From a42012d9c082519dd4a4dba6632e1907f3c44a54 Mon Sep 17 00:00:00 2001 From: NuklearRabbit <145918611+NuklearRabbit@users.noreply.github.com> Date: Wed, 2 Sep 2026 23:37:29 +0200 Subject: [PATCH 1/2] hygiene: prepare MobilityOps for public release --- .env.example | 4 ++++ .gitea/workflows/ci.yml | 2 ++ .gitleaksignore | 4 ++++ SECURITY.md | 2 +- compose.yaml | 2 ++ n8n/workflows/MANIFEST.md | 2 +- n8n/workflows/fleet-ops-alert-receiver.json | 2 +- 7 files changed, 15 insertions(+), 3 deletions(-) create mode 100644 .gitleaksignore diff --git a/.env.example b/.env.example index 349b87e..f5266f4 100644 --- a/.env.example +++ b/.env.example @@ -86,6 +86,10 @@ N8N_ENCRYPTION_KEY=replace-me N8N_BASIC_AUTH_ACTIVE=true N8N_BASIC_AUTH_USER=admin N8N_BASIC_AUTH_PASSWORD=change-me +# Recipient and sender used by the importable alert workflow. Configure real, +# monitored addresses in the deployment environment; repository defaults stay synthetic. +MOBILITYOPS_ALERT_RECIPIENT=alerts@example.test +MOBILITYOPS_ALERT_SENDER=n8n@example.test MOBILITYOPS_CALLBACK_TOKEN=replace-me-n8n-callback-token # Sent as the X-Fleet-Ops-Trigger-Token header when Fleet Ops calls the n8n return- # processing webhook, so the webhook trigger can require Header Auth instead of being diff --git a/.gitea/workflows/ci.yml b/.gitea/workflows/ci.yml index 3aef1d3..1ae1495 100644 --- a/.gitea/workflows/ci.yml +++ b/.gitea/workflows/ci.yml @@ -12,6 +12,8 @@ permissions: jobs: acceptance: + # Never execute code from an untrusted public fork on the private runner. + if: ${{ gitea.event.pull_request.head.repo.full_name == gitea.repository }} runs-on: ubuntu-latest timeout-minutes: 60 steps: diff --git a/.gitleaksignore b/.gitleaksignore new file mode 100644 index 0000000..6f68e54 --- /dev/null +++ b/.gitleaksignore @@ -0,0 +1,4 @@ +81e3fd63bdbcb2e9c4ae1d709ea46f40537b6f62:backend/tests/test_data_quality.py:generic-api-key:869 +0091c57c7fd82ffda16da1edfe5fa5589c8f1e13:backend/tests/test_return.py:generic-api-key:93 +0091c57c7fd82ffda16da1edfe5fa5589c8f1e13:backend/tests/test_return.py:generic-api-key:122 +0091c57c7fd82ffda16da1edfe5fa5589c8f1e13:backend/tests/test_return.py:generic-api-key:127 diff --git a/SECURITY.md b/SECURITY.md index 9beb10f..0124648 100644 --- a/SECURITY.md +++ b/SECURITY.md @@ -15,7 +15,7 @@ release line only. Do not disclose suspected vulnerabilities through a public issue. -Report them privately to `jens@itworx.tech` with: +Report them privately to `security@itworx.tech` with: - the affected revision, endpoint or component; - reproduction steps and prerequisites; diff --git a/compose.yaml b/compose.yaml index e7c2cc5..c997696 100644 --- a/compose.yaml +++ b/compose.yaml @@ -107,6 +107,8 @@ services: N8N_BASIC_AUTH_PASSWORD: ${N8N_BASIC_AUTH_PASSWORD:-change-me} N8N_SECURE_COOKIE: "false" N8N_BLOCK_ENV_ACCESS_IN_NODE: "false" + MOBILITYOPS_ALERT_RECIPIENT: ${MOBILITYOPS_ALERT_RECIPIENT:-alerts@example.test} + MOBILITYOPS_ALERT_SENDER: ${MOBILITYOPS_ALERT_SENDER:-n8n@example.test} MOBILITYOPS_CALLBACK_TOKEN: ${MOBILITYOPS_CALLBACK_TOKEN:-replace-me-n8n-callback-token} ports: - "5678:5678" diff --git a/n8n/workflows/MANIFEST.md b/n8n/workflows/MANIFEST.md index 8e08085..e3feda9 100644 --- a/n8n/workflows/MANIFEST.md +++ b/n8n/workflows/MANIFEST.md @@ -121,4 +121,4 @@ this handler was not observed live. | Active status | Imported inactive by default; production deployment must publish it before enabling Alertmanager. | | Error Workflow | `Fleet Ops — Workflow Error Handler` (wired) | | Safety | Strict Alertmanager payload shape, bounded to 25 alerts and bounded text fields. | -| Checksum (sha256) | `3672ad3d14b65c603c8c3f2067197cc50372e9d4c2fc314d1c9b6aaf3ecef444` | +| Checksum (sha256) | `4eb1ae41c4e675a9bb51a43722a507da8a6eae8a6ce8649b7e3a57417911a418` | diff --git a/n8n/workflows/fleet-ops-alert-receiver.json b/n8n/workflows/fleet-ops-alert-receiver.json index 0da470e..8b27c1a 100644 --- a/n8n/workflows/fleet-ops-alert-receiver.json +++ b/n8n/workflows/fleet-ops-alert-receiver.json @@ -17,7 +17,7 @@ "id": "accept", "name": "Accept alert", "type": "n8n-nodes-base.respondToWebhook", "typeVersion": 1.4, "position": [740, 300] }, { - "parameters": {"toRecipients": "jens@itworx.tech", "subject": "={{ $('Validate and format').item.json.subject }}", "bodyContent": "={{ $('Validate and format').item.json.html }}", "additionalFields": {"from": "n8n@itworx.tech", "bodyContentType": "html"}}, + "parameters": {"toRecipients": "={{ $env.MOBILITYOPS_ALERT_RECIPIENT || 'alerts@example.test' }}", "subject": "={{ $('Validate and format').item.json.subject }}", "bodyContent": "={{ $('Validate and format').item.json.html }}", "additionalFields": {"from": "={{ $env.MOBILITYOPS_ALERT_SENDER || 'n8n@example.test' }}", "bodyContentType": "html"}}, "id": "email", "name": "Send owner email", "type": "n8n-nodes-base.microsoftOutlook", "typeVersion": 2, "position": [980, 300], "credentials": {"microsoftOutlookOAuth2Api": {"id": "EDTj3sOsganaoDVL", "name": "M365 n8n Shared Mailbox"}}, "retryOnFail": true, "maxTries": 3, "waitBetweenTries": 1000 From 2d92084489533a32e82c23f34de3885c283c2e9c Mon Sep 17 00:00:00 2001 From: NuklearRabbit <145918611+NuklearRabbit@users.noreply.github.com> Date: Thu, 3 Sep 2026 01:13:21 +0200 Subject: [PATCH 2/2] test: stabilize browser assertions under CI load --- frontend/playwright.config.ts | 4 ++++ 1 file changed, 4 insertions(+) diff --git a/frontend/playwright.config.ts b/frontend/playwright.config.ts index 108705a..62cc300 100644 --- a/frontend/playwright.config.ts +++ b/frontend/playwright.config.ts @@ -6,6 +6,10 @@ export default defineConfig({ // it mutates demo data via a reset and is run explicitly, not as part of the suite. testIgnore: process.env.CAPTURE_EVIDENCE === "1" ? undefined : "**/_*.spec.ts", timeout: 30_000, + // CI exercises the browser while image scans and container services share the + // same runner. Keep assertions strict, but allow successful API-backed route + // transitions enough time to render under that bounded load. + expect: { timeout: 15_000 }, fullyParallel: false, workers: 1, snapshotPathTemplate: "{testDir}/__screenshots__/{arg}{ext}",