Upgrade Forgejo to our forked [xorm v1.4.0](https://code.forgejo.org/xorm/xorm/compare/v1.3.9-forgejo.12...v1.4.0), which is now named `code.forgejo.org/xorm/xorm` to reflect the current expectation that it is a permanent fork. A small number of API changes were made recently in https://code.forgejo.org/xorm/xorm/issues/120 which are accounted for in this PR, in addition to the module rename. ## Checklist The [contributor guide](https://forgejo.org/docs/next/contributor/) contains information that will be helpful to first time contributors. All work and communication must conform to Forgejo's [AI Agreement](https://codeberg.org/forgejo/governance/src/branch/main/AIAgreement.md). There also are a few [conditions for merging Pull Requests in Forgejo repositories](https://codeberg.org/forgejo/governance/src/branch/main/PullRequestsAgreement.md). You are also welcome to join the [Forgejo development chatroom](https://matrix.to/#/#forgejo-development:matrix.org). ### Documentation - [ ] I created a pull request [to the documentation](https://codeberg.org/forgejo/docs) to explain to Forgejo users how to use this change. - [x] I did not document these changes and I do not expect someone else to do it. ### Release notes - [ ] This change will be noticed by a Forgejo user or admin (feature, bug fix, performance, etc.). I suggest to include a release note for this change. - [x] This change is not visible to a Forgejo user or admin (refactor, dependency upgrade, etc.). I think there is no need to add a release note for this change. Reviewed-on: https://codeberg.org/forgejo/forgejo/pulls/12639 Reviewed-by: Otto <otto@codeberg.org>
102 lines
3.4 KiB
Go
102 lines
3.4 KiB
Go
// Copyright 2025 The Forgejo Authors. All rights reserved.
|
|
// SPDX-License-Identifier: GPL-3.0-or-later
|
|
|
|
package forgejo_migrations
|
|
|
|
import (
|
|
"context"
|
|
"fmt"
|
|
|
|
"forgejo.org/models/db"
|
|
"forgejo.org/modules/keying"
|
|
"forgejo.org/modules/log"
|
|
"forgejo.org/modules/secret"
|
|
"forgejo.org/modules/setting"
|
|
"forgejo.org/modules/timeutil"
|
|
|
|
"code.forgejo.org/xorm/xorm"
|
|
"code.forgejo.org/xorm/xorm/schemas"
|
|
)
|
|
|
|
func init() {
|
|
registerMigration(&Migration{
|
|
Description: "migrate `header_authorization_encrypted` of `webhook` table to store keying material",
|
|
Upgrade: migrateWebhookSecrets,
|
|
})
|
|
}
|
|
|
|
func migrateWebhookSecrets(x *xorm.Engine) error {
|
|
type Webhook struct {
|
|
ID int64 `xorm:"pk autoincr"`
|
|
RepoID int64 `xorm:"INDEX"` // An ID of 0 indicates either a default or system webhook
|
|
OwnerID int64 `xorm:"INDEX"`
|
|
HeaderAuthorizationEncrypted []byte `xorm:"BLOB"`
|
|
|
|
CreatedUnix timeutil.TimeStamp `xorm:"INDEX created"`
|
|
UpdatedUnix timeutil.TimeStamp `xorm:"INDEX updated"`
|
|
}
|
|
|
|
return db.WithTx(db.DefaultContext, func(ctx context.Context) error {
|
|
sess := db.GetEngine(ctx)
|
|
|
|
switch x.Dialect().URI().DBType {
|
|
case schemas.MYSQL:
|
|
if _, err := sess.Exec("ALTER TABLE `webhook` MODIFY `header_authorization_encrypted` BLOB"); err != nil {
|
|
return err
|
|
}
|
|
case schemas.SQLITE:
|
|
if _, err := sess.Exec("ALTER TABLE `webhook` RENAME COLUMN `header_authorization_encrypted` TO `header_authorization_encrypted_backup`"); err != nil {
|
|
return err
|
|
}
|
|
if _, err := sess.Exec("ALTER TABLE `webhook` ADD COLUMN `header_authorization_encrypted` BLOB"); err != nil {
|
|
return err
|
|
}
|
|
if _, err := sess.Exec("UPDATE `webhook` SET `header_authorization_encrypted` = `header_authorization_encrypted_backup`"); err != nil {
|
|
return err
|
|
}
|
|
if _, err := sess.Exec("ALTER TABLE `webhook` DROP COLUMN `header_authorization_encrypted_backup`"); err != nil {
|
|
return err
|
|
}
|
|
case schemas.POSTGRES:
|
|
if _, err := sess.Exec("ALTER TABLE `webhook` ALTER COLUMN `header_authorization_encrypted` SET DATA TYPE bytea USING header_authorization_encrypted::text::bytea"); err != nil {
|
|
return err
|
|
}
|
|
}
|
|
|
|
key := keying.Webhook
|
|
|
|
oldEncryptionKey := setting.SecretKey
|
|
messages := make([]string, 0, 100)
|
|
ids := make([]int64, 0, 100)
|
|
|
|
err := db.Iterate(ctx, nil, func(ctx context.Context, bean *Webhook) error {
|
|
if len(bean.HeaderAuthorizationEncrypted) == 0 {
|
|
return nil
|
|
}
|
|
|
|
secretBytes, err := secret.DecryptSecret(oldEncryptionKey, string(bean.HeaderAuthorizationEncrypted))
|
|
if err != nil {
|
|
messages = append(messages, fmt.Sprintf("webhook.id=%d, webhook.repo_id=%d, webhook.owner_id=%d: secret.DecryptSecret(): %v", bean.ID, bean.RepoID, bean.OwnerID, err))
|
|
ids = append(ids, bean.ID)
|
|
return nil
|
|
}
|
|
|
|
bean.HeaderAuthorizationEncrypted = key.Encrypt([]byte(secretBytes), keying.ColumnAndID("header_authorization_encrypted", bean.ID))
|
|
_, err = sess.Cols("header_authorization_encrypted").ID(bean.ID).Update(bean)
|
|
return err
|
|
})
|
|
|
|
if err == nil {
|
|
if len(ids) > 0 {
|
|
log.Error("migration[v14a_migrate_webhook_authorization]: The following webhook were found to be corrupted and removed from the database.")
|
|
for _, message := range messages {
|
|
log.Error("migration[v14a_migrate_webhook_authorization]: %s", message)
|
|
}
|
|
|
|
_, err = sess.In("id", ids).NoAutoCondition().NoAutoTime().Delete(&Webhook{})
|
|
}
|
|
}
|
|
return err
|
|
})
|
|
}
|