
PostgreSQL driver, necessary.
Recommendations
django_select2
Reason
Integration of Select2 for multi-part form fields and dynamic select fields
Recommendations
requests
Reason
Not used in core
Recommendations
django-two-factor-auth
Reason
2FA, obviously. Necessary.
Recommendations
django-yarnpkg
Reason
Define JS dependencies and integratre with colelctstatic, necessary.
Recommendations
django-material
Reason
Partial integration of materialize and Django
Recommendations
django-pwa
Reason
Progressive Web App utilities
Recommendations
django-dynamic-preferences
Reason
Code-defined preferences with frontend
Recommendations
django_widget_tweaks
Reason
Rendering of single form fields with options in templates
Recommendations
Formclass vs. template)django-filter
Reason
Filter list views dybamically
Recommendations
django-templated-email and html2text
Reason
used to generate HTML mails and fallback plaintext parts
Recommendations
django-ckeditor
Reason
WYSIWYG fields
Recommendations
django-js-reverse
Reason
Used to pass URL map to JavaScript code
Recommendations
calendarweek
Reason
Mainly used in Chronos for wee kcalculations, and partially for the i18n of the week selector
Recommendations
Celery, django-celery-results, django-celery-beat, django-celery-email, celery-progress
Reason
Asynchronous tasks
Recommendations
django-jsonstore
Reason
Extended data on extensible omdel
Recommendations
django-colorfield
Reason
Used in theme preferences, and provided for other apps (like the timetable in Chronos)
Recommendations
django-bleach
Reason
Sanitise HTML
Recommendations
django-guardian + rules
Reason
Object-level permissions and code-defined privileges
Recommendations
django-cache-memoize
Reason
Caching of function results with a decorator
Recommendations
django-haystack and celery-haystack-ng
Reason
Global search with indexing
Recommendations
django-dbbackup
Reason
Backups of database and media
Recommendations
spdx-licence-list and licence-expression
Reason
Used on about page to determine free licences
Recommendations
django-reversion
Reason
Used for history of models and soft deletion
Recommendations
django-favicon-plus-reloaded
Reason
Generation of icons for web apps and meta-tags
Recommendations
django-health-check and psutil
Reason
Provides checks for system health
Recommendations
django-cachalot
Reason
Query caching
Recommendations
django-prometheus
Reason
Provides metrics in Promtheus exporter format
Recommendations
importlib-metadata
Reason
Backwards-compatibility for Python 3.7, used in ap pauto-discovery
Recommendations
django-model-utils
Reason
Some useful mixins and such, used to add automatic timestamps
Recommendations
FieldTracker)bs4 (BeautifulSoup)
Reason
Used in
html_helpersto do… somethingRecommendations
django-extensions and ipython
Reason
Currently used to get
shell_plusRecommendations
It seems having good utilites at hand is also important for admins, not only for developers, and if admins hit rough edges where they e.g. need a shell, we should make their lives easier
django-dirtyfields
Reason
Track field modifications for conditional saves/syncs
Recommendations
FieldTrackerfromdjango-model-utils(!2137)changed the description
changed the description
changed title from Dependency review 2{-.0a4-} to Dependency review 2{+021.06+}
marked the checklist item Discuss whether this should be an optional extra dependency as completed
marked the checklist item Get !2100 merged as completed
marked the checklist item Document how apps can add assets that are configurable as completed
marked the checklist item Document how apps should use forms, views models, and tables, and all of them together as completed
marked the checklist item Document how apps can add menu items and what they should take care of as completed
marked the checklist item Document how config files and environment variables are handled in the admin manual as completed
marked the checklist item Document this in the admin and user parts of the documentation as completed
marked the checklist item Find out why this is a direct dependency, and probably remove. as completed
marked the checklist item Document in developer reference that apps can rely on PostgreSQL-only features as completed
marked the checklist item Document in dev reference that apps can and should use it as completed
marked the checklist item Document how to add own JS dependencies for apps in dev reference as completed
marked the checklist item Document in dev reference what apps should do to get a ocnsistent material design, and how to use partials from core, etc. as completed
marked the checklist item Document in user manual how to get a native feeling with the PWA (e.e. adding to homescreen on mobile phones) as completed
marked the checklist item Document in dev reference how to control caching, add things to the serviceworker, etc/ as completed
marked the checklist item Document in admin manual how settings and preferences relate, and what preference scopes exist (site, group, person) as completed
marked the checklist item Document in user manual how to change personal preferences as completed
marked the checklist item Document preference best practices as completed
marked the checklist item Document in dev reference how to add own prefernces, and when to use preferences as completed
marked the checklist item Remove django-settings-context-processor and define better ways to handl the values it passes as completed
marked the checklist item Docuemnt in dev reference that it can be used and when to do so (definition of such attributes in
Formclass vs. template) as completedmarked the checklist item Best practices for form layout as completed
marked the checklist item Document in dev reference that it can and should be used as completed
marked the checklist item Document in dev reference that it can and should be used as completed
marked the checklist item Explain why corporate design matters as completed
marked the checklist item Explain why a good plaintext part also matters as completed
mentioned in merge request !2244
marked the checklist item Document in dev reference when to use it, and how to do so consistently as completed
marked the checklist item Explain why this can be a security risk, and how to prevent this as completed
marked the checklist item Document in dev reference how to use this as completed
marked the checklist item Discuss whether we need this. If there is a proxy, it probably should handle the maintenance page itself anyway… as completed
marked the checklist item Document in admin reference (how to set upo, why it is needed, how to do maintenance) as completed
marked the checklist item Document in dev reference how to use and when to use asynchronous tasks as completed
marked the checklist item Determine whether this should be an optional dependency as completed
marked the checklist item Discuss migration to uwsgi caching backend as default as completed
marked the checklist item Dcoument in dev reference when to use model extensions (and when to use a separate model instead), and hwo this works, and its limitations as completed
marked the checklist item Discuss whether we want to support data pseudonymisation out of the box as completed
marked the checklist item Discuss whether this should be optional as completed
marked the checklist item Document in dev reference that it can and should be used as completed
marked the checklist item Document in dev reference that it can and should be used as completed
marked the checklist item Best practices as completed
marked the checklist item Security implications as completed
marked the checklist item Legal requirements as completed
marked the checklist item Discuss whether there should be a frontend as completed
marked the checklist item Document in dev reference whe nand how to use it as completed
marked the checklist item Remove (and ensure that apps that currently need it depend on it directly; probably only Exlibris) as completed
marked the checklist item Document in dev reference how to fil lthe global search index as completed
marked the checklist item Document in admin manual how to do backups, including best practices as completed
marked the checklist item Document in dev reference how to declare meta-data of apps as completed
marked the checklist item Define rules to require 2FA for views or parts of them as completed
marked the checklist item Document in dev reference that it can and should be used as completed
marked the checklist item Explain when to create a revision as completed
marked the checklist item Document in admin manual how to configure own icons as completed
marked the checklist item Document in admin manual what this is and how to use as completed
marked the checklist item Document in dev reference how to add own health checks, and when to do so as completed
marked the checklist item Document in dev reference that it is used, and what this means for queries as completed
marked the checklist item Document in admin manual what this is and how to use it as completed
marked the checklist item Provide a good Grafana dashboard with AlekSIS as completed
marked the checklist item Document in dev reference how to add own metrics as completed
marked the checklist item Get !2071 merged as completed
marked the checklist item Document in dev reference that it can and should be used (especially
FieldTracker) as completedmarked the checklist item Discuss whether this is really considered important enough to be in core as completed
marked the checklist item Get !2136 merged as completed
marked the checklist item Document in admin manual whichtools are available and how to use them as completed
marked the checklist item Check that we provide Celery progress everywhere we should as completed
marked the checklist item Document fo apps that his can and should be relied on when working with phone numbers as completed
marked the checklist item Document use of 2FA in the user manual as completed
marked the checklist item Document htis mechanism in the dev reference as completed
marked the checklist item Reevaluate AGPL licence and whether it is relevant for us or not as completed
marked the checklist item Document in dev reference how to let the user wait for a task result, when to do so, and when not as completed
marked the checklist item Verify that the field has a good widget by defualt as completed
marked the checklist item Find out where it is used (DashboardFeeds?) as completed
marked the checklist item Discuss whether it should be a core dependency as completed
marked the checklist item Resolve #363 as completed
marked the checklist item Discuss whether all of this should be in core, or rather in Winkel, or nowhere at all as completed
marked the checklist item Resolve #356 as completed
marked the checklist item Discuss whether we can suppor tonly Python >3.9 as completed
marked the checklist item Discuss whether we need app auto-discovery as completed
marked the checklist item Find out what it does, and whether it is needed in core or not as completed
marked the checklist item Discuss the above, and whther things like this should be a core dependency as completed