From e7424e70aa9eeed4c75689decf1027c0f5184e56 Mon Sep 17 00:00:00 2001 From: Chirag Aggarwal Date: Mon, 2 Mar 2026 23:14:08 +0530 Subject: [PATCH 1/6] chore: improve sdk diff check --- src/Appwrite/Platform/Tasks/SDKs.php | 79 ++++++++++++++++++---------- 1 file changed, 51 insertions(+), 28 deletions(-) diff --git a/src/Appwrite/Platform/Tasks/SDKs.php b/src/Appwrite/Platform/Tasks/SDKs.php index a480f4cb4f..1ec23d5f16 100644 --- a/src/Appwrite/Platform/Tasks/SDKs.php +++ b/src/Appwrite/Platform/Tasks/SDKs.php @@ -486,9 +486,9 @@ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND $useAi = ($ai !== 'no'); $apiKey = $useAi ? System::getEnv('_APP_ASSISTANT_OPENAI_API_KEY', '') : ''; $aiChangelog = ''; // Track AI-generated changelog for PR description - Console::info('Checking for _APP_ASSISTANT_OPENAI_API_KEY... [' . (! empty($apiKey) ? 'FOUND' : 'NOT FOUND') . ']'); + if (! empty($apiKey) && ! $examplesOnly) { - Console::info("Using AI to determine version bump and changelog for {$language['name']} SDK..."); + Console::info("Analyzing SDK changes with AI..."); $aiResult = $this->generateVersionAndChangelog($language, $result); if ($aiResult !== null) { @@ -502,6 +502,12 @@ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND // Update the changelog file $this->updateChangelogFile($language['changelog'], $newVersion, $newChangelog); + // Also update CHANGELOG.md in the generated SDK directory + $sdkChangelogPath = $result . '/CHANGELOG.md'; + if (file_exists($sdkChangelogPath)) { + $this->updateChangelogFile($sdkChangelogPath, $newVersion, $newChangelog); + } + // Reload the language config with updated values $language['version'] = $newVersion; @@ -512,10 +518,8 @@ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND } catch (\Throwable $exception) { Console::error($exception->getMessage()); } - - Console::success("AI determined version: {$newVersion} ({$aiResult['versionBump']} bump)"); } else { - Console::warning('AI version generation failed, using existing version'); + Console::warning('AI analysis failed, using existing version'); } } @@ -524,33 +528,45 @@ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND $repoBranch = $language['repoBranch'] ?? 'main'; if ($git && ! empty($gitUrl)) { + Console::info("Preparing {$language['name']} SDK repository..."); + \exec('rm -rf ' . $target . ' && \ mkdir -p ' . $target . ' && \ cd ' . $target . ' && \ - git init && \ + git init --quiet && \ git config core.ignorecase false && \ git config pull.rebase false && \ + git config advice.defaultBranchName false && \ git remote add origin ' . $gitUrl . ' && \ - git fetch origin && \ + git fetch origin --quiet --no-tags --depth 1 ' . $repoBranch . ' 2>&1 | grep -v "^remote:" | grep -v "^From " | grep -v "^ \* " || true && \ (git checkout -f ' . $repoBranch . ' 2>/dev/null || git checkout -b ' . $repoBranch . ') && \ - git pull origin ' . $repoBranch . ' && \ + git pull origin ' . $repoBranch . ' --quiet --no-tags 2>&1 | grep -v "^From " | grep -v "^ \* " || true && \ (git checkout -f ' . $gitBranch . ' 2>/dev/null || git checkout -b ' . $gitBranch . ') && \ - (git fetch origin ' . $gitBranch . ' 2>/dev/null || git push -u origin ' . $gitBranch . ') && \ + (git fetch origin ' . $gitBranch . ' --quiet --no-tags --depth 1 2>/dev/null || git push -u origin ' . $gitBranch . ' --quiet 2>&1 | grep -v "^remote:" || true) && \ git reset --hard origin/' . $gitBranch . ' 2>/dev/null || true && \ - (test -d .github && cp -r .github /tmp/.github-backup-$$ || true) && \ - git rm -rf --cached . && \ - git clean -fdx -e .git -e .github && \ + (if [ -d .github ]; then cp -r .github /tmp/.github-backup-$$ 2>/dev/null; fi) && \ + git rm -rf --cached . 2>/dev/null && \ + git clean -fdx -e .git -e .github 2>/dev/null && \ cp -r ' . $result . '/. ' . $target . '/ && \ - (test -d /tmp/.github-backup-$$ && cp -rn /tmp/.github-backup-$$/.github . && rm -rf /tmp/.github-backup-$$ || true) && \ + (if [ -d /tmp/.github-backup-$$/.github ]; then cp -rn /tmp/.github-backup-$$/.github . 2>/dev/null && rm -rf /tmp/.github-backup-$$; fi) && \ git add -A && \ - git commit -m "' . $message . '" && \ - git push -u origin ' . $gitBranch . ' - '); + git commit -m "' . $message . '" --quiet && \ + git push -u origin ' . $gitBranch . ' --quiet 2>&1 | grep -E "^(To | |[0-9a-f]+\\.\\.[0-9a-f]+)" || true + ', $gitOutput, $gitReturnCode); + + if ($gitReturnCode !== 0) { + Console::warning("Git operations completed with warnings (exit code: {$gitReturnCode})"); + } Console::success("Pushed {$language['name']} SDK to {$gitUrl}"); if ($git) { $prTitle = "feat: {$language['name']} SDK update for version {$language['version']}"; - $prBody = "This PR contains updates to the {$language['name']} SDK for version {$language['version']} . "; + + // Build PR body with AI changelog if available + $prBody = "This PR contains updates to the {$language['name']} SDK for version {$language['version']}."; + if (!empty($aiChangelog) && $aiChangelog !== '* No user-facing SDK changes.') { + $prBody .= "\n\n## Changes\n\n{$aiChangelog}"; + } $repoName = $language['gitUserName'] . '/' . $language['gitRepoName']; Console::info("Creating pull request for {$language['name']} SDK..."); @@ -778,10 +794,12 @@ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND - `patch`: backward-compatible fixes or small improvements. Changelog rules: - - Include only user-facing SDK changes. - - Exclude internal/project-infra changes (for example `.github/workflows/**`, `.github/ISSUE_TEMPLATE/**`, CI/release automation/template cleanup). - - Never add "Internal housekeeping" style entries. - - If only excluded changes exist, return exactly: `* No user-facing SDK changes.` + - Keep entries brief and direct (15 words or less each) + - USER-FACING: Source code changes, commands/params, docs, examples, scripts + - EXCLUDE: .github/, CI configs, internal tooling + - Format: "Breaking: Removed X" or "Added Y feature" or "Fixed Z bug" + - One change per bullet, avoid combining multiple changes + - If no user-facing changes: `* No user-facing SDK changes.` Diff context: - Stats: {{diff_stats}} @@ -805,11 +823,13 @@ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ->setExcludePaths([ '.github/workflows/**', '.github/ISSUE_TEMPLATE/**', + '.git/**', ]) ->setMaxDiffLines(500) ->setUserId('sdk-analyst'); Console::info("Running DiffCheck for {$language['name']} SDK..."); + $result = (new DiffCheck())->run( runner: $adapter, base: DiffCheckRepository::remote($gitUrl, $repoBranch), @@ -819,7 +839,7 @@ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ); if (!$result['hasChanges']) { - Console::warning("No changes detected for {$language['name']} SDK"); + Console::info("✓ No changes detected - SDK is up to date"); return null; } @@ -831,15 +851,11 @@ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND return null; } - Console::log('AI raw response:'); - Console::log($responseContent); - Console::log('--- End of AI response ---'); - $parsed = json_decode($responseContent, true); if (json_last_error() !== JSON_ERROR_NONE) { Console::warning('Failed to parse AI response as JSON: ' . json_last_error_msg()); - Console::log('Raw response that failed to parse:'); + Console::log('Raw response:'); Console::log($responseContent); return null; @@ -850,7 +866,14 @@ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND return null; } - Console::info("AI analysis complete - Version bump: {$parsed['versionBump']}, New version: {$parsed['version']}"); + Console::success("✓ Analysis complete"); + Console::log(" Version: {$language['version']} → {$parsed['version']} ({$parsed['versionBump']} bump)"); + Console::log(" Changelog:"); + foreach (explode("\n", $parsed['changelog']) as $line) { + if (trim($line)) { + Console::log(" {$line}"); + } + } return [ 'version' => $parsed['version'], From e31843be4bcf88fe279df3141b4ca7fd29fcb92b Mon Sep 17 00:00:00 2001 From: Chirag Aggarwal Date: Mon, 2 Mar 2026 23:20:29 +0530 Subject: [PATCH 2/6] change --- src/Appwrite/Platform/Tasks/SDKs.php | 50 ++++++++++++++++++++++------ 1 file changed, 40 insertions(+), 10 deletions(-) diff --git a/src/Appwrite/Platform/Tasks/SDKs.php b/src/Appwrite/Platform/Tasks/SDKs.php index 1ec23d5f16..0bdfd44e49 100644 --- a/src/Appwrite/Platform/Tasks/SDKs.php +++ b/src/Appwrite/Platform/Tasks/SDKs.php @@ -887,6 +887,16 @@ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND } } + /** + * Get the SDK config file path + * + * @return string Path to the SDK config file + */ + protected function getSdkConfigPath(): string + { + return __DIR__ . '/../../../../app/config/sdks.php'; + } + /** * Update SDK version in the config file * @@ -897,7 +907,7 @@ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND */ private function updateSdkVersion(string $platform, string $sdkKey, string $newVersion): bool { - $configPath = __DIR__ . '/../../../../app/config/sdks.php'; + $configPath = $this->getSdkConfigPath(); if (! file_exists($configPath)) { Console::error("Config file not found: {$configPath}"); @@ -907,13 +917,13 @@ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND $content = file_get_contents($configPath); - // Find and replace the version for this specific SDK - // Pattern matches the version line in the SDK array - $pattern = '/(\[\s*[\'"]key[\'"]\s*=>\s*[\'"]' . preg_quote($sdkKey, '/') . '[\'"]\s*,[\s\S]*?[\'"]version[\'"]\s*=>\s*[\'"])([^\'"]+)([\'"])/m'; + // First, try to find inline version in SDK array (pattern 1) + // Pattern matches: ['key' => 'nodejs', ... 'version' => '22.1.2'] + $inlinePattern = '/(\[\s*[\'"]key[\'"]\s*=>\s*[\'"]' . preg_quote($sdkKey, '/') . '[\'"]\s*,[\s\S]*?[\'"]version[\'"]\s*=>\s*[\'"])([^\'"]+)([\'"])/m'; - if (preg_match($pattern, $content, $matches)) { + if (preg_match($inlinePattern, $content, $matches)) { $oldVersion = $matches[2]; - $newContent = preg_replace($pattern, '${1}' . $newVersion . '${3}', $content); + $newContent = preg_replace($inlinePattern, '${1}' . $newVersion . '${3}', $content); if (file_put_contents($configPath, $newContent) !== false) { Console::success("Updated {$sdkKey} version from {$oldVersion} to {$newVersion} in config"); @@ -924,11 +934,31 @@ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND return false; } - } else { - Console::warning("Could not find version entry for {$sdkKey} in config"); - - return false; } + + // Second, try to find version in array format (pattern 2) + // Pattern matches: 'nodejs' => '22.1.2', or "nodejs" => "22.1.2", + // Also handles extra whitespace: 'nodejs' => '22.1.2', + $arrayPattern = '/([\'"]' . preg_quote($sdkKey, '/') . '[\'"]\s*=>\s*[\'"])([^\'"]+)([\'"],)/m'; + + if (preg_match($arrayPattern, $content, $matches)) { + $oldVersion = $matches[2]; + $newContent = preg_replace($arrayPattern, '${1}' . $newVersion . '${3}', $content); + + if (file_put_contents($configPath, $newContent) !== false) { + Console::success("Updated {$sdkKey} version from {$oldVersion} to {$newVersion} in config"); + + return true; + } else { + Console::error('Failed to write config file'); + + return false; + } + } + + Console::warning("Could not find version entry for {$sdkKey} in config"); + + return false; } /** From 94bd9661b3285af3dfb8578d4cac202821821bc0 Mon Sep 17 00:00:00 2001 From: Chirag Aggarwal Date: Mon, 2 Mar 2026 23:24:48 +0530 Subject: [PATCH 3/6] change --- src/Appwrite/Platform/Tasks/SDKs.php | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/src/Appwrite/Platform/Tasks/SDKs.php b/src/Appwrite/Platform/Tasks/SDKs.php index 0bdfd44e49..34fa0b5d2a 100644 --- a/src/Appwrite/Platform/Tasks/SDKs.php +++ b/src/Appwrite/Platform/Tasks/SDKs.php @@ -798,7 +798,7 @@ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND - USER-FACING: Source code changes, commands/params, docs, examples, scripts - EXCLUDE: .github/, CI configs, internal tooling - Format: "Breaking: Removed X" or "Added Y feature" or "Fixed Z bug" - - One change per bullet, avoid combining multiple changes + - Group related changes together (e.g., "Added A, B, and C options" not separate bullets) - If no user-facing changes: `* No user-facing SDK changes.` Diff context: From f41c19ed3eb34352fb87cf6a34416a3a031fa9a4 Mon Sep 17 00:00:00 2001 From: Chirag Aggarwal Date: Mon, 2 Mar 2026 23:26:48 +0530 Subject: [PATCH 4/6] improve prompt --- src/Appwrite/Platform/Tasks/SDKs.php | 83 +++++++++++++++++----------- 1 file changed, 51 insertions(+), 32 deletions(-) diff --git a/src/Appwrite/Platform/Tasks/SDKs.php b/src/Appwrite/Platform/Tasks/SDKs.php index 34fa0b5d2a..0e37940a59 100644 --- a/src/Appwrite/Platform/Tasks/SDKs.php +++ b/src/Appwrite/Platform/Tasks/SDKs.php @@ -781,38 +781,57 @@ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ); $prompt = <<", + "changelog": [ + "", + "" + ] + } + PROMPT; $options = (new DiffCheckOptions()) ->setSchema($schema) From feedd0eb4a5860d85ac138cce7f56ea74849ae4b Mon Sep 17 00:00:00 2001 From: Chirag Aggarwal Date: Mon, 2 Mar 2026 23:30:47 +0530 Subject: [PATCH 5/6] improve prompt --- src/Appwrite/Platform/Tasks/SDKs.php | 10 ---------- 1 file changed, 10 deletions(-) diff --git a/src/Appwrite/Platform/Tasks/SDKs.php b/src/Appwrite/Platform/Tasks/SDKs.php index 0e37940a59..949dbb3e6b 100644 --- a/src/Appwrite/Platform/Tasks/SDKs.php +++ b/src/Appwrite/Platform/Tasks/SDKs.php @@ -821,16 +821,6 @@ THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND ```diff {{diff}} ``` - - Respond with only valid JSON in this exact structure — no markdown fencing, no commentary: - { - "bump": "major" | "minor" | "patch", - "version": "", - "changelog": [ - "", - "" - ] - } PROMPT; $options = (new DiffCheckOptions()) From 598c71fb118280bf3d0c0e4ef2889fd44d181ab8 Mon Sep 17 00:00:00 2001 From: Hemachandar <132386067+hmacr@users.noreply.github.com> Date: Tue, 3 Mar 2026 00:15:09 +0530 Subject: [PATCH 6/6] Move VCS events APIs to Modules (#11403) * Move VCS events APIs to Modules * trait * lint * fix external flow * fix overriden vars * feedback --- app/config/services.php | 2 +- app/controllers/api/vcs.php | 705 ------------------ .../Http/GitHub/Authorize/External/Update.php | 141 ++++ .../Modules/VCS/Http/GitHub/Deployment.php | 523 +++++++++++++ .../Modules/VCS/Http/GitHub/Events/Create.php | 244 ++++++ .../Platform/Modules/VCS/Services/Http.php | 6 + 6 files changed, 915 insertions(+), 706 deletions(-) delete mode 100644 app/controllers/api/vcs.php create mode 100644 src/Appwrite/Platform/Modules/VCS/Http/GitHub/Authorize/External/Update.php create mode 100644 src/Appwrite/Platform/Modules/VCS/Http/GitHub/Deployment.php create mode 100644 src/Appwrite/Platform/Modules/VCS/Http/GitHub/Events/Create.php diff --git a/app/config/services.php b/app/config/services.php index 0bbba96032..a99501c530 100644 --- a/app/config/services.php +++ b/app/config/services.php @@ -188,7 +188,7 @@ return [ 'name' => 'VCS', 'subtitle' => 'The VCS service allows you to interact with providers like GitHub, GitLab etc.', 'description' => '', - 'controller' => 'api/vcs.php', + 'controller' => '', // Uses modules 'sdk' => false, 'docs' => false, 'docsUrl' => '', diff --git a/app/controllers/api/vcs.php b/app/controllers/api/vcs.php deleted file mode 100644 index 6dd18ed0f3..0000000000 --- a/app/controllers/api/vcs.php +++ /dev/null @@ -1,705 +0,0 @@ -getAttribute('resourceType'); - - if ($resourceType !== "function" && $resourceType !== "site") { - continue; - } - - $projectId = $repository->getAttribute('projectId'); - $project = $authorization->skip(fn () => $dbForPlatform->getDocument('projects', $projectId)); - if ($project->isEmpty()) { - throw new Exception(Exception::PROJECT_NOT_FOUND, 'Repository references non-existent project'); - } - $dbForProject = $getProjectDB($project); - - $resourceCollection = $resourceType === "function" ? 'functions' : 'sites'; - $resourceId = $repository->getAttribute('resourceId'); - $resource = $authorization->skip(fn () => $dbForProject->getDocument($resourceCollection, $resourceId)); - $resourceInternalId = $resource->getSequence(); - - $deploymentId = ID::unique(); - $repositoryId = $repository->getId(); - $repositoryInternalId = $repository->getSequence(); - $providerRepositoryId = $repository->getAttribute('providerRepositoryId'); - $installationId = $repository->getAttribute('installationId'); - $installationInternalId = $repository->getAttribute('installationInternalId'); - $productionBranch = $resource->getAttribute('providerBranch'); - $activate = false; - - if ($providerBranch == $productionBranch && $external === false) { - $activate = true; - } - - $owner = $github->getOwnerName($providerInstallationId) ?? ''; - try { - $repositoryName = $github->getRepositoryName($providerRepositoryId) ?? ''; - if (empty($repositoryName)) { - throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); - } - } catch (RepositoryNotFound $e) { - throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); - } - - if (empty($repositoryName)) { - throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); - } - - $isAuthorized = !$external; - - if (!$isAuthorized && !empty($providerPullRequestId)) { - if (\in_array($providerPullRequestId, $repository->getAttribute('providerPullRequestIds', []))) { - $isAuthorized = true; - } - } - - $commentStatus = $isAuthorized ? 'waiting' : 'failed'; - $protocol = System::getEnv('_APP_OPTIONS_FORCE_HTTPS') === 'disabled' ? 'http' : 'https'; - $hostname = $platform['consoleHostname'] ?? ''; - - $authorizeUrl = $protocol . '://' . $hostname . "/console/git/authorize-contributor?projectId={$projectId}&installationId={$installationId}&repositoryId={$repositoryId}&providerPullRequestId={$providerPullRequestId}"; - - $action = $isAuthorized ? ['type' => 'logs'] : ['type' => 'authorize', 'url' => $authorizeUrl]; - - $latestCommentId = ''; - - if (!empty($providerPullRequestId) && $resource->getAttribute('providerSilentMode', false) === false) { - $latestComment = $authorization->skip(fn () => $dbForPlatform->findOne('vcsComments', [ - Query::equal('providerRepositoryId', [$providerRepositoryId]), - Query::equal('providerPullRequestId', [$providerPullRequestId]), - Query::orderDesc('$createdAt'), - ])); - - if (!$latestComment->isEmpty()) { - $latestCommentId = $latestComment->getAttribute('providerCommentId', ''); - - $retries = 0; - $lockAcquired = false; - - while ($retries < 9) { - $retries++; - - try { - $dbForPlatform->createDocument('vcsCommentLocks', new Document([ - '$id' => $latestCommentId - ])); - $lockAcquired = true; - break; - } catch (\Throwable $err) { - if ($retries >= 9) { - Console::warning("Error creating vcs comment lock for " . $latestCommentId . ": " . $err->getMessage()); - } - - \sleep(1); - } - } - - if ($lockAcquired) { - // Wrap in try/finally to ensure lock file gets deleted - try { - $comment = new Comment($platform); - $comment->parseComment($github->getComment($owner, $repositoryName, $latestCommentId)); - $comment->addBuild($project, $resource, $resourceType, $commentStatus, $deploymentId, $action, ''); - - $latestCommentId = \strval($github->updateComment($owner, $repositoryName, $latestCommentId, $comment->generateComment())); - } finally { - $authorization->skip(fn () => $dbForPlatform->deleteDocument('vcsCommentLocks', $latestCommentId)); - } - } - } else { - $comment = new Comment($platform); - $comment->addBuild($project, $resource, $resourceType, $commentStatus, $deploymentId, $action, ''); - $latestCommentId = \strval($github->createComment($owner, $repositoryName, $providerPullRequestId, $comment->generateComment())); - - if (!empty($latestCommentId)) { - $teamId = $project->getAttribute('teamId', ''); - - $latestComment = $authorization->skip(fn () => $dbForPlatform->createDocument('vcsComments', new Document([ - '$id' => ID::unique(), - '$permissions' => [ - Permission::read(Role::team(ID::custom($teamId))), - Permission::update(Role::team(ID::custom($teamId), 'owner')), - Permission::update(Role::team(ID::custom($teamId), 'developer')), - Permission::delete(Role::team(ID::custom($teamId), 'owner')), - Permission::delete(Role::team(ID::custom($teamId), 'developer')), - ], - 'installationInternalId' => $installationInternalId, - 'installationId' => $installationId, - 'projectInternalId' => $project->getSequence(), - 'projectId' => $project->getId(), - 'providerRepositoryId' => $providerRepositoryId, - 'providerBranch' => $providerBranch, - 'providerPullRequestId' => $providerPullRequestId, - 'providerCommentId' => $latestCommentId - ]))); - } - } - } elseif (!empty($providerBranch)) { - $latestComments = $authorization->skip(fn () => $dbForPlatform->find('vcsComments', [ - Query::equal('providerRepositoryId', [$providerRepositoryId]), - Query::equal('providerBranch', [$providerBranch]), - Query::orderDesc('$createdAt'), - ])); - - foreach ($latestComments as $comment) { - $latestCommentId = $comment->getAttribute('providerCommentId', ''); - - $retries = 0; - $lockAcquired = false; - - while ($retries < 9) { - $retries++; - - try { - $dbForPlatform->createDocument('vcsCommentLocks', new Document([ - '$id' => $latestCommentId - ])); - $lockAcquired = true; - break; - } catch (\Throwable $err) { - if ($retries >= 9) { - Console::warning("Error creating vcs comment lock for " . $latestCommentId . ": " . $err->getMessage()); - } - - \sleep(1); - } - } - - if ($lockAcquired) { - // Wrap in try/finally to ensure lock file gets deleted - try { - $comment = new Comment($platform); - $comment->parseComment($github->getComment($owner, $repositoryName, $latestCommentId)); - $comment->addBuild($project, $resource, $resourceType, $commentStatus, $deploymentId, $action, ''); - - $latestCommentId = \strval($github->updateComment($owner, $repositoryName, $latestCommentId, $comment->generateComment())); - } finally { - $authorization->skip(fn () => $dbForPlatform->deleteDocument('vcsCommentLocks', $latestCommentId)); - } - } - } - } - - if (!$isAuthorized) { - $resourceName = $resource->getAttribute('name'); - $projectName = $project->getAttribute('name'); - $name = "{$resourceName} ({$projectName})"; - $message = 'Authorization required for external contributor.'; - - $providerRepositoryId = $repository->getAttribute('providerRepositoryId'); - try { - $repositoryName = $github->getRepositoryName($providerRepositoryId) ?? ''; - if (empty($repositoryName)) { - throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); - } - } catch (RepositoryNotFound $e) { - throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); - } - $owner = $github->getOwnerName($providerInstallationId); - $github->updateCommitStatus($repositoryName, $providerCommitHash, $owner, 'failure', $message, $authorizeUrl, $name); - continue; - } - - if ($external) { - $pullRequestResponse = $github->getPullRequest($owner, $repositoryName, $providerPullRequestId); - $providerRepositoryName = $pullRequestResponse['head']['repo']['owner']['login']; - $providerRepositoryOwner = $pullRequestResponse['head']['repo']['name']; - } - - $commands = []; - if (!empty($resource->getAttribute('installCommand', ''))) { - $commands[] = $resource->getAttribute('installCommand', ''); - } - if (!empty($resource->getAttribute('buildCommand', ''))) { - $commands[] = $resource->getAttribute('buildCommand', ''); - } - if (!empty($resource->getAttribute('commands', ''))) { - $commands[] = $resource->getAttribute('commands', ''); - } - - $deployment = $authorization->skip(fn () => $dbForProject->createDocument('deployments', new Document([ - '$id' => $deploymentId, - '$permissions' => [ - Permission::read(Role::any()), - Permission::update(Role::any()), - Permission::delete(Role::any()), - ], - 'resourceId' => $resourceId, - 'resourceInternalId' => $resourceInternalId, - 'resourceType' => $resourceCollection, - 'entrypoint' => $resource->getAttribute('entrypoint', ''), - 'buildCommands' => \implode(' && ', $commands), - 'startCommand' => $resource->getAttribute('startCommand', ''), - 'buildOutput' => $resource->getAttribute('outputDirectory', ''), - 'adapter' => $resource->getAttribute('adapter', ''), - 'fallbackFile' => $resource->getAttribute('fallbackFile', ''), - 'type' => 'vcs', - 'installationId' => $installationId, - 'installationInternalId' => $installationInternalId, - 'providerRepositoryId' => $providerRepositoryId, - 'repositoryId' => $repositoryId, - 'repositoryInternalId' => $repositoryInternalId, - 'providerBranchUrl' => $providerBranchUrl, - 'providerRepositoryName' => $providerRepositoryName, - 'providerRepositoryOwner' => $providerRepositoryOwner, - 'providerRepositoryUrl' => $providerRepositoryUrl, - 'providerCommitHash' => $providerCommitHash, - 'providerCommitAuthorUrl' => $providerCommitAuthorUrl, - 'providerCommitAuthor' => $providerCommitAuthor, - 'providerCommitMessage' => mb_strimwidth($providerCommitMessage, 0, 255, '...'), - 'providerCommitUrl' => $providerCommitUrl, - 'providerCommentId' => \strval($latestCommentId), - 'providerBranch' => $providerBranch, - 'activate' => $activate, - ]))); - - $resource = $resource - ->setAttribute('latestDeploymentId', $deployment->getId()) - ->setAttribute('latestDeploymentInternalId', $deployment->getSequence()) - ->setAttribute('latestDeploymentCreatedAt', $deployment->getCreatedAt()) - ->setAttribute('latestDeploymentStatus', $deployment->getAttribute('status', '')); - $authorization->skip(fn () => $dbForProject->updateDocument($resource->getCollection(), $resource->getId(), $resource)); - - if ($resource->getCollection() === 'sites') { - $projectId = $project->getId(); - - // Deployment preview - $sitesDomain = $platform['sitesDomain']; - $domain = ID::unique() . "." . $sitesDomain; - $ruleId = md5($domain); - $previewRuleId = $ruleId; - $authorization->skip( - fn () => $dbForPlatform->createDocument('rules', new Document([ - '$id' => $ruleId, - 'projectId' => $project->getId(), - 'projectInternalId' => $project->getSequence(), - 'domain' => $domain, - 'type' => 'deployment', - 'trigger' => 'deployment', - 'deploymentId' => $deployment->getId(), - 'deploymentInternalId' => $deployment->getSequence(), - 'deploymentResourceType' => 'site', - 'deploymentResourceId' => $resourceId, - 'deploymentResourceInternalId' => $resourceInternalId, - 'deploymentVcsProviderBranch' => $providerBranch, - 'status' => 'verified', - 'certificateId' => '', - 'search' => implode(' ', [$ruleId, $domain]), - 'owner' => 'Appwrite', - 'region' => $project->getAttribute('region') - ])) - ); - - // VCS branch preview - if (!empty($providerBranch)) { - $domain = (new BranchDomainFilter())->apply([ - 'branch' => $providerBranch, - 'resourceId' => $resource->getId(), - 'projectId' => $project->getId(), - 'sitesDomain' => $sitesDomain, - ]); - $ruleId = md5($domain); - try { - $authorization->skip( - fn () => $dbForPlatform->createDocument('rules', new Document([ - '$id' => $ruleId, - 'projectId' => $project->getId(), - 'projectInternalId' => $project->getSequence(), - 'domain' => $domain, - 'type' => 'deployment', - 'trigger' => 'deployment', - 'deploymentId' => $deployment->getId(), - 'deploymentInternalId' => $deployment->getSequence(), - 'deploymentResourceType' => 'site', - 'deploymentResourceId' => $resourceId, - 'deploymentResourceInternalId' => $resourceInternalId, - 'deploymentVcsProviderBranch' => $providerBranch, - 'status' => 'verified', - 'certificateId' => '', - 'search' => implode(' ', [$ruleId, $domain]), - 'owner' => 'Appwrite', - 'region' => $project->getAttribute('region') - ])) - ); - } catch (Duplicate $err) { - // Ignore, rule already exists; will be updated by builds worker - } - } - - // VCS commit preview - if (!empty($providerCommitHash)) { - $domain = "commit-" . substr($providerCommitHash, 0, 16) . ".{$sitesDomain}"; - $ruleId = md5($domain); - try { - $authorization->skip( - fn () => $dbForPlatform->createDocument('rules', new Document([ - '$id' => $ruleId, - 'projectId' => $project->getId(), - 'projectInternalId' => $project->getSequence(), - 'domain' => $domain, - 'type' => 'deployment', - 'trigger' => 'deployment', - 'deploymentId' => $deployment->getId(), - 'deploymentInternalId' => $deployment->getSequence(), - 'deploymentResourceType' => 'site', - 'deploymentResourceId' => $resourceId, - 'deploymentResourceInternalId' => $resourceInternalId, - 'deploymentVcsProviderBranch' => $providerBranch, - 'status' => 'verified', - 'certificateId' => '', - 'search' => implode(' ', [$ruleId, $domain]), - 'owner' => 'Appwrite', - 'region' => $project->getAttribute('region') - ])) - ); - } catch (Duplicate $err) { - // Ignore, rule already exists; will be updated by builds worker - } - } - } - - if ($resource->getCollection() === 'sites' && !empty($latestCommentId) && !empty($previewRuleId)) { - $retries = 0; - $lockAcquired = false; - - while ($retries < 9) { - $retries++; - - try { - $dbForPlatform->createDocument('vcsCommentLocks', new Document([ - '$id' => $latestCommentId - ])); - $lockAcquired = true; - break; - } catch (\Throwable $err) { - if ($retries >= 9) { - Console::warning("Error creating vcs comment lock for " . $latestCommentId . ": " . $err->getMessage()); - } - - \sleep(1); - } - } - - if ($lockAcquired) { - // Wrap in try/finally to ensure lock file gets deleted - try { - $rule = $authorization->skip(fn () => $dbForPlatform->getDocument('rules', $previewRuleId)); - - $protocol = System::getEnv('_APP_OPTIONS_FORCE_HTTPS') === 'disabled' ? 'http' : 'https'; - $previewUrl = !empty($rule) ? ("{$protocol}://" . $rule->getAttribute('domain', '')) : ''; - - if (!empty($previewUrl)) { - $comment = new Comment($platform); - $comment->parseComment($github->getComment($owner, $repositoryName, $latestCommentId)); - $comment->addBuild($project, $resource, $resourceType, $commentStatus, $deploymentId, $action, $previewUrl); - $github->updateComment($owner, $repositoryName, $latestCommentId, $comment->generateComment()); - } - } finally { - $authorization->skip(fn () => $dbForPlatform->deleteDocument('vcsCommentLocks', $latestCommentId)); - } - } - } - - if (!empty($providerCommitHash) && $resource->getAttribute('providerSilentMode', false) === false) { - $resourceName = $resource->getAttribute('name'); - $projectName = $project->getAttribute('name'); - $region = $project->getAttribute('region', 'default'); - $name = "{$resourceName} ({$projectName})"; - $message = 'Starting...'; - - $providerRepositoryId = $repository->getAttribute('providerRepositoryId'); - try { - $repositoryName = $github->getRepositoryName($providerRepositoryId) ?? ''; - if (empty($repositoryName)) { - throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); - } - } catch (RepositoryNotFound $e) { - throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); - } - $owner = $github->getOwnerName($providerInstallationId); - - $providerTargetUrl = $protocol . '://' . $hostname . "/console/project-$region-$projectId/$resourceCollection/$resourceType-$resourceId"; - $github->updateCommitStatus($repositoryName, $providerCommitHash, $owner, 'pending', $message, $providerTargetUrl, $name); - } - - $queueForBuilds - ->setType(BUILD_TYPE_DEPLOYMENT) - ->setResource($resource) - ->setDeployment($deployment) - ->setProject($project); // set the project because it won't be set for git deployments - - $queueForBuilds->trigger(); // must trigger here so that we create a build for each function/site - - //TODO: Add event? - } catch (Throwable $e) { - $errors[] = $e->getMessage(); - } - } - - $queueForBuilds->reset(); // prevent shutdown hook from triggering again - - if (!empty($errors)) { - throw new Exception(Exception::GENERAL_UNKNOWN, \implode("\n", $errors)); - } -}; - -Http::post('/v1/vcs/github/events') - ->desc('Create event') - ->groups(['api', 'vcs']) - ->label('scope', 'public') - ->inject('gitHub') - ->inject('request') - ->inject('response') - ->inject('dbForPlatform') - ->inject('authorization') - ->inject('getProjectDB') - ->inject('queueForBuilds') - ->inject('platform') - ->action( - function (GitHub $github, Request $request, Response $response, Database $dbForPlatform, Authorization $authorization, callable $getProjectDB, Build $queueForBuilds, array $platform) use ($createGitDeployments) { - $payload = $request->getRawPayload(); - $signatureRemote = $request->getHeader('x-hub-signature-256', ''); - $signatureLocal = System::getEnv('_APP_VCS_GITHUB_WEBHOOK_SECRET', ''); - - $valid = empty($signatureRemote) ? true : $github->validateWebhookEvent($payload, $signatureRemote, $signatureLocal); - - if (!$valid) { - throw new Exception(Exception::GENERAL_ACCESS_FORBIDDEN, "Invalid webhook payload signature. Please make sure the webhook secret has same value in your GitHub app and in the _APP_VCS_GITHUB_WEBHOOK_SECRET environment variable"); - } - - $event = $request->getHeader('x-github-event', ''); - $privateKey = System::getEnv('_APP_VCS_GITHUB_PRIVATE_KEY'); - $githubAppId = System::getEnv('_APP_VCS_GITHUB_APP_ID'); - $parsedPayload = $github->getEvent($event, $payload); - - if ($event == $github::EVENT_PUSH) { - $providerBranchCreated = $parsedPayload["branchCreated"] ?? false; - $providerBranchDeleted = $parsedPayload["branchDeleted"] ?? false; - $providerBranch = $parsedPayload["branch"] ?? ''; - $providerBranchUrl = $parsedPayload["branchUrl"] ?? ''; - $providerRepositoryId = $parsedPayload["repositoryId"] ?? ''; - $providerRepositoryName = $parsedPayload["repositoryName"] ?? ''; - $providerInstallationId = $parsedPayload["installationId"] ?? ''; - $providerRepositoryUrl = $parsedPayload["repositoryUrl"] ?? ''; - $providerCommitHash = $parsedPayload["commitHash"] ?? ''; - $providerRepositoryOwner = $parsedPayload["owner"] ?? ''; - $providerCommitAuthorName = $parsedPayload["headCommitAuthorName"] ?? ''; - $providerCommitAuthorEmail = $parsedPayload["headCommitAuthorEmail"] ?? ''; - $providerCommitAuthorUrl = $parsedPayload["authorUrl"] ?? ''; - $providerCommitMessage = $parsedPayload["headCommitMessage"] ?? ''; - $providerCommitUrl = $parsedPayload["headCommitUrl"] ?? ''; - - $github->initializeVariables($providerInstallationId, $privateKey, $githubAppId); - - //find resourceId from relevant resources table - $repositories = $authorization->skip(fn () => $dbForPlatform->find('repositories', [ - Query::equal('providerRepositoryId', [$providerRepositoryId]), - Query::limit(100), - ])); - - // create new deployment only on push (not committed by us) and not when branch is created or deleted - if ($providerCommitAuthorEmail !== APP_VCS_GITHUB_EMAIL && !$providerBranchCreated && !$providerBranchDeleted) { - $createGitDeployments($github, $providerInstallationId, $repositories, $providerBranch, $providerBranchUrl, $providerRepositoryName, $providerRepositoryUrl, $providerRepositoryOwner, $providerCommitHash, $providerCommitAuthorName, $providerCommitAuthorUrl, $providerCommitMessage, $providerCommitUrl, '', false, $dbForPlatform, $authorization, $queueForBuilds, $getProjectDB, $request, $platform); - } - } elseif ($event == $github::EVENT_INSTALLATION) { - if ($parsedPayload["action"] == "deleted") { - // TODO: Use worker for this job instead (update function/site as well) - $providerInstallationId = $parsedPayload["installationId"]; - - $installations = $dbForPlatform->find('installations', [ - Query::equal('providerInstallationId', [$providerInstallationId]), - Query::limit(1000) - ]); - - foreach ($installations as $installation) { - $repositories = $authorization->skip(fn () => $dbForPlatform->find('repositories', [ - Query::equal('installationInternalId', [$installation->getSequence()]), - Query::limit(1000) - ])); - - foreach ($repositories as $repository) { - $authorization->skip(fn () => $dbForPlatform->deleteDocument('repositories', $repository->getId())); - } - - $authorization->skip(fn () => $dbForPlatform->deleteDocument('installations', $installation->getId())); - } - } - } elseif ($event == $github::EVENT_PULL_REQUEST) { - if ($parsedPayload["action"] == "opened" || $parsedPayload["action"] == "reopened" || $parsedPayload["action"] == "synchronize") { - $providerBranch = $parsedPayload["branch"] ?? ''; - $providerBranchUrl = $parsedPayload["branchUrl"] ?? ''; - $providerRepositoryId = $parsedPayload["repositoryId"] ?? ''; - $providerRepositoryName = $parsedPayload["repositoryName"] ?? ''; - $providerInstallationId = $parsedPayload["installationId"] ?? ''; - $providerRepositoryUrl = $parsedPayload["repositoryUrl"] ?? ''; - $providerPullRequestId = $parsedPayload["pullRequestNumber"] ?? ''; - $providerCommitHash = $parsedPayload["commitHash"] ?? ''; - $providerRepositoryOwner = $parsedPayload["owner"] ?? ''; - $external = $parsedPayload["external"] ?? true; - $providerCommitUrl = $parsedPayload["headCommitUrl"] ?? ''; - $providerCommitAuthorUrl = $parsedPayload["authorUrl"] ?? ''; - - // Ignore sync for non-external. We handle it in push webhook - if (!$external && $parsedPayload["action"] == "synchronize") { - return $response->json($parsedPayload); - } - - $github->initializeVariables($providerInstallationId, $privateKey, $githubAppId); - - $commitDetails = $github->getCommit($providerRepositoryOwner, $providerRepositoryName, $providerCommitHash); - $providerCommitAuthor = $commitDetails["commitAuthor"] ?? ''; - $providerCommitMessage = $commitDetails["commitMessage"] ?? ''; - - $repositories = $authorization->skip(fn () => $dbForPlatform->find('repositories', [ - Query::equal('providerRepositoryId', [$providerRepositoryId]), - Query::orderDesc('$createdAt') - ])); - - $createGitDeployments($github, $providerInstallationId, $repositories, $providerBranch, $providerBranchUrl, $providerRepositoryName, $providerRepositoryUrl, $providerRepositoryOwner, $providerCommitHash, $providerCommitAuthor, $providerCommitAuthorUrl, $providerCommitMessage, $providerCommitUrl, $providerPullRequestId, $external, $dbForPlatform, $authorization, $queueForBuilds, $getProjectDB, $request, $platform); - } elseif ($parsedPayload["action"] == "closed") { - // Allowed external contributions cleanup - - $providerRepositoryId = $parsedPayload["repositoryId"] ?? ''; - $providerPullRequestId = $parsedPayload["pullRequestNumber"] ?? ''; - $external = $parsedPayload["external"] ?? true; - - if ($external) { - $repositories = $authorization->skip(fn () => $dbForPlatform->find('repositories', [ - Query::equal('providerRepositoryId', [$providerRepositoryId]), - Query::orderDesc('$createdAt') - ])); - - foreach ($repositories as $repository) { - $providerPullRequestIds = $repository->getAttribute('providerPullRequestIds', []); - - if (\in_array($providerPullRequestId, $providerPullRequestIds)) { - $providerPullRequestIds = \array_diff($providerPullRequestIds, [$providerPullRequestId]); - $repository = $repository->setAttribute('providerPullRequestIds', $providerPullRequestIds); - $repository = $authorization->skip(fn () => $dbForPlatform->updateDocument('repositories', $repository->getId(), $repository)); - } - } - } - } - } - - $response->json($parsedPayload); - } - ); - -Http::patch('/v1/vcs/github/installations/:installationId/repositories/:repositoryId') - ->desc('Update external deployment (authorize)') - ->groups(['api', 'vcs']) - ->label('scope', 'vcs.write') - ->label('sdk', new Method( - namespace: 'vcs', - group: 'repositories', - name: 'updateExternalDeployments', - description: '/docs/references/vcs/update-external-deployments.md', - auth: [AuthType::ADMIN], - responses: [ - new SDKResponse( - code: Response::STATUS_CODE_NOCONTENT, - model: Response::MODEL_NONE, - ) - ] - )) - ->param('installationId', '', new Text(256), 'Installation Id') - ->param('repositoryId', '', new Text(256), 'VCS Repository Id') - ->param('providerPullRequestId', '', new Text(256), 'GitHub Pull Request Id') - ->inject('gitHub') - ->inject('response') - ->inject('project') - ->inject('dbForPlatform') - ->inject('authorization') - ->inject('getProjectDB') - ->inject('queueForBuilds') - ->inject('platform') - ->action(function (string $installationId, string $repositoryId, string $providerPullRequestId, GitHub $github, Request $request, Response $response, Document $project, Database $dbForPlatform, Authorization $authorization, callable $getProjectDB, Build $queueForBuilds, array $platform) use ($createGitDeployments) { - $installation = $dbForPlatform->getDocument('installations', $installationId); - - if ($installation->isEmpty()) { - throw new Exception(Exception::INSTALLATION_NOT_FOUND); - } - - $repository = $authorization->skip(fn () => $dbForPlatform->findOne('repositories', [ - Query::equal('$id', [$repositoryId]), - Query::equal('projectInternalId', [$project->getSequence()]) - ])); - - if ($repository->isEmpty()) { - throw new Exception(Exception::REPOSITORY_NOT_FOUND); - } - - if (\in_array($providerPullRequestId, $repository->getAttribute('providerPullRequestIds', []))) { - throw new Exception(Exception::PROVIDER_CONTRIBUTION_CONFLICT); - } - - $providerPullRequestIds = \array_unique(\array_merge($repository->getAttribute('providerPullRequestIds', []), [$providerPullRequestId])); - $repository = $repository->setAttribute('providerPullRequestIds', $providerPullRequestIds); - - // TODO: Delete from array when PR is closed - - $repository = $authorization->skip(fn () => $dbForPlatform->updateDocument('repositories', $repository->getId(), $repository)); - - $privateKey = System::getEnv('_APP_VCS_GITHUB_PRIVATE_KEY'); - $githubAppId = System::getEnv('_APP_VCS_GITHUB_APP_ID'); - $providerInstallationId = $installation->getAttribute('providerInstallationId'); - $github->initializeVariables($providerInstallationId, $privateKey, $githubAppId); - - $repositories = [$repository]; - $providerRepositoryId = $repository->getAttribute('providerRepositoryId'); - - $owner = $github->getOwnerName($providerInstallationId); - try { - $repositoryName = $github->getRepositoryName($providerRepositoryId) ?? ''; - if (empty($repositoryName)) { - throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); - } - } catch (RepositoryNotFound $e) { - throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); - } - $pullRequestResponse = $github->getPullRequest($owner, $repositoryName, $providerPullRequestId); - - $providerBranch = \explode(':', $pullRequestResponse['head']['label'])[1] ?? ''; - $providerCommitHash = $pullRequestResponse['head']['sha'] ?? ''; - $providerBranchUrl = $pullRequestResponse['head']['repo']['html_url'] ?? ''; - $providerRepositoryName = $pullRequestResponse['head']['repo']['name'] ?? ''; - $providerRepositoryUrl = $pullRequestResponse['head']['repo']['html_url'] ?? ''; - $providerRepositoryOwner = $pullRequestResponse['head']['repo']['owner']['login'] ?? ''; - $providerCommitAuthor = $pullRequestResponse['head']['user']['login'] ?? ''; - $providerCommitAuthorUrl = $pullRequestResponse['head']['user']['html_url'] ?? ''; - $providerCommitMessage = $pullRequestResponse['title'] ?? ''; - $providerCommitUrl = $pullRequestResponse['html_url'] ?? ''; - - $createGitDeployments($github, $providerInstallationId, $repositories, $providerBranch, '', '', '', '', $providerCommitHash, '', '', '', '', $providerPullRequestId, true, $dbForPlatform, $authorization, $queueForBuilds, $getProjectDB, $request, $platform); - - $response->noContent(); - }); diff --git a/src/Appwrite/Platform/Modules/VCS/Http/GitHub/Authorize/External/Update.php b/src/Appwrite/Platform/Modules/VCS/Http/GitHub/Authorize/External/Update.php new file mode 100644 index 0000000000..6b521e56d0 --- /dev/null +++ b/src/Appwrite/Platform/Modules/VCS/Http/GitHub/Authorize/External/Update.php @@ -0,0 +1,141 @@ +setHttpMethod(Action::HTTP_REQUEST_METHOD_PATCH) + ->setHttpPath('/v1/vcs/github/installations/:installationId/repositories/:repositoryId') + ->desc('Update external deployment (authorize)') + ->groups(['api', 'vcs']) + ->label('scope', 'vcs.write') + ->label('sdk', new Method( + namespace: 'vcs', + group: 'repositories', + name: 'updateExternalDeployments', + description: '/docs/references/vcs/update-external-deployments.md', + auth: [AuthType::ADMIN], + responses: [ + new SDKResponse( + code: Response::STATUS_CODE_NOCONTENT, + model: Response::MODEL_NONE, + ) + ] + )) + ->param('installationId', '', new Text(256), 'Installation Id') + ->param('repositoryId', '', new Text(256), 'VCS Repository Id') + ->param('providerPullRequestId', '', new Text(256), 'GitHub Pull Request Id') + ->inject('gitHub') + ->inject('response') + ->inject('project') + ->inject('dbForPlatform') + ->inject('authorization') + ->inject('getProjectDB') + ->inject('queueForBuilds') + ->inject('platform') + ->callback($this->action(...)); + } + + public function action( + string $installationId, + string $repositoryId, + string $providerPullRequestId, + GitHub $github, + Response $response, + Document $project, + Database $dbForPlatform, + Authorization $authorization, + callable $getProjectDB, + Build $queueForBuilds, + array $platform + ) { + $installation = $dbForPlatform->getDocument('installations', $installationId); + + if ($installation->isEmpty()) { + throw new Exception(Exception::INSTALLATION_NOT_FOUND); + } + + $repository = $authorization->skip(fn () => $dbForPlatform->findOne('repositories', [ + Query::equal('$id', [$repositoryId]), + Query::equal('projectInternalId', [$project->getSequence()]) + ])); + + if ($repository->isEmpty()) { + throw new Exception(Exception::REPOSITORY_NOT_FOUND); + } + + if (\in_array($providerPullRequestId, $repository->getAttribute('providerPullRequestIds', []))) { + throw new Exception(Exception::PROVIDER_CONTRIBUTION_CONFLICT); + } + + $providerPullRequestIds = \array_unique(\array_merge($repository->getAttribute('providerPullRequestIds', []), [$providerPullRequestId])); + $repository = $repository->setAttribute('providerPullRequestIds', $providerPullRequestIds); + + $repository = $authorization->skip(fn () => $dbForPlatform->updateDocument('repositories', $repository->getId(), $repository)); + + $privateKey = System::getEnv('_APP_VCS_GITHUB_PRIVATE_KEY'); + $githubAppId = System::getEnv('_APP_VCS_GITHUB_APP_ID'); + $providerInstallationId = $installation->getAttribute('providerInstallationId'); + $github->initializeVariables($providerInstallationId, $privateKey, $githubAppId); + + $repositories = [$repository]; + $providerRepositoryId = $repository->getAttribute('providerRepositoryId'); + + try { + $providerRepositoryName = $github->getRepositoryName($providerRepositoryId) ?? ''; + if (empty($providerRepositoryName)) { + throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); + } + } catch (RepositoryNotFound $e) { + throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); + } + + $owner = $github->getOwnerName($providerInstallationId); + $pullRequestResponse = $github->getPullRequest($owner, $providerRepositoryName, $providerPullRequestId); + + $providerRepositoryUrl = $pullRequestResponse['head']['repo']['html_url'] ?? ''; + $providerRepositoryOwner = $pullRequestResponse['head']['repo']['owner']['login'] ?? ''; + $providerBranch = \explode(':', $pullRequestResponse['head']['label'])[1] ?? ''; + $providerBranchUrl = "$providerRepositoryUrl/tree/$providerBranch"; + $providerCommitHash = $pullRequestResponse['head']['sha'] ?? ''; + + $commitDetails = $github->getCommit($providerRepositoryOwner, $providerRepositoryName, $providerCommitHash); + $providerCommitMessage = $commitDetails["commitMessage"] ?? ''; + $providerCommitUrl = $commitDetails["commitUrl"] ?? ''; + $providerCommitAuthor = $commitDetails["commitAuthor"] ?? ''; + $providerCommitAuthorUrl = $commitDetails["commitAuthorUrl"] ?? ''; + + $this->createGitDeployments($github, $providerInstallationId, $repositories, $providerBranch, $providerBranchUrl, $providerRepositoryName, $providerRepositoryUrl, $providerRepositoryOwner, $providerCommitHash, $providerCommitAuthor, $providerCommitAuthorUrl, $providerCommitMessage, $providerCommitUrl, $providerPullRequestId, true, $dbForPlatform, $authorization, $queueForBuilds, $getProjectDB, $platform); + + $response->noContent(); + } +} diff --git a/src/Appwrite/Platform/Modules/VCS/Http/GitHub/Deployment.php b/src/Appwrite/Platform/Modules/VCS/Http/GitHub/Deployment.php new file mode 100644 index 0000000000..6d493e2cdb --- /dev/null +++ b/src/Appwrite/Platform/Modules/VCS/Http/GitHub/Deployment.php @@ -0,0 +1,523 @@ +getId(); + $projectId = $repository->getAttribute('projectId'); + $resourceId = $repository->getAttribute('resourceId'); + $resourceType = $repository->getAttribute('resourceType'); + + $logBase = "vcs.github.event.repo.{$repositoryId}"; + Span::add("{$logBase}.projectId", $projectId); + Span::add("{$logBase}.resourceId", $resourceId); + Span::add("{$logBase}.resourceType", $resourceType); + + if ($resourceType !== "function" && $resourceType !== "site") { + continue; + } + + $project = $authorization->skip(fn () => $dbForPlatform->getDocument('projects', $projectId)); + + if ($project->isEmpty()) { + throw new Exception(Exception::PROJECT_NOT_FOUND, 'Repository references non-existent project'); + } + + try { + $dsn = new DSN($project->getAttribute('database')); + $databaseName = $dsn->getHost(); + } catch (\InvalidArgumentException) { + $databaseName = $project->getAttribute('database'); + } + + $databases = Config::getParam('pools-database', []); + $index = in_array($databaseName, $databases); + + if ($index === false) { + Console::error("Database: '{$databaseName}' is not part of region: " . System::getEnv('_APP_REGION')); + continue; + } + + $dbForProject = $getProjectDB($project); + $resourceCollection = $resourceType === "function" ? 'functions' : 'sites'; + $resource = $authorization->skip(fn () => $dbForProject->getDocument($resourceCollection, $resourceId)); + $resourceInternalId = $resource->getSequence(); + + $deploymentId = ID::unique(); + $repositoryId = $repository->getId(); + $repositoryInternalId = $repository->getSequence(); + $providerRepositoryId = $repository->getAttribute('providerRepositoryId'); + $installationId = $repository->getAttribute('installationId'); + $installationInternalId = $repository->getAttribute('installationInternalId'); + $productionBranch = $resource->getAttribute('providerBranch'); + $activate = false; + + if ($providerBranch == $productionBranch && $external === false) { + $activate = true; + } + + $owner = $github->getOwnerName($providerInstallationId) ?? ''; + try { + $repositoryName = $github->getRepositoryName($providerRepositoryId) ?? ''; + if (empty($repositoryName)) { + throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); + } + } catch (RepositoryNotFound $e) { + throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); + } + + if (empty($repositoryName)) { + throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); + } + + $isAuthorized = !$external; + + if (!$isAuthorized && !empty($providerPullRequestId)) { + if (\in_array($providerPullRequestId, $repository->getAttribute('providerPullRequestIds', []))) { + $isAuthorized = true; + } + } + + Span::add("{$logBase}.authorized", $isAuthorized); + + $commentStatus = 'waiting'; + $protocol = System::getEnv('_APP_OPTIONS_FORCE_HTTPS') === 'disabled' ? 'http' : 'https'; + $hostname = $platform['consoleHostname'] ?? ''; + + $authorizeUrl = $protocol . '://' . $hostname . "/console/git/authorize-contributor?projectId={$projectId}&installationId={$installationId}&repositoryId={$repositoryId}&providerPullRequestId={$providerPullRequestId}"; + + $action = $isAuthorized ? ['type' => 'logs'] : ['type' => 'authorize', 'url' => $authorizeUrl]; + + $latestCommentId = ''; + + if (!empty($providerPullRequestId) && $resource->getAttribute('providerSilentMode', false) === false) { + $latestComment = $authorization->skip(fn () => $dbForPlatform->findOne('vcsComments', [ + Query::equal('providerRepositoryId', [$providerRepositoryId]), + Query::equal('providerPullRequestId', [$providerPullRequestId]), + Query::orderDesc('$createdAt'), + ])); + + if (!$latestComment->isEmpty()) { + $latestCommentId = $latestComment->getAttribute('providerCommentId', ''); + + $retries = 0; + $lockAcquired = false; + + while ($retries < 9) { + $retries++; + + try { + $dbForPlatform->createDocument('vcsCommentLocks', new Document([ + '$id' => $latestCommentId + ])); + $lockAcquired = true; + break; + } catch (\Throwable $err) { + if ($retries >= 9) { + Console::warning("Error creating vcs comment lock for " . $latestCommentId . ": " . $err->getMessage()); + } + + \sleep(1); + } + } + + if ($lockAcquired) { + // Wrap in try/finally to ensure lock file gets deleted + try { + $comment = new Comment($platform); + $comment->parseComment($github->getComment($owner, $repositoryName, $latestCommentId)); + $comment->addBuild($project, $resource, $resourceType, $commentStatus, $deploymentId, $action, ''); + + $latestCommentId = \strval($github->updateComment($owner, $repositoryName, $latestCommentId, $comment->generateComment())); + } finally { + $authorization->skip(fn () => $dbForPlatform->deleteDocument('vcsCommentLocks', $latestCommentId)); + } + } + } else { + $comment = new Comment($platform); + $comment->addBuild($project, $resource, $resourceType, $commentStatus, $deploymentId, $action, ''); + $latestCommentId = \strval($github->createComment($owner, $repositoryName, $providerPullRequestId, $comment->generateComment())); + + if (!empty($latestCommentId)) { + $teamId = $project->getAttribute('teamId', ''); + + $latestComment = $authorization->skip(fn () => $dbForPlatform->createDocument('vcsComments', new Document([ + '$id' => ID::unique(), + '$permissions' => [ + Permission::read(Role::team(ID::custom($teamId))), + Permission::update(Role::team(ID::custom($teamId), 'owner')), + Permission::update(Role::team(ID::custom($teamId), 'developer')), + Permission::delete(Role::team(ID::custom($teamId), 'owner')), + Permission::delete(Role::team(ID::custom($teamId), 'developer')), + ], + 'installationInternalId' => $installationInternalId, + 'installationId' => $installationId, + 'projectInternalId' => $project->getSequence(), + 'projectId' => $project->getId(), + 'providerRepositoryId' => $providerRepositoryId, + 'providerBranch' => $providerBranch, + 'providerPullRequestId' => $providerPullRequestId, + 'providerCommentId' => $latestCommentId + ]))); + } + } + } elseif (!empty($providerBranch)) { + $latestComments = $authorization->skip(fn () => $dbForPlatform->find('vcsComments', [ + Query::equal('providerRepositoryId', [$providerRepositoryId]), + Query::equal('providerBranch', [$providerBranch]), + Query::orderDesc('$createdAt'), + ])); + + foreach ($latestComments as $comment) { + $latestCommentId = $comment->getAttribute('providerCommentId', ''); + + $retries = 0; + $lockAcquired = false; + + while ($retries < 9) { + $retries++; + + try { + $dbForPlatform->createDocument('vcsCommentLocks', new Document([ + '$id' => $latestCommentId + ])); + $lockAcquired = true; + break; + } catch (\Throwable $err) { + if ($retries >= 9) { + Console::warning("Error creating vcs comment lock for " . $latestCommentId . ": " . $err->getMessage()); + } + + \sleep(1); + } + } + + if ($lockAcquired) { + // Wrap in try/finally to ensure lock file gets deleted + try { + $comment = new Comment($platform); + $comment->parseComment($github->getComment($owner, $repositoryName, $latestCommentId)); + $comment->addBuild($project, $resource, $resourceType, $commentStatus, $deploymentId, $action, ''); + + $latestCommentId = \strval($github->updateComment($owner, $repositoryName, $latestCommentId, $comment->generateComment())); + } finally { + $authorization->skip(fn () => $dbForPlatform->deleteDocument('vcsCommentLocks', $latestCommentId)); + } + } + } + } + + if (!$isAuthorized) { + $resourceName = $resource->getAttribute('name'); + $projectName = $project->getAttribute('name'); + $name = "{$resourceName} ({$projectName})"; + $message = 'Authorization required for external contributor.'; + + $providerRepositoryId = $repository->getAttribute('providerRepositoryId'); + try { + $repositoryName = $github->getRepositoryName($providerRepositoryId) ?? ''; + if (empty($repositoryName)) { + throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); + } + } catch (RepositoryNotFound $e) { + throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); + } + $owner = $github->getOwnerName($providerInstallationId); + $github->updateCommitStatus($repositoryName, $providerCommitHash, $owner, 'pending', $message, $authorizeUrl, $name); + continue; + } + + $commands = []; + if (!empty($resource->getAttribute('installCommand', ''))) { + $commands[] = $resource->getAttribute('installCommand', ''); + } + if (!empty($resource->getAttribute('buildCommand', ''))) { + $commands[] = $resource->getAttribute('buildCommand', ''); + } + if (!empty($resource->getAttribute('commands', ''))) { + $commands[] = $resource->getAttribute('commands', ''); + } + + $deployment = $authorization->skip(fn () => $dbForProject->createDocument('deployments', new Document([ + '$id' => $deploymentId, + '$permissions' => [ + Permission::read(Role::any()), + Permission::update(Role::any()), + Permission::delete(Role::any()), + ], + 'resourceId' => $resourceId, + 'resourceInternalId' => $resourceInternalId, + 'resourceType' => $resourceCollection, + 'entrypoint' => $resource->getAttribute('entrypoint', ''), + 'buildCommands' => \implode(' && ', $commands), + 'startCommand' => $resource->getAttribute('startCommand', ''), + 'buildOutput' => $resource->getAttribute('outputDirectory', ''), + 'adapter' => $resource->getAttribute('adapter', ''), + 'fallbackFile' => $resource->getAttribute('fallbackFile', ''), + 'type' => 'vcs', + 'installationId' => $installationId, + 'installationInternalId' => $installationInternalId, + 'providerRepositoryId' => $providerRepositoryId, + 'repositoryId' => $repositoryId, + 'repositoryInternalId' => $repositoryInternalId, + 'providerBranchUrl' => $providerBranchUrl, + 'providerRepositoryName' => $providerRepositoryName, + 'providerRepositoryOwner' => $providerRepositoryOwner, + 'providerRepositoryUrl' => $providerRepositoryUrl, + 'providerCommitHash' => $providerCommitHash, + 'providerCommitAuthorUrl' => $providerCommitAuthorUrl, + 'providerCommitAuthor' => $providerCommitAuthor, + 'providerCommitMessage' => mb_strimwidth($providerCommitMessage, 0, 255, '...'), + 'providerCommitUrl' => $providerCommitUrl, + 'providerCommentId' => \strval($latestCommentId), + 'providerBranch' => $providerBranch, + 'activate' => $activate, + ]))); + + $resource = $resource + ->setAttribute('latestDeploymentId', $deployment->getId()) + ->setAttribute('latestDeploymentInternalId', $deployment->getSequence()) + ->setAttribute('latestDeploymentCreatedAt', $deployment->getCreatedAt()) + ->setAttribute('latestDeploymentStatus', $deployment->getAttribute('status', '')); + $authorization->skip(fn () => $dbForProject->updateDocument($resource->getCollection(), $resource->getId(), $resource)); + + if ($resource->getCollection() === 'sites') { + $projectId = $project->getId(); + + // Deployment preview + $sitesDomain = $platform['sitesDomain']; + $domain = ID::unique() . "." . $sitesDomain; + $ruleId = md5($domain); + $previewRuleId = $ruleId; + $authorization->skip( + fn () => $dbForPlatform->createDocument('rules', new Document([ + '$id' => $ruleId, + 'projectId' => $project->getId(), + 'projectInternalId' => $project->getSequence(), + 'domain' => $domain, + 'type' => 'deployment', + 'trigger' => 'deployment', + 'deploymentId' => $deployment->getId(), + 'deploymentInternalId' => $deployment->getSequence(), + 'deploymentResourceType' => 'site', + 'deploymentResourceId' => $resourceId, + 'deploymentResourceInternalId' => $resourceInternalId, + 'deploymentVcsProviderBranch' => $providerBranch, + 'status' => 'verified', + 'certificateId' => '', + 'search' => implode(' ', [$ruleId, $domain]), + 'owner' => 'Appwrite', + 'region' => $project->getAttribute('region') + ])) + ); + + // VCS branch preview + if (!empty($providerBranch)) { + $domain = (new BranchDomainFilter())->apply([ + 'branch' => $providerBranch, + 'resourceId' => $resource->getId(), + 'projectId' => $project->getId(), + 'sitesDomain' => $sitesDomain, + ]); + $ruleId = md5($domain); + try { + $authorization->skip( + fn () => $dbForPlatform->createDocument('rules', new Document([ + '$id' => $ruleId, + 'projectId' => $project->getId(), + 'projectInternalId' => $project->getSequence(), + 'domain' => $domain, + 'type' => 'deployment', + 'trigger' => 'deployment', + 'deploymentId' => $deployment->getId(), + 'deploymentInternalId' => $deployment->getSequence(), + 'deploymentResourceType' => 'site', + 'deploymentResourceId' => $resourceId, + 'deploymentResourceInternalId' => $resourceInternalId, + 'deploymentVcsProviderBranch' => $providerBranch, + 'status' => 'verified', + 'certificateId' => '', + 'search' => implode(' ', [$ruleId, $domain]), + 'owner' => 'Appwrite', + 'region' => $project->getAttribute('region') + ])) + ); + } catch (Duplicate $err) { + // Ignore, rule already exists; will be updated by builds worker + } + } + + // VCS commit preview + if (!empty($providerCommitHash)) { + $domain = "commit-" . substr($providerCommitHash, 0, 16) . ".{$sitesDomain}"; + $ruleId = md5($domain); + try { + $authorization->skip( + fn () => $dbForPlatform->createDocument('rules', new Document([ + '$id' => $ruleId, + 'projectId' => $project->getId(), + 'projectInternalId' => $project->getSequence(), + 'domain' => $domain, + 'type' => 'deployment', + 'trigger' => 'deployment', + 'deploymentId' => $deployment->getId(), + 'deploymentInternalId' => $deployment->getSequence(), + 'deploymentResourceType' => 'site', + 'deploymentResourceId' => $resourceId, + 'deploymentResourceInternalId' => $resourceInternalId, + 'deploymentVcsProviderBranch' => $providerBranch, + 'status' => 'verified', + 'certificateId' => '', + 'search' => implode(' ', [$ruleId, $domain]), + 'owner' => 'Appwrite', + 'region' => $project->getAttribute('region') + ])) + ); + } catch (Duplicate $err) { + // Ignore, rule already exists; will be updated by builds worker + } + } + } + + if ($resource->getCollection() === 'sites' && !empty($latestCommentId) && !empty($previewRuleId)) { + $retries = 0; + $lockAcquired = false; + + while ($retries < 9) { + $retries++; + + try { + $dbForPlatform->createDocument('vcsCommentLocks', new Document([ + '$id' => $latestCommentId + ])); + $lockAcquired = true; + break; + } catch (\Throwable $err) { + if ($retries >= 9) { + Console::warning("Error creating vcs comment lock for " . $latestCommentId . ": " . $err->getMessage()); + } + + \sleep(1); + } + } + + if ($lockAcquired) { + // Wrap in try/finally to ensure lock file gets deleted + try { + $rule = $authorization->skip(fn () => $dbForPlatform->getDocument('rules', $previewRuleId)); + + $protocol = System::getEnv('_APP_OPTIONS_FORCE_HTTPS') === 'disabled' ? 'http' : 'https'; + $previewUrl = !empty($rule) ? ("{$protocol}://" . $rule->getAttribute('domain', '')) : ''; + + if (!empty($previewUrl)) { + $comment = new Comment($platform); + $comment->parseComment($github->getComment($owner, $repositoryName, $latestCommentId)); + $comment->addBuild($project, $resource, $resourceType, $commentStatus, $deploymentId, $action, $previewUrl); + $github->updateComment($owner, $repositoryName, $latestCommentId, $comment->generateComment()); + } + } finally { + $authorization->skip(fn () => $dbForPlatform->deleteDocument('vcsCommentLocks', $latestCommentId)); + } + } + } + + if (!empty($providerCommitHash) && $resource->getAttribute('providerSilentMode', false) === false) { + $resourceName = $resource->getAttribute('name'); + $projectName = $project->getAttribute('name'); + $region = $project->getAttribute('region', 'default'); + $name = "{$resourceName} ({$projectName})"; + $message = 'Starting...'; + + $providerRepositoryId = $repository->getAttribute('providerRepositoryId'); + try { + $repositoryName = $github->getRepositoryName($providerRepositoryId) ?? ''; + if (empty($repositoryName)) { + throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); + } + } catch (RepositoryNotFound $e) { + throw new Exception(Exception::PROVIDER_REPOSITORY_NOT_FOUND); + } + $owner = $github->getOwnerName($providerInstallationId); + + $providerTargetUrl = $protocol . '://' . $hostname . "/console/project-$region-$projectId/$resourceCollection/$resourceType-$resourceId"; + $github->updateCommitStatus($repositoryName, $providerCommitHash, $owner, 'pending', $message, $providerTargetUrl, $name); + } + + $queueName = $this->getBuildQueueName($project, $dbForPlatform, $authorization); + + $queueForBuilds + ->setQueue($queueName) + ->setType(BUILD_TYPE_DEPLOYMENT) + ->setResource($resource) + ->setDeployment($deployment) + ->setProject($project); // set the project because it won't be set for git deployments + + $queueForBuilds->trigger(); // must trigger here so that we create a build for each function/site + + Span::add("{$logBase}.build.triggered", 'true'); + //TODO: Add event? + } catch (\Throwable $e) { + Span::add("{$logBase}.error", $e->getMessage()); + $errors[] = $e->getMessage(); + } + } + + $queueForBuilds->reset(); // prevent shutdown hook from triggering again + + if (!empty($errors)) { + throw new Exception(Exception::GENERAL_UNKNOWN, \implode("\n", $errors)); + } + } + + protected function getBuildQueueName(Document $project, Database $dbForPlatform, Authorization $authorization): string + { + return System::getEnv('_APP_BUILDS_QUEUE_NAME', Event::BUILDS_QUEUE_NAME); + } +} diff --git a/src/Appwrite/Platform/Modules/VCS/Http/GitHub/Events/Create.php b/src/Appwrite/Platform/Modules/VCS/Http/GitHub/Events/Create.php new file mode 100644 index 0000000000..de6750fe64 --- /dev/null +++ b/src/Appwrite/Platform/Modules/VCS/Http/GitHub/Events/Create.php @@ -0,0 +1,244 @@ +setHttpMethod(Action::HTTP_REQUEST_METHOD_POST) + ->setHttpPath('/v1/vcs/github/events') + ->desc('Create event') + ->groups(['api', 'vcs']) + ->label('scope', 'public') + ->inject('gitHub') + ->inject('request') + ->inject('response') + ->inject('dbForPlatform') + ->inject('authorization') + ->inject('getProjectDB') + ->inject('queueForBuilds') + ->inject('platform') + ->callback($this->action(...)); + } + + public function action( + GitHub $github, + Request $request, + Response $response, + Database $dbForPlatform, + Authorization $authorization, + callable $getProjectDB, + Build $queueForBuilds, + array $platform + ) { + $this->preprocessEvent($request); + + $event = $request->getHeader('x-github-event', ''); + Span::add('vcs.github.event.name', $event); + + $payload = $request->getRawPayload(); + $signature = $request->getHeader('x-hub-signature-256', ''); + $secretKey = System::getEnv('_APP_VCS_GITHUB_WEBHOOK_SECRET', ''); + + $valid = empty($signature) ? true : $github->validateWebhookEvent($payload, $signature, $secretKey); + Span::add('vcs.github.event.signature.valid', $valid); + + if (!$valid) { + throw new Exception(Exception::GENERAL_ACCESS_FORBIDDEN, "Invalid webhook payload signature. Please make sure the webhook secret has same value in your GitHub app and in the _APP_VCS_GITHUB_WEBHOOK_SECRET environment variable"); + } + + $githubAppId = System::getEnv('_APP_VCS_GITHUB_APP_ID'); + $privateKey = System::getEnv('_APP_VCS_GITHUB_PRIVATE_KEY'); + $parsedPayload = $github->getEvent($event, $payload); + + match ($event) { + $github::EVENT_INSTALLATION => $this->handleInstallationEvent($parsedPayload, $dbForPlatform, $authorization), + $github::EVENT_PUSH => $this->handlePushEvent($parsedPayload, $githubAppId, $privateKey, $github, $dbForPlatform, $authorization, $queueForBuilds, $getProjectDB, $platform), + $github::EVENT_PULL_REQUEST => $this->handlePullRequestEvent($parsedPayload, $privateKey, $githubAppId, $github, $dbForPlatform, $authorization, $queueForBuilds, $getProjectDB, $platform), + default => null, + }; + + return $response->json($parsedPayload); + } + + protected function preprocessEvent(Request $request) + { + return; + } + + private function handleInstallationEvent( + array $parsedPayload, + Database $dbForPlatform, + Authorization $authorization, + ) { + if ($parsedPayload["action"] !== "deleted") { + return; + } + + // TODO: Use worker for this job instead (update function/site as well) + $providerInstallationId = $parsedPayload["installationId"]; + + $installations = $dbForPlatform->find('installations', [ + Query::equal('providerInstallationId', [$providerInstallationId]), + Query::limit(1000) + ]); + + foreach ($installations as $installation) { + $repositories = $authorization->skip(fn () => $dbForPlatform->find('repositories', [ + Query::equal('installationInternalId', [$installation->getSequence()]), + Query::limit(1000) + ])); + + foreach ($repositories as $repository) { + $authorization->skip(fn () => $dbForPlatform->deleteDocument('repositories', $repository->getId())); + } + + $authorization->skip(fn () => $dbForPlatform->deleteDocument('installations', $installation->getId())); + } + } + + private function handlePushEvent( + array $parsedPayload, + string $githubAppId, + string $privateKey, + GitHub $github, + Database $dbForPlatform, + Authorization $authorization, + Build $queueForBuilds, + callable $getProjectDB, + array $platform, + ) { + $providerBranchCreated = $parsedPayload["branchCreated"] ?? false; + $providerBranchDeleted = $parsedPayload["branchDeleted"] ?? false; + $providerBranch = $parsedPayload["branch"] ?? ''; + $providerBranchUrl = $parsedPayload["branchUrl"] ?? ''; + $providerRepositoryId = $parsedPayload["repositoryId"] ?? ''; + $providerRepositoryName = $parsedPayload["repositoryName"] ?? ''; + $providerInstallationId = $parsedPayload["installationId"] ?? ''; + $providerRepositoryUrl = $parsedPayload["repositoryUrl"] ?? ''; + $providerCommitHash = $parsedPayload["commitHash"] ?? ''; + $providerRepositoryOwner = $parsedPayload["owner"] ?? ''; + $providerCommitAuthorName = $parsedPayload["headCommitAuthorName"] ?? ''; + $providerCommitAuthorEmail = $parsedPayload["headCommitAuthorEmail"] ?? ''; + $providerCommitAuthorUrl = $parsedPayload["authorUrl"] ?? ''; + $providerCommitMessage = $parsedPayload["headCommitMessage"] ?? ''; + $providerCommitUrl = $parsedPayload["headCommitUrl"] ?? ''; + + Span::add('vcs.github.event.repo.id', $providerRepositoryId); + Span::add('vcs.github.event.repo.name', $providerRepositoryName); + Span::add('vcs.github.event.branch', $providerBranch); + Span::add('vcs.github.event.installation.id', $providerInstallationId); + + $github->initializeVariables($providerInstallationId, $privateKey, $githubAppId); + + // Find associated repositories + $repositories = $authorization->skip(fn () => $dbForPlatform->find('repositories', [ + Query::equal('providerRepositoryId', [$providerRepositoryId]), + Query::limit(100), + ])); + + // Create new deployment only on push (not committed by us) and not when branch is created or deleted + if ($providerCommitAuthorEmail !== APP_VCS_GITHUB_EMAIL && !$providerBranchCreated && !$providerBranchDeleted) { + $this->createGitDeployments($github, $providerInstallationId, $repositories, $providerBranch, $providerBranchUrl, $providerRepositoryName, $providerRepositoryUrl, $providerRepositoryOwner, $providerCommitHash, $providerCommitAuthorName, $providerCommitAuthorUrl, $providerCommitMessage, $providerCommitUrl, '', false, $dbForPlatform, $authorization, $queueForBuilds, $getProjectDB, $platform); + } + } + + private function handlePullRequestEvent( + array $parsedPayload, + string $privateKey, + string $githubAppId, + GitHub $github, + Database $dbForPlatform, + Authorization $authorization, + Build $queueForBuilds, + callable $getProjectDB, + array $platform, + ) { + $action = $parsedPayload["action"] ?? ''; + + if ($action == "opened" || $action == "reopened" || $action == "synchronize") { + $providerBranch = $parsedPayload["branch"] ?? ''; + $providerBranchUrl = $parsedPayload["branchUrl"] ?? ''; + $providerRepositoryId = $parsedPayload["repositoryId"] ?? ''; + $providerRepositoryName = $parsedPayload["repositoryName"] ?? ''; + $providerInstallationId = $parsedPayload["installationId"] ?? ''; + $providerRepositoryUrl = $parsedPayload["repositoryUrl"] ?? ''; + $providerPullRequestId = $parsedPayload["pullRequestNumber"] ?? ''; + $providerCommitHash = $parsedPayload["commitHash"] ?? ''; + $providerRepositoryOwner = $parsedPayload["owner"] ?? ''; + $external = $parsedPayload["external"] ?? true; + $providerCommitUrl = $parsedPayload["headCommitUrl"] ?? ''; + $providerCommitAuthorUrl = $parsedPayload["authorUrl"] ?? ''; + + Span::add('vcs.github.event.repo.id', $providerRepositoryId); + Span::add('vcs.github.event.repo.name', $providerRepositoryName); + Span::add('vcs.github.event.branch', $providerBranch); + Span::add('vcs.github.event.installation.id', $providerInstallationId); + + // Ignore sync for non-external. We handle it in push webhook + if (!$external && $parsedPayload["action"] == "synchronize") { + return; + } + + $github->initializeVariables($providerInstallationId, $privateKey, $githubAppId); + + $commitDetails = $github->getCommit($providerRepositoryOwner, $providerRepositoryName, $providerCommitHash); + $providerCommitAuthor = $commitDetails["commitAuthor"] ?? ''; + $providerCommitMessage = $commitDetails["commitMessage"] ?? ''; + + $repositories = $authorization->skip(fn () => $dbForPlatform->find('repositories', [ + Query::equal('providerRepositoryId', [$providerRepositoryId]), + Query::orderDesc('$createdAt') + ])); + + $this->createGitDeployments($github, $providerInstallationId, $repositories, $providerBranch, $providerBranchUrl, $providerRepositoryName, $providerRepositoryUrl, $providerRepositoryOwner, $providerCommitHash, $providerCommitAuthor, $providerCommitAuthorUrl, $providerCommitMessage, $providerCommitUrl, $providerPullRequestId, $external, $dbForPlatform, $authorization, $queueForBuilds, $getProjectDB, $platform); + } elseif ($action == "closed") { + // Allowed external contributions cleanup + + $providerRepositoryId = $parsedPayload["repositoryId"] ?? ''; + $providerPullRequestId = $parsedPayload["pullRequestNumber"] ?? ''; + $external = $parsedPayload["external"] ?? true; + + if ($external) { + $repositories = $authorization->skip(fn () => $dbForPlatform->find('repositories', [ + Query::equal('providerRepositoryId', [$providerRepositoryId]), + Query::orderDesc('$createdAt') + ])); + + foreach ($repositories as $repository) { + $providerPullRequestIds = $repository->getAttribute('providerPullRequestIds', []); + + if (\in_array($providerPullRequestId, $providerPullRequestIds)) { + $providerPullRequestIds = \array_diff($providerPullRequestIds, [$providerPullRequestId]); + $repository = $repository->setAttribute('providerPullRequestIds', $providerPullRequestIds); + $repository = $authorization->skip(fn () => $dbForPlatform->updateDocument('repositories', $repository->getId(), $repository)); + } + } + } + } + } +} diff --git a/src/Appwrite/Platform/Modules/VCS/Services/Http.php b/src/Appwrite/Platform/Modules/VCS/Services/Http.php index 8bd2314f9e..ae766ad00e 100644 --- a/src/Appwrite/Platform/Modules/VCS/Services/Http.php +++ b/src/Appwrite/Platform/Modules/VCS/Services/Http.php @@ -2,8 +2,10 @@ namespace Appwrite\Platform\Modules\VCS\Services; +use Appwrite\Platform\Modules\VCS\Http\GitHub\Authorize\External\Update as UpdateExternalDeployment; use Appwrite\Platform\Modules\VCS\Http\GitHub\Authorize\Get as GetGitHubAuthorize; use Appwrite\Platform\Modules\VCS\Http\GitHub\Callback\Get as GetGitHubCallback; +use Appwrite\Platform\Modules\VCS\Http\GitHub\Events\Create as CreateGitHubEvent; use Appwrite\Platform\Modules\VCS\Http\Installations\Delete as DeleteInstallation; use Appwrite\Platform\Modules\VCS\Http\Installations\Get as GetInstallation; use Appwrite\Platform\Modules\VCS\Http\Installations\Repositories\Branches\XList as ListRepositoryBranches; @@ -24,6 +26,7 @@ class Http extends Service // GitHub Authorization & Callback $this->addAction(GetGitHubAuthorize::getName(), new GetGitHubAuthorize()); $this->addAction(GetGitHubCallback::getName(), new GetGitHubCallback()); + $this->addAction(UpdateExternalDeployment::getName(), new UpdateExternalDeployment()); // Installations $this->addAction(GetInstallation::getName(), new GetInstallation()); @@ -37,5 +40,8 @@ class Http extends Service $this->addAction(ListRepositoryBranches::getName(), new ListRepositoryBranches()); $this->addAction(GetRepositoryContents::getName(), new GetRepositoryContents()); $this->addAction(CreateRepositoryDetections::getName(), new CreateRepositoryDetections()); + + // Events + $this->addAction(CreateGitHubEvent::getName(), new CreateGitHubEvent()); } }