Skip to content

Merge to main pre-release - #1323

Merged
donaldgray merged 199 commits into
mainfrom
develop
Oct 5, 2026
Merged

donaldgray merged 199 commits into
mainfrom
develop

Conversation

@donaldgray

Copy link
Copy Markdown
Member

What does this change?

Merge latest develop to main. All changes have previously been approved.

dependabot Bot and others added 30 commits June 22, 2026 07:13
Bumps [actions/checkout](https://github.com/actions/checkout) from 6 to 7.
- [Release notes](https://github.com/actions/checkout/releases)
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md)
- [Commits](actions/checkout@v6...v7)

---
updated-dependencies:
- dependency-name: actions/checkout
  dependency-version: '7'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Bumps [actions/setup-dotnet](https://github.com/actions/setup-dotnet) from 5 to 6.
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](actions/setup-dotnet@v5...v6)

---
updated-dependencies:
- dependency-name: actions/setup-dotnet
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Add note to PR template around considerations
- Tixghten GetBatchEntitiesBase
- Add additional test
Bumps [actions/cache](https://github.com/actions/cache) from 5 to 6.
- [Release notes](https://github.com/actions/cache/releases)
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md)
- [Commits](actions/cache@v5...v6)

---
updated-dependencies:
- dependency-name: actions/cache
  dependency-version: '6'
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
…setup-dotnet-6

Bump actions/setup-dotnet from 5 to 6
…checkout-7

Bump actions/checkout from 6 to 7
Additional bulk adjunct query operations
Add additional query endpoints for adjunct batches
Remove DLCS.Mock as no longer used
HandleDelete -> ConvertDeleteToHttp returns NoContent() = 204
(HydraController.cs:174); the 202 annotation was a lie. No behaviour
change. Hygiene-sprint mechanical track (cards SPA-08, XC-01).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
DeleteSpace uses HandleDelete -> NoContent() = 204 with an empty body;
the annotation promised a Space body that never arrives. No behaviour
change. Hygiene-sprint mechanical track (cards SPA-09, XC-01).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
All 13 ProblemDetails ProducesResponseType annotations (PUT, PATCH and
legacy POST) now declare typeof(Error), matching the actual HydraProblem
bodies and every other controller. These were the only ProblemDetails
annotations in API. No behaviour change. Hygiene-sprint mechanical
track (card XC-05).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
PUT /adjuncts/{id} is an upsert returning 201 for a new adjunct, and
deliberately returns a single Adjunct (adjuncts.Single().ToHydra), never
a collection. Was annotated 200-only with HydraCollection<Adjunct>. No
behaviour change. Hygiene-sprint mechanical track (card XC-11).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The no-adjuncts-found path returns HydraProblem(..., 400, ...)
(CustomerAdjunctsController.cs:65), not 404. No behaviour change.
Hygiene-sprint mechanical track.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
role is freely settable on POST and PUT (CustomHeaderConverter copies
it; UpdateCustomHeader writes it) and the docs table says readonly
False. Only generated vocab/Hydra docs change. Hygiene-sprint
mechanical track (card ACC-04).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
The @id-must-be-empty rule reported a named query error on custom
header requests; the converter parameter was likewise misnamed
hydraNamedQuery. Hygiene-sprint mechanical track (card ACC-05).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Ties made property emission order undefined:
- ImageStorage: adjunctSize/lastChecked/checkingInProgress all 55 ->
  55/56/57
- ApiKey: key/secret both 12 -> 12/13
- PortalUser: created/roles both 13 -> 13/14 (enabled 14 -> 15 to keep
  the sequence)

Serialisation ordering only; no schema or value change. Hygiene-sprint
mechanical track (card ACC-07).

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
JackLewis-digirati and others added 27 commits September 11, 2026 11:46
Stop roles and tags from being wiped on PATCH
Update comment for IncludeRelationsForProjections
Introduces IAwsClientProvider<T> as consistent interface for AWS all
clients.

Existing SetupAWS registers AmbientAwsClientProvider<T> as an open generic,
this hands out the client registered in DI (as before) using standard
credentials chain.
WithCustomerScoped* methods registers a
CustomerScopedAwsClientProvider<T> which is closed generic and overrides
above.

Customer-scoped clients use a role assumed per-customer, tagging the STS
session with the customer. The current customer is held in an
AsyncLocal via ICustomerAwsContext.

Credentials are cached per-customer and shared across client types, so a
customer costs a single STS session rather than one per client.
AssumeRoleAWSCredentials refreshes itself, so cached entries stay valid.

Assuming a role is skipped when LocalStack is in use, as LocalStack does
not support the required STS operations.
S3BucketReader, S3BucketWriter, TopicPublisher and MediaConvertWrapper
now take IAwsClientProvider<T> rather than the client itself, fetching
the client for the current operation on each call. Consumers are
unaffected, they continue to inject IBucketReader, ITopicPublisher etc.
and no registration lifetimes change.

Portal registers IAmazonS3 directly rather than via SetupAWS, so would
have had no IAwsClientProvider<> registration; it now calls
AddAmbientAwsClientProviders() to pick up the default registrations.

SQS and CloudFront clients are untouched - neither has a per-customer
boundary, and the SQS listener polls before any customer is known.
Engine now opts in to customer-scoped S3, SNS and MediaConvert clients.
SQS is left ambient as the queue listener polls before any customer is
known.

The customer is recorded at the three entry points that reach AWS:
AssetIngester and AdjunctIngester (covering both the queue handler and
the synchronous ingest endpoints) and TranscodeCompleteHandler.

Which mode is in use is logged on startup, as this is a security
control.
No expectation this will be inherited, silences CA1816 warning around
calling GC.SuppressFinalize
Prefix with CustomerId, rather than JobId for access restriction.
Make percent requests that exceed 100% bound to 100%
Modifying roles should cause a reingest to happen
@donaldgray
donaldgray requested a review from a team as a code owner October 2, 2026 11:13
@donaldgray
donaldgray merged commit e7158e5 into main Oct 5, 2026
27 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants