Feat v0.6.6 final hardening
Some checks failed
CI/CD / detect-changes (pull_request) Successful in 4s
CI/CD / test-frontend (pull_request) Successful in 6s
CI/CD / test-go-pg (pull_request) Failing after 2m41s
CI/CD / test-sqlite (pull_request) Failing after 2m48s
CI/CD / build-and-deploy (pull_request) Has been skipped
Some checks failed
CI/CD / detect-changes (pull_request) Successful in 4s
CI/CD / test-frontend (pull_request) Successful in 6s
CI/CD / test-go-pg (pull_request) Failing after 2m41s
CI/CD / test-sqlite (pull_request) Failing after 2m48s
CI/CD / build-and-deploy (pull_request) Has been skipped
Final pass before public release — security, correctness, developer experience. - ValidateManifest() gate: centralized manifest validation (12 unit tests) - Extension dependency auto-activation from bundled packages - OIDC nonce validation: ID token nonce checked against stored state - Schema migration stub replaced with log-only additive policy - OptionalAuth middleware for anonymous workflow visitor routes - Package signing schema reservation (signature field + env var) - PublishAsync event bus counter fix - Health UI tooltips explaining published vs delivered gap - ICD/SDK runner updated for v0.6.x endpoints (metrics, cluster, backups, OpenAPI) - Version bump, ROADMAP, CHANGELOG Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -97,6 +97,12 @@ type Config struct {
|
||||
ClusterHeartbeatInterval time.Duration
|
||||
ClusterStaleThreshold time.Duration
|
||||
ClusterEndpoint string
|
||||
|
||||
// Package signing (future)
|
||||
// PACKAGE_VERIFY_SIGNATURES: when true, log warnings for unsigned packages.
|
||||
// No cryptographic verification yet — this reserves the manifest schema slot
|
||||
// and config plumbing so it can be implemented without a breaking change.
|
||||
PackageVerifySignatures bool
|
||||
}
|
||||
|
||||
// Load reads configuration from environment variables.
|
||||
@@ -161,6 +167,8 @@ func Load() *Config {
|
||||
ClusterHeartbeatInterval: getEnvDuration("CLUSTER_HEARTBEAT_INTERVAL", 10*time.Second),
|
||||
ClusterStaleThreshold: getEnvDuration("CLUSTER_STALE_THRESHOLD", 30*time.Second),
|
||||
ClusterEndpoint: getEnv("CLUSTER_ENDPOINT", ""),
|
||||
|
||||
PackageVerifySignatures: getEnvBool("PACKAGE_VERIFY_SIGNATURES", false),
|
||||
}
|
||||
}
|
||||
|
||||
|
||||
Reference in New Issue
Block a user