commit f942f41f340e05e1d93631e5ba7d1ca9bceef4f8 Author: mathieu Date: Tue Aug 18 15:15:53 2026 +0200 premier essaie diff --git a/A_FAIRE.md b/A_FAIRE.md new file mode 100644 index 0000000..8df2d29 --- /dev/null +++ b/A_FAIRE.md @@ -0,0 +1,91 @@ +# À faire avant la première installation + +Deux points restés en suspens à la livraison du paquet, à traiter quand tu voudras +déployer. Rien ici n'est bloqué par le code : tout fonctionne, il manque des +informations que seul toi peux fournir. + +--- + +## 1. Remplacer l'URL de démonstration et déposer la release + +Le `manifest.toml` porte une URL **fictive** (`gitea.example.org`) : le paquet ne +pouvait pas connaître ton vrai domaine Gitea au moment de sa création. En l'état, +l'installation échouerait au téléchargement de l'archive. + +### Ce qu'il faut faire + +**a. Créer la release du code.** Sur le dépôt `mabibli` (celui du code C#, pas +celui-ci) : + +``` +git tag v0.1.0 +git push origin v0.1.0 +``` + +Puis créer la release correspondante dans l'interface Gitea et y téléverser +l'archive `build/dist/mabibli-0.1.0-linux-x64.tar.gz`. + +⚠️ L'archive fait **68 Mo** — c'est normal, le publish est *self-contained* et +embarque le runtime .NET. C'est précisément ce qui évite d'installer +`dotnet-runtime` sur le serveur YunoHost. + +**b. Régénérer le manifeste avec la vraie URL :** + +``` +./build/publier-release.sh --base-url +``` + +Le script recompile, produit l'archive, calcule son `sha256` et l'inscrit dans le +`manifest.toml` avec la bonne URL. Committer ensuite le manifeste modifié. + +**c. Chercher les autres occurrences du domaine fictif**, qui ne sont pas couvertes +par le script : + +``` +grep -rn "gitea.example.org" . +``` + +Elles se trouvent dans `manifest.toml` (champ `upstream.code`), `README.md`, et +`conf/systemd.service` (directive `Documentation=`). + +### Comment vérifier + +Le `sha256` du manifeste doit correspondre à l'archive réellement déposée : + +``` +sha256sum build/dist/mabibli-0.1.0-linux-x64.tar.gz +grep sha256 manifest.toml +``` + +S'ils diffèrent, l'installation s'interrompra à la vérification d'intégrité — ce qui +est le comportement souhaité, mais autant le savoir avant. + +--- + +## 2. L'application exige un domaine entier, pas un sous-chemin + +**Contrainte technique, pas un choix.** MaBibli doit être installée sur +`mabibli.mondomaine.tld`, et **non** sur `mondomaine.tld/mabibli`. + +### Pourquoi + +Deux éléments sont figés **à la compilation** du client Blazor WebAssembly : + +- la balise `` de `index.html`, qui détermine la racine de toutes les + URL de l'application ; +- les empreintes d'intégrité inscrites dans `service-worker-assets.js`, qui + garantissent que le service worker sert bien les fichiers attendus. + +Réécrire ces valeurs sur le serveur au moment de l'installation casserait les +empreintes, donc le service worker, donc le fonctionnement hors-ligne. Et comme +rien n'est recompilé côté serveur — c'est tout l'intérêt du déploiement +self-contained —, il n'existe pas de solution propre pour un sous-chemin. + +Le paquet déclare donc l'application en `full_domain` auprès de YunoHost, qui +demandera un domaine dédié à l'installation. + +### Si tu voulais lever cette contrainte plus tard + +Il faudrait produire une archive **par chemin d'installation**, ou recompiler sur le +serveur. Les deux annulent le bénéfice du self-contained. À moins d'un besoin réel, +un sous-domaine reste la bonne réponse. diff --git a/LICENSE b/LICENSE new file mode 100644 index 0000000..be3f7b2 --- /dev/null +++ b/LICENSE @@ -0,0 +1,661 @@ + GNU AFFERO GENERAL PUBLIC LICENSE + Version 3, 19 November 2007 + + Copyright (C) 2007 Free Software Foundation, Inc. + Everyone is permitted to copy and distribute verbatim copies + of this license document, but changing it is not allowed. + + Preamble + + The GNU Affero General Public License is a free, copyleft license for +software and other kinds of works, specifically designed to ensure +cooperation with the community in the case of network server software. + + The licenses for most software and other practical works are designed +to take away your freedom to share and change the works. By contrast, +our General Public Licenses are intended to guarantee your freedom to +share and change all versions of a program--to make sure it remains free +software for all its users. + + When we speak of free software, we are referring to freedom, not +price. Our General Public Licenses are designed to make sure that you +have the freedom to distribute copies of free software (and charge for +them if you wish), that you receive source code or can get it if you +want it, that you can change the software or use pieces of it in new +free programs, and that you know you can do these things. + + Developers that use our General Public Licenses protect your rights +with two steps: (1) assert copyright on the software, and (2) offer +you this License which gives you legal permission to copy, distribute +and/or modify the software. + + A secondary benefit of defending all users' freedom is that +improvements made in alternate versions of the program, if they +receive widespread use, become available for other developers to +incorporate. Many developers of free software are heartened and +encouraged by the resulting cooperation. However, in the case of +software used on network servers, this result may fail to come about. +The GNU General Public License permits making a modified version and +letting the public access it on a server without ever releasing its +source code to the public. + + The GNU Affero General Public License is designed specifically to +ensure that, in such cases, the modified source code becomes available +to the community. It requires the operator of a network server to +provide the source code of the modified version running there to the +users of that server. Therefore, public use of a modified version, on +a publicly accessible server, gives the public access to the source +code of the modified version. + + An older license, called the Affero General Public License and +published by Affero, was designed to accomplish similar goals. This is +a different license, not a version of the Affero GPL, but Affero has +released a new version of the Affero GPL which permits relicensing under +this license. + + The precise terms and conditions for copying, distribution and +modification follow. + + TERMS AND CONDITIONS + + 0. Definitions. + + "This License" refers to version 3 of the GNU Affero General Public License. + + "Copyright" also means copyright-like laws that apply to other kinds of +works, such as semiconductor masks. + + "The Program" refers to any copyrightable work licensed under this +License. Each licensee is addressed as "you". "Licensees" and +"recipients" may be individuals or organizations. + + To "modify" a work means to copy from or adapt all or part of the work +in a fashion requiring copyright permission, other than the making of an +exact copy. The resulting work is called a "modified version" of the +earlier work or a work "based on" the earlier work. + + A "covered work" means either the unmodified Program or a work based +on the Program. + + To "propagate" a work means to do anything with it that, without +permission, would make you directly or secondarily liable for +infringement under applicable copyright law, except executing it on a +computer or modifying a private copy. Propagation includes copying, +distribution (with or without modification), making available to the +public, and in some countries other activities as well. + + To "convey" a work means any kind of propagation that enables other +parties to make or receive copies. Mere interaction with a user through +a computer network, with no transfer of a copy, is not conveying. + + An interactive user interface displays "Appropriate Legal Notices" +to the extent that it includes a convenient and prominently visible +feature that (1) displays an appropriate copyright notice, and (2) +tells the user that there is no warranty for the work (except to the +extent that warranties are provided), that licensees may convey the +work under this License, and how to view a copy of this License. If +the interface presents a list of user commands or options, such as a +menu, a prominent item in the list meets this criterion. + + 1. Source Code. + + The "source code" for a work means the preferred form of the work +for making modifications to it. "Object code" means any non-source +form of a work. + + A "Standard Interface" means an interface that either is an official +standard defined by a recognized standards body, or, in the case of +interfaces specified for a particular programming language, one that +is widely used among developers working in that language. + + The "System Libraries" of an executable work include anything, other +than the work as a whole, that (a) is included in the normal form of +packaging a Major Component, but which is not part of that Major +Component, and (b) serves only to enable use of the work with that +Major Component, or to implement a Standard Interface for which an +implementation is available to the public in source code form. A +"Major Component", in this context, means a major essential component +(kernel, window system, and so on) of the specific operating system +(if any) on which the executable work runs, or a compiler used to +produce the work, or an object code interpreter used to run it. + + The "Corresponding Source" for a work in object code form means all +the source code needed to generate, install, and (for an executable +work) run the object code and to modify the work, including scripts to +control those activities. However, it does not include the work's +System Libraries, or general-purpose tools or generally available free +programs which are used unmodified in performing those activities but +which are not part of the work. For example, Corresponding Source +includes interface definition files associated with source files for +the work, and the source code for shared libraries and dynamically +linked subprograms that the work is specifically designed to require, +such as by intimate data communication or control flow between those +subprograms and other parts of the work. + + The Corresponding Source need not include anything that users +can regenerate automatically from other parts of the Corresponding +Source. + + The Corresponding Source for a work in source code form is that +same work. + + 2. Basic Permissions. + + All rights granted under this License are granted for the term of +copyright on the Program, and are irrevocable provided the stated +conditions are met. This License explicitly affirms your unlimited +permission to run the unmodified Program. The output from running a +covered work is covered by this License only if the output, given its +content, constitutes a covered work. This License acknowledges your +rights of fair use or other equivalent, as provided by copyright law. + + You may make, run and propagate covered works that you do not +convey, without conditions so long as your license otherwise remains +in force. You may convey covered works to others for the sole purpose +of having them make modifications exclusively for you, or provide you +with facilities for running those works, provided that you comply with +the terms of this License in conveying all material for which you do +not control copyright. Those thus making or running the covered works +for you must do so exclusively on your behalf, under your direction +and control, on terms that prohibit them from making any copies of +your copyrighted material outside their relationship with you. + + Conveying under any other circumstances is permitted solely under +the conditions stated below. Sublicensing is not allowed; section 10 +makes it unnecessary. + + 3. Protecting Users' Legal Rights From Anti-Circumvention Law. + + No covered work shall be deemed part of an effective technological +measure under any applicable law fulfilling obligations under article +11 of the WIPO copyright treaty adopted on 20 December 1996, or +similar laws prohibiting or restricting circumvention of such +measures. + + When you convey a covered work, you waive any legal power to forbid +circumvention of technological measures to the extent such circumvention +is effected by exercising rights under this License with respect to +the covered work, and you disclaim any intention to limit operation or +modification of the work as a means of enforcing, against the work's +users, your or third parties' legal rights to forbid circumvention of +technological measures. + + 4. Conveying Verbatim Copies. + + You may convey verbatim copies of the Program's source code as you +receive it, in any medium, provided that you conspicuously and +appropriately publish on each copy an appropriate copyright notice; +keep intact all notices stating that this License and any +non-permissive terms added in accord with section 7 apply to the code; +keep intact all notices of the absence of any warranty; and give all +recipients a copy of this License along with the Program. + + You may charge any price or no price for each copy that you convey, +and you may offer support or warranty protection for a fee. + + 5. Conveying Modified Source Versions. + + You may convey a work based on the Program, or the modifications to +produce it from the Program, in the form of source code under the +terms of section 4, provided that you also meet all of these conditions: + + a) The work must carry prominent notices stating that you modified + it, and giving a relevant date. + + b) The work must carry prominent notices stating that it is + released under this License and any conditions added under section + 7. This requirement modifies the requirement in section 4 to + "keep intact all notices". + + c) You must license the entire work, as a whole, under this + License to anyone who comes into possession of a copy. This + License will therefore apply, along with any applicable section 7 + additional terms, to the whole of the work, and all its parts, + regardless of how they are packaged. This License gives no + permission to license the work in any other way, but it does not + invalidate such permission if you have separately received it. + + d) If the work has interactive user interfaces, each must display + Appropriate Legal Notices; however, if the Program has interactive + interfaces that do not display Appropriate Legal Notices, your + work need not make them do so. + + A compilation of a covered work with other separate and independent +works, which are not by their nature extensions of the covered work, +and which are not combined with it such as to form a larger program, +in or on a volume of a storage or distribution medium, is called an +"aggregate" if the compilation and its resulting copyright are not +used to limit the access or legal rights of the compilation's users +beyond what the individual works permit. Inclusion of a covered work +in an aggregate does not cause this License to apply to the other +parts of the aggregate. + + 6. Conveying Non-Source Forms. + + You may convey a covered work in object code form under the terms +of sections 4 and 5, provided that you also convey the +machine-readable Corresponding Source under the terms of this License, +in one of these ways: + + a) Convey the object code in, or embodied in, a physical product + (including a physical distribution medium), accompanied by the + Corresponding Source fixed on a durable physical medium + customarily used for software interchange. + + b) Convey the object code in, or embodied in, a physical product + (including a physical distribution medium), accompanied by a + written offer, valid for at least three years and valid for as + long as you offer spare parts or customer support for that product + model, to give anyone who possesses the object code either (1) a + copy of the Corresponding Source for all the software in the + product that is covered by this License, on a durable physical + medium customarily used for software interchange, for a price no + more than your reasonable cost of physically performing this + conveying of source, or (2) access to copy the + Corresponding Source from a network server at no charge. + + c) Convey individual copies of the object code with a copy of the + written offer to provide the Corresponding Source. This + alternative is allowed only occasionally and noncommercially, and + only if you received the object code with such an offer, in accord + with subsection 6b. + + d) Convey the object code by offering access from a designated + place (gratis or for a charge), and offer equivalent access to the + Corresponding Source in the same way through the same place at no + further charge. You need not require recipients to copy the + Corresponding Source along with the object code. If the place to + copy the object code is a network server, the Corresponding Source + may be on a different server (operated by you or a third party) + that supports equivalent copying facilities, provided you maintain + clear directions next to the object code saying where to find the + Corresponding Source. Regardless of what server hosts the + Corresponding Source, you remain obligated to ensure that it is + available for as long as needed to satisfy these requirements. + + e) Convey the object code using peer-to-peer transmission, provided + you inform other peers where the object code and Corresponding + Source of the work are being offered to the general public at no + charge under subsection 6d. + + A separable portion of the object code, whose source code is excluded +from the Corresponding Source as a System Library, need not be +included in conveying the object code work. + + A "User Product" is either (1) a "consumer product", which means any +tangible personal property which is normally used for personal, family, +or household purposes, or (2) anything designed or sold for incorporation +into a dwelling. In determining whether a product is a consumer product, +doubtful cases shall be resolved in favor of coverage. For a particular +product received by a particular user, "normally used" refers to a +typical or common use of that class of product, regardless of the status +of the particular user or of the way in which the particular user +actually uses, or expects or is expected to use, the product. A product +is a consumer product regardless of whether the product has substantial +commercial, industrial or non-consumer uses, unless such uses represent +the only significant mode of use of the product. + + "Installation Information" for a User Product means any methods, +procedures, authorization keys, or other information required to install +and execute modified versions of a covered work in that User Product from +a modified version of its Corresponding Source. The information must +suffice to ensure that the continued functioning of the modified object +code is in no case prevented or interfered with solely because +modification has been made. + + If you convey an object code work under this section in, or with, or +specifically for use in, a User Product, and the conveying occurs as +part of a transaction in which the right of possession and use of the +User Product is transferred to the recipient in perpetuity or for a +fixed term (regardless of how the transaction is characterized), the +Corresponding Source conveyed under this section must be accompanied +by the Installation Information. But this requirement does not apply +if neither you nor any third party retains the ability to install +modified object code on the User Product (for example, the work has +been installed in ROM). + + The requirement to provide Installation Information does not include a +requirement to continue to provide support service, warranty, or updates +for a work that has been modified or installed by the recipient, or for +the User Product in which it has been modified or installed. Access to a +network may be denied when the modification itself materially and +adversely affects the operation of the network or violates the rules and +protocols for communication across the network. + + Corresponding Source conveyed, and Installation Information provided, +in accord with this section must be in a format that is publicly +documented (and with an implementation available to the public in +source code form), and must require no special password or key for +unpacking, reading or copying. + + 7. Additional Terms. + + "Additional permissions" are terms that supplement the terms of this +License by making exceptions from one or more of its conditions. +Additional permissions that are applicable to the entire Program shall +be treated as though they were included in this License, to the extent +that they are valid under applicable law. If additional permissions +apply only to part of the Program, that part may be used separately +under those permissions, but the entire Program remains governed by +this License without regard to the additional permissions. + + When you convey a copy of a covered work, you may at your option +remove any additional permissions from that copy, or from any part of +it. (Additional permissions may be written to require their own +removal in certain cases when you modify the work.) You may place +additional permissions on material, added by you to a covered work, +for which you have or can give appropriate copyright permission. + + Notwithstanding any other provision of this License, for material you +add to a covered work, you may (if authorized by the copyright holders of +that material) supplement the terms of this License with terms: + + a) Disclaiming warranty or limiting liability differently from the + terms of sections 15 and 16 of this License; or + + b) Requiring preservation of specified reasonable legal notices or + author attributions in that material or in the Appropriate Legal + Notices displayed by works containing it; or + + c) Prohibiting misrepresentation of the origin of that material, or + requiring that modified versions of such material be marked in + reasonable ways as different from the original version; or + + d) Limiting the use for publicity purposes of names of licensors or + authors of the material; or + + e) Declining to grant rights under trademark law for use of some + trade names, trademarks, or service marks; or + + f) Requiring indemnification of licensors and authors of that + material by anyone who conveys the material (or modified versions of + it) with contractual assumptions of liability to the recipient, for + any liability that these contractual assumptions directly impose on + those licensors and authors. + + All other non-permissive additional terms are considered "further +restrictions" within the meaning of section 10. If the Program as you +received it, or any part of it, contains a notice stating that it is +governed by this License along with a term that is a further +restriction, you may remove that term. If a license document contains +a further restriction but permits relicensing or conveying under this +License, you may add to a covered work material governed by the terms +of that license document, provided that the further restriction does +not survive such relicensing or conveying. + + If you add terms to a covered work in accord with this section, you +must place, in the relevant source files, a statement of the +additional terms that apply to those files, or a notice indicating +where to find the applicable terms. + + Additional terms, permissive or non-permissive, may be stated in the +form of a separately written license, or stated as exceptions; +the above requirements apply either way. + + 8. Termination. + + You may not propagate or modify a covered work except as expressly +provided under this License. Any attempt otherwise to propagate or +modify it is void, and will automatically terminate your rights under +this License (including any patent licenses granted under the third +paragraph of section 11). + + However, if you cease all violation of this License, then your +license from a particular copyright holder is reinstated (a) +provisionally, unless and until the copyright holder explicitly and +finally terminates your license, and (b) permanently, if the copyright +holder fails to notify you of the violation by some reasonable means +prior to 60 days after the cessation. + + Moreover, your license from a particular copyright holder is +reinstated permanently if the copyright holder notifies you of the +violation by some reasonable means, this is the first time you have +received notice of violation of this License (for any work) from that +copyright holder, and you cure the violation prior to 30 days after +your receipt of the notice. + + Termination of your rights under this section does not terminate the +licenses of parties who have received copies or rights from you under +this License. If your rights have been terminated and not permanently +reinstated, you do not qualify to receive new licenses for the same +material under section 10. + + 9. Acceptance Not Required for Having Copies. + + You are not required to accept this License in order to receive or +run a copy of the Program. Ancillary propagation of a covered work +occurring solely as a consequence of using peer-to-peer transmission +to receive a copy likewise does not require acceptance. However, +nothing other than this License grants you permission to propagate or +modify any covered work. These actions infringe copyright if you do +not accept this License. Therefore, by modifying or propagating a +covered work, you indicate your acceptance of this License to do so. + + 10. Automatic Licensing of Downstream Recipients. + + Each time you convey a covered work, the recipient automatically +receives a license from the original licensors, to run, modify and +propagate that work, subject to this License. You are not responsible +for enforcing compliance by third parties with this License. + + An "entity transaction" is a transaction transferring control of an +organization, or substantially all assets of one, or subdividing an +organization, or merging organizations. If propagation of a covered +work results from an entity transaction, each party to that +transaction who receives a copy of the work also receives whatever +licenses to the work the party's predecessor in interest had or could +give under the previous paragraph, plus a right to possession of the +Corresponding Source of the work from the predecessor in interest, if +the predecessor has it or can get it with reasonable efforts. + + You may not impose any further restrictions on the exercise of the +rights granted or affirmed under this License. For example, you may +not impose a license fee, royalty, or other charge for exercise of +rights granted under this License, and you may not initiate litigation +(including a cross-claim or counterclaim in a lawsuit) alleging that +any patent claim is infringed by making, using, selling, offering for +sale, or importing the Program or any portion of it. + + 11. Patents. + + A "contributor" is a copyright holder who authorizes use under this +License of the Program or a work on which the Program is based. The +work thus licensed is called the contributor's "contributor version". + + A contributor's "essential patent claims" are all patent claims +owned or controlled by the contributor, whether already acquired or +hereafter acquired, that would be infringed by some manner, permitted +by this License, of making, using, or selling its contributor version, +but do not include claims that would be infringed only as a +consequence of further modification of the contributor version. For +purposes of this definition, "control" includes the right to grant +patent sublicenses in a manner consistent with the requirements of +this License. + + Each contributor grants you a non-exclusive, worldwide, royalty-free +patent license under the contributor's essential patent claims, to +make, use, sell, offer for sale, import and otherwise run, modify and +propagate the contents of its contributor version. + + In the following three paragraphs, a "patent license" is any express +agreement or commitment, however denominated, not to enforce a patent +(such as an express permission to practice a patent or covenant not to +sue for patent infringement). To "grant" such a patent license to a +party means to make such an agreement or commitment not to enforce a +patent against the party. + + If you convey a covered work, knowingly relying on a patent license, +and the Corresponding Source of the work is not available for anyone +to copy, free of charge and under the terms of this License, through a +publicly available network server or other readily accessible means, +then you must either (1) cause the Corresponding Source to be so +available, or (2) arrange to deprive yourself of the benefit of the +patent license for this particular work, or (3) arrange, in a manner +consistent with the requirements of this License, to extend the patent +license to downstream recipients. "Knowingly relying" means you have +actual knowledge that, but for the patent license, your conveying the +covered work in a country, or your recipient's use of the covered work +in a country, would infringe one or more identifiable patents in that +country that you have reason to believe are valid. + + If, pursuant to or in connection with a single transaction or +arrangement, you convey, or propagate by procuring conveyance of, a +covered work, and grant a patent license to some of the parties +receiving the covered work authorizing them to use, propagate, modify +or convey a specific copy of the covered work, then the patent license +you grant is automatically extended to all recipients of the covered +work and works based on it. + + A patent license is "discriminatory" if it does not include within +the scope of its coverage, prohibits the exercise of, or is +conditioned on the non-exercise of one or more of the rights that are +specifically granted under this License. You may not convey a covered +work if you are a party to an arrangement with a third party that is +in the business of distributing software, under which you make payment +to the third party based on the extent of your activity of conveying +the work, and under which the third party grants, to any of the +parties who would receive the covered work from you, a discriminatory +patent license (a) in connection with copies of the covered work +conveyed by you (or copies made from those copies), or (b) primarily +for and in connection with specific products or compilations that +contain the covered work, unless you entered into that arrangement, +or that patent license was granted, prior to 28 March 2007. + + Nothing in this License shall be construed as excluding or limiting +any implied license or other defenses to infringement that may +otherwise be available to you under applicable patent law. + + 12. No Surrender of Others' Freedom. + + If conditions are imposed on you (whether by court order, agreement or +otherwise) that contradict the conditions of this License, they do not +excuse you from the conditions of this License. If you cannot convey a +covered work so as to satisfy simultaneously your obligations under this +License and any other pertinent obligations, then as a consequence you may +not convey it at all. For example, if you agree to terms that obligate you +to collect a royalty for further conveying from those to whom you convey +the Program, the only way you could satisfy both those terms and this +License would be to refrain entirely from conveying the Program. + + 13. Remote Network Interaction; Use with the GNU General Public License. + + Notwithstanding any other provision of this License, if you modify the +Program, your modified version must prominently offer all users +interacting with it remotely through a computer network (if your version +supports such interaction) an opportunity to receive the Corresponding +Source of your version by providing access to the Corresponding Source +from a network server at no charge, through some standard or customary +means of facilitating copying of software. This Corresponding Source +shall include the Corresponding Source for any work covered by version 3 +of the GNU General Public License that is incorporated pursuant to the +following paragraph. + + Notwithstanding any other provision of this License, you have +permission to link or combine any covered work with a work licensed +under version 3 of the GNU General Public License into a single +combined work, and to convey the resulting work. The terms of this +License will continue to apply to the part which is the covered work, +but the work with which it is combined will remain governed by version +3 of the GNU General Public License. + + 14. Revised Versions of this License. + + The Free Software Foundation may publish revised and/or new versions of +the GNU Affero General Public License from time to time. Such new versions +will be similar in spirit to the present version, but may differ in detail to +address new problems or concerns. + + Each version is given a distinguishing version number. If the +Program specifies that a certain numbered version of the GNU Affero General +Public License "or any later version" applies to it, you have the +option of following the terms and conditions either of that numbered +version or of any later version published by the Free Software +Foundation. If the Program does not specify a version number of the +GNU Affero General Public License, you may choose any version ever published +by the Free Software Foundation. + + If the Program specifies that a proxy can decide which future +versions of the GNU Affero General Public License can be used, that proxy's +public statement of acceptance of a version permanently authorizes you +to choose that version for the Program. + + Later license versions may give you additional or different +permissions. However, no additional obligations are imposed on any +author or copyright holder as a result of your choosing to follow a +later version. + + 15. Disclaimer of Warranty. + + THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY +APPLICABLE LAW. EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT +HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY +OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, +THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR +PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM +IS WITH YOU. SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF +ALL NECESSARY SERVICING, REPAIR OR CORRECTION. + + 16. Limitation of Liability. + + IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING +WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS +THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY +GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE +USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF +DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD +PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), +EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF +SUCH DAMAGES. + + 17. Interpretation of Sections 15 and 16. + + If the disclaimer of warranty and limitation of liability provided +above cannot be given local legal effect according to their terms, +reviewing courts shall apply local law that most closely approximates +an absolute waiver of all civil liability in connection with the +Program, unless a warranty or assumption of liability accompanies a +copy of the Program in return for a fee. + + END OF TERMS AND CONDITIONS + + How to Apply These Terms to Your New Programs + + If you develop a new program, and you want it to be of the greatest +possible use to the public, the best way to achieve this is to make it +free software which everyone can redistribute and change under these terms. + + To do so, attach the following notices to the program. It is safest +to attach them to the start of each source file to most effectively +state the exclusion of warranty; and each file should have at least +the "copyright" line and a pointer to where the full notice is found. + + + Copyright (C) + + This program is free software: you can redistribute it and/or modify + it under the terms of the GNU Affero General Public License as published by + the Free Software Foundation, either version 3 of the License, or + (at your option) any later version. + + This program is distributed in the hope that it will be useful, + but WITHOUT ANY WARRANTY; without even the implied warranty of + MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the + GNU Affero General Public License for more details. + + You should have received a copy of the GNU Affero General Public License + along with this program. If not, see . + +Also add information on how to contact you by electronic and paper mail. + + If your software can interact with users remotely through a computer +network, you should also make sure that it provides a way for users to +get its source. For example, if your program is a web application, its +interface could display a "Source" link that leads users to an archive +of the code. There are many ways you could offer source, and different +solutions will be better for different programs; see section 13 for the +specific requirements. + + You should also get your employer (if you work as a programmer) or school, +if any, to sign a "copyright disclaimer" for the program, if necessary. +For more information on this, and how to apply and follow the GNU AGPL, see +. diff --git a/README.md b/README.md new file mode 100644 index 0000000..641a88c --- /dev/null +++ b/README.md @@ -0,0 +1,70 @@ +# Paquet YunoHost pour MaBibli + +Paquet d'installation de [MaBibli](https://gitea.example.org/mathieu/mabibli), application de +gestion de bibliothèque personnelle (catalogue, prêts, scan ISBN). + +Ce dépôt **ne contient aucun code C#**. Il porte uniquement de quoi installer sur YunoHost une +archive déjà compilée : le manifeste, les configurations nginx et systemd, et les scripts +d'installation. + +## Contenu + +| Fichier | Rôle | +|---|---| +| `manifest.toml` | Identité, version, URL de l'archive et son `sha256`, ressources (utilisateur système, répertoires, port, permissions) | +| `conf/systemd.service` | Unité du service — écoute sur `127.0.0.1`, base dans le répertoire de données, durcissement | +| `conf/nginx.conf` | Reverse proxy et intégration SSOwat | +| `scripts/_common.sh` | Variables partagées et sauvegarde/restauration cohérente de la base SQLite | +| `scripts/install` `remove` `upgrade` `backup` `restore` | Cycle de vie de l'application | +| `build/publier-release.sh` | Compile, archive, calcule le `sha256` et met à jour `manifest.toml` | + +## Publier une nouvelle version + +Le serveur ne compile jamais : il télécharge une archive déjà produite. La chaîne est donc +« compiler ici, déposer une release, mettre à jour le manifeste ». + +```bash +# Depuis ce dépôt, avec le dépôt du code à côté (../mabibli) +./build/publier-release.sh --version 0.2.0 --base-url https://gitea.exemple.org/mathieu/mabibli/releases/download +``` + +Le script : + +1. lance `dotnet publish MaBibli.Api -c Release -r linux-x64 --self-contained` ; +2. vérifie que le binaire est là, que `wwwroot/` a bien été embarqué, et que **toutes** les + ressources référencées par `index.html` existent réellement dans le publish ; +3. produit `build/dist/mabibli--linux-x64.tar.gz`, de façon reproductible ; +4. en calcule le `sha256` ; +5. réécrit `version`, `amd64.url` et `amd64.sha256` dans `manifest.toml`. + +Restent à faire à la main : créer le tag et la release sur Gitea, y téléverser l'archive, puis +committer `manifest.toml`. + +Le script ne dépend d'aucun environnement de CI : tout passe par des options ou des variables +d'environnement (`MABIBLI_SOURCE_DIR`, `MABIBLI_VERSION`, `MABIBLI_BASE_URL`, +`MABIBLI_OUTPUT_DIR`), il ne pose aucune question et s'arrête à la première erreur. Il est donc +utilisable tel quel dans Gitea Actions le jour où un runner sera disponible. + +## Points de conception + +**Le service n'écoute que sur `127.0.0.1`.** L'application déduit l'identité de l'en-tête +`YNH_USER` injecté par SSOwat ; cet en-tête n'est digne de confiance que si nginx est le seul +chemin d'accès. Un service exposé sur le réseau permettrait de forger `YNH_USER` et de +contourner le portail. La contrainte est écrite dans `conf/systemd.service` (`ASPNETCORE_URLS`) +et le port n'est pas ouvert au pare-feu. + +**Aucune compilation sur le serveur.** Le publish est *self-contained* : il embarque son propre +runtime .NET, donc aucun paquet `dotnet-runtime` n'est nécessaire. `ynh_setup_source` vérifie le +`sha256` de l'archive avant de la déployer. + +**Les données survivent aux mises à jour.** La base SQLite vit dans le répertoire de données, pas +à côté du binaire ; `upgrade` ne remplace que le répertoire d'installation. + +**La sauvegarde passe par l'API de sauvegarde en ligne de SQLite.** La base est en mode WAL : +copier le seul fichier `.db` d'une base active peut ne rien sauvegarder du tout. Voir +`doc/ADMIN.md`. + +## Documentation + +- `doc/DESCRIPTION.md` — présentation affichée dans le catalogue YunoHost +- `doc/ADMIN.md` — authentification, emplacement des données, sauvegarde, contraintes diff --git a/build/dist/mabibli-0.1.0-linux-x64.tar.gz b/build/dist/mabibli-0.1.0-linux-x64.tar.gz new file mode 100644 index 0000000..28e40f3 Binary files /dev/null and b/build/dist/mabibli-0.1.0-linux-x64.tar.gz differ diff --git a/build/publier-release.sh b/build/publier-release.sh new file mode 100755 index 0000000..babaf2f --- /dev/null +++ b/build/publier-release.sh @@ -0,0 +1,272 @@ +#!/bin/bash +# +# Produit l'archive de release de MaBibli et met à jour manifest.toml. +# +# Pourquoi ce script vit dans `mabibli_ynh` et non dans `mabibli` : +# sa sortie utile n'est pas l'archive, c'est le couple (url, sha256) que le +# manifeste doit porter. Le garder ici permet de compiler, d'archiver et de mettre à +# jour le manifeste en une commande, puis de committer le tout d'un bloc — le +# manifeste ne peut pas se désynchroniser de l'archive qu'il décrit. +# +# Réutilisable en CI (Gitea Actions) sans modification : aucune interaction, aucune +# variable propre à un environnement d'intégration, tout passe par des options ou des +# variables d'environnement, et le script échoue au premier problème. +# +# Exemple d'usage en CI : +# ./build/publier-release.sh \ +# --source-dir "$GITHUB_WORKSPACE/mabibli" \ +# --version 0.2.0 \ +# --base-url "https://gitea.exemple.org/mathieu/mabibli/releases/download" +# +set -euo pipefail + +#================================================= +# VALEURS PAR DÉFAUT +#================================================= + +racine_paquet="$(cd "$(dirname "${BASH_SOURCE[0]}")/.." && pwd)" + +source_dir="${MABIBLI_SOURCE_DIR:-$(cd "$racine_paquet/../mabibli" 2>/dev/null && pwd || true)}" +version="${MABIBLI_VERSION:-}" +base_url="${MABIBLI_BASE_URL:-https://gitea.example.org/mathieu/mabibli/releases/download}" +output_dir="${MABIBLI_OUTPUT_DIR:-$racine_paquet/build/dist}" +maj_manifeste=1 +runtime="linux-x64" +projet="MaBibli.Api" + +#================================================= +# OPTIONS +#================================================= + +usage() { + cat <<'FIN' +Usage : publier-release.sh [options] + + --source-dir CHEMIN Dépôt du code C# (défaut : ../mabibli) + --version X.Y.Z Version de la release (défaut : déduite de manifest.toml) + --base-url URL Racine des URL de release, sans le tag ni le fichier + --output-dir CHEMIN Où déposer l'archive (défaut : build/dist) + --no-manifest-update Ne pas réécrire manifest.toml + -h, --help Cette aide + +Variables d'environnement équivalentes : MABIBLI_SOURCE_DIR, MABIBLI_VERSION, +MABIBLI_BASE_URL, MABIBLI_OUTPUT_DIR. +FIN +} + +while [ $# -gt 0 ]; do + case "$1" in + --source-dir) source_dir="$2"; shift 2 ;; + --version) version="$2"; shift 2 ;; + --base-url) base_url="$2"; shift 2 ;; + --output-dir) output_dir="$2"; shift 2 ;; + --no-manifest-update) maj_manifeste=0; shift ;; + -h|--help) usage; exit 0 ;; + *) echo "Option inconnue : $1" >&2; usage >&2; exit 2 ;; + esac +done + +manifeste="$racine_paquet/manifest.toml" + +#================================================= +# CONTRÔLES PRÉALABLES +#================================================= + +echoerr() { echo "$@" >&2; } + +if [ -z "$source_dir" ] || [ ! -d "$source_dir" ]; then + echoerr "Dépôt du code introuvable : '${source_dir:-}'" + echoerr "Précisez-le avec --source-dir." + exit 1 +fi +source_dir="$(cd "$source_dir" && pwd)" + +if [ ! -d "$source_dir/$projet" ]; then + echoerr "'$source_dir' ne contient pas de projet $projet." + exit 1 +fi + +if ! command -v dotnet >/dev/null; then + echoerr "Le SDK .NET est introuvable. Il n'est nécessaire QUE sur cette machine :" + echoerr "le serveur YunoHost reçoit un publish self-contained et n'a pas de SDK." + exit 1 +fi + +# La version par défaut se lit dans le manifeste, en retirant le suffixe ~ynhN : +# le tag et le nom de fichier portent la version applicative, pas celle du paquet. +if [ -z "$version" ]; then + version="$(sed -n 's/^version *= *"\([^"~]*\).*"/\1/p' "$manifeste" | head -1)" + if [ -z "$version" ]; then + echoerr "Impossible de déduire la version depuis $manifeste ; utilisez --version." + exit 1 + fi + echo "Version déduite de manifest.toml : $version" +fi + +#================================================= +# COMPILATION +#================================================= + +travail="$(mktemp -d)" +# shellcheck disable=SC2064 +trap "rm -rf '$travail'" EXIT + +publish="$travail/publish" + +echo +echo "=== Compilation self-contained $runtime ===" +echo " source : $source_dir" +echo " version: $version" + +# `--self-contained` embarque le runtime .NET dans le dossier publié : c'est ce qui +# permet au paquet YunoHost de ne dépendre d'aucun `dotnet-runtime` côté serveur. +# +# `MaBibli.Api` référence `MaBibli.Client` : le client Blazor WebAssembly est compilé +# au passage et atterrit dans `wwwroot/`. Un seul publish suffit donc pour les trois +# projets. +dotnet publish "$source_dir/$projet" \ + --configuration Release \ + --runtime "$runtime" \ + --self-contained \ + --output "$publish" \ + -p:Version="$version" + +#================================================= +# CONTRÔLES SUR LE RÉSULTAT +#================================================= + +echo +echo "=== Vérification du publish ===" + +if [ ! -x "$publish/$projet" ]; then + echoerr "Binaire '$projet' absent ou non exécutable dans le publish." + exit 1 +fi + +# Sans `wwwroot`, le service démarrerait et répondrait — en ne servant aucune page. +# C'est le défaut qui est passé inaperçu pendant trois phases du projet, faute de +# regarder ailleurs que la racine. On le vérifie donc ici, à la source. +if [ ! -f "$publish/wwwroot/index.html" ]; then + echoerr "wwwroot/index.html absent : le client Blazor n'a pas été embarqué." + exit 1 +fi + +# `index.html` doit référencer un script réellement présent. Un placeholder non +# substitué (`blazor.webassembly#[.{fingerprint}].js`) donnerait une page blanche +# alors que `/` répondrait 200. +if grep -q '#\[\.{fingerprint}\]' "$publish/wwwroot/index.html"; then + echoerr "index.html contient des placeholders d'empreinte non substitués." + echoerr "Voir CLAUDE.md, « Empreintes WASM désactivées »." + exit 1 +fi + +for ressource in $(grep -oE '(src|href)="[^"]+"' "$publish/wwwroot/index.html" \ + | sed -E 's/^(src|href)="//; s/"$//' \ + | grep -vE '^(https?:|data:|#|/$|\.$)'); do + if [ ! -f "$publish/wwwroot/$ressource" ]; then + echoerr "index.html référence '$ressource', absent du publish." + exit 1 + fi +done + +echo " binaire, wwwroot et ressources d'index.html : OK" + +#================================================= +# ARCHIVE +#================================================= + +archive_nom="mabibli-$version-$runtime.tar.gz" +mkdir -p "$output_dir" +archive="$output_dir/$archive_nom" + +echo +echo "=== Archive ===" + +# Fichiers à la racine de l'archive, sans dossier intermédiaire : cohérent avec +# `in_subdir = false` dans manifest.toml. +# +# Options de reproductibilité : sans elles, deux compilations identiques donneraient +# deux sha256 différents (dates, ordre de parcours, uid/gid). En CI comme en local, +# on veut pouvoir vérifier qu'une archive correspond bien à un commit. +tar --create --gzip \ + --file="$archive" \ + --directory="$publish" \ + --owner=0 --group=0 --numeric-owner \ + --mtime="@${SOURCE_DATE_EPOCH:-0}" \ + --sort=name \ + . + +somme="$(sha256sum "$archive" | cut -d' ' -f1)" +taille="$(du -h "$archive" | cut -f1)" +taille_octets="$(stat -c%s "$archive")" + +echo " fichier : $archive" +echo " taille : $taille ($taille_octets octets)" +echo " sha256 : $somme" + +#================================================= +# MISE À JOUR DU MANIFESTE +#================================================= + +url="$base_url/v$version/$archive_nom" + +if [ "$maj_manifeste" -eq 1 ]; then + echo + echo "=== Mise à jour de manifest.toml ===" + + # Le suffixe ~ynhN est conservé s'il existe déjà pour cette version, sinon + # remis à ~ynh1 : un changement de version applicative repart toujours de 1. + version_actuelle="$(sed -n 's/^version *= *"\([^"]*\)".*/\1/p' "$manifeste" | head -1)" + if [[ "$version_actuelle" == "$version~ynh"* ]]; then + version_paquet="$version_actuelle" + echo " version : $version_paquet (inchangée)" + else + version_paquet="$version~ynh1" + echo " version : $version_actuelle -> $version_paquet" + fi + + python3 - "$manifeste" "$version_paquet" "$url" "$somme" <<'PY' +import re, sys + +chemin, version, url, somme = sys.argv[1:5] +with open(chemin, encoding="utf-8") as f: + texte = f.read() + +remplacements = [ + (r'^version = ".*"$', f'version = "{version}"'), + (r'^ amd64\.url = ".*"$', f' amd64.url = "{url}"'), + (r'^ amd64\.sha256 = ".*"$', f' amd64.sha256 = "{somme}"'), +] + +for motif, valeur in remplacements: + texte, n = re.subn(motif, valeur, texte, count=1, flags=re.MULTILINE) + if n != 1: + sys.exit(f"Motif introuvable dans le manifeste : {motif}") + +with open(chemin, "w", encoding="utf-8") as f: + f.write(texte) +PY + + echo " url : $url" + echo " sha256 : $somme" +fi + +#================================================= +# SUITE À DONNER +#================================================= + +cat < 1024, donc même +# CAP_NET_BIND_SERVICE est inutile. +CapabilityBoundingSet= +AmbientCapabilities= + +# Liste reprise de radarr_ynh, autre application .NET packagée sans Docker, donc +# éprouvée sur ce runtime. +SystemCallFilter=~@clock @debug @module @mount @obsolete @reboot @setuid @swap + +# ⚠️ Ne PAS ajouter MemoryDenyWriteExecute=yes : le JIT de .NET a besoin de pages +# exécutables inscriptibles, le service ne démarrerait pas. + +[Install] +WantedBy=multi-user.target diff --git a/doc/ADMIN.md b/doc/ADMIN.md new file mode 100644 index 0000000..473f9dd --- /dev/null +++ b/doc/ADMIN.md @@ -0,0 +1,82 @@ +## Comment l'authentification fonctionne + +MaBibli n'a **pas de connexion propre**. L'identité vient entièrement du portail YunoHost : +nginx authentifie le visiteur, puis SSOwat injecte dans la requête les en-têtes `YNH_USER`, +`YNH_USER_EMAIL` et `YNH_USER_FULLNAME`, que l'application se contente de lire. + +Conséquences pratiques : + +- **Qui peut voir la bibliothèque se règle dans les permissions YunoHost** (`mabibli.main`), + pas dans l'application. +- La collection est **commune** à toutes les personnes autorisées. Chaque livre garde une trace + de qui l'a saisi, mais personne n'est cloisonné : c'est une bibliothèque de foyer. +- Les **statuts de lecture sont personnels** (chacun sa progression), les **prêts sont communs** + (un livre absent l'est pour tout le monde). +- Se déconnecter du portail YunoHost ne déconnecte pas nécessairement des applications : + chacune garde sa propre session. C'est une limite connue de YunoHost, pas de MaBibli. + +⚠️ **Ne pas exposer le port interne.** Le service écoute volontairement sur `127.0.0.1` +uniquement. L'application fait confiance à `YNH_USER` parce que SSOwat écrase cet en-tête à +chaque requête ; un service joignable directement permettrait à quiconque de forger +`YNH_USER` et de contourner le portail. Le port n'est pas ouvert au pare-feu, et +`ASPNETCORE_URLS` dans l'unité systemd ne doit jamais être élargi à `0.0.0.0` ou `*`. + +## Domaine entier obligatoire + +MaBibli s'installe **sur un domaine entier**, pas sous un sous-chemin (`/mabibli`). + +Le client est une application Blazor WebAssembly : son chemin de base et les empreintes +d'intégrité de son service worker sont figés **à la compilation**. Comme le paquet installe une +archive déjà compilée — et ne compile jamais rien sur le serveur — il n'existe pas de moyen +propre de les réécrire à l'installation. YunoHost refusera donc un changement d'URL vers un +sous-chemin. + +## Où vivent les données + +| Quoi | Où | +|---|---| +| Binaires et client web | `/var/www/mabibli` (appartient à `root`, l'application ne peut pas s'y écrire) | +| Base SQLite | `/home/yunohost.app/mabibli/mabibli.db` | +| Journaux | `journalctl -u mabibli` | + +La base est **délibérément séparée des binaires** : une mise à jour remplace intégralement +`/var/www/mabibli` sans jamais toucher aux données. Le schéma est migré automatiquement au +démarrage, il n'y a aucune commande à lancer après une mise à jour. + +## Sauvegarde + +La base tourne en mode **WAL**. C'est important pour qui voudrait bricoler une sauvegarde à la +main : à un instant donné, l'essentiel des données peut se trouver dans `mabibli.db-wal` et +**pas** dans `mabibli.db`. Mesuré sur une base fraîchement migrée, `mabibli.db` faisait 4 Ko — +et ne contenait **aucune table** — pendant que le fichier `-wal` en portait 205 Ko. + +Le script de sauvegarde du paquet ne copie donc pas les fichiers tels quels : il demande à +SQLite un instantané cohérent (`.backup`, l'API de sauvegarde en ligne), déposé à côté de la +base sous le nom `mabibli-instantane.db`. C'est ce fichier que la restauration remet en place, +en écartant au passage les `-wal` / `-shm` de l'archive, qui décrivaient l'état d'une autre +copie de la base. + +Le service **n'est pas arrêté** pendant la sauvegarde : l'API de sauvegarde en ligne garantit la +cohérence du fichier produit sans bloquer les lectures, et couper l'application à chaque +sauvegarde nocturne coûterait une indisponibilité pour rien. + +Pour une sauvegarde manuelle, la bonne commande est donc : + +```bash +sqlite3 /home/yunohost.app/mabibli/mabibli.db ".backup '/quelque/part/mabibli.db'" +``` + +et surtout pas un `cp` du seul fichier `.db`. + +## Le scan du code-barres exige HTTPS + +L'accès à la caméra n'est autorisé par les navigateurs que dans un contexte sécurisé. En +production, le certificat Let's Encrypt de YunoHost suffit. En revanche, joindre le serveur par +son IP locale (`http://192.168.x.x`) fera **toujours** échouer le scan : ce n'est pas un +contexte sécurisé. La saisie manuelle de l'ISBN reste disponible dans tous les cas. + +## Accès sortant nécessaire + +Le serveur doit pouvoir joindre `catalogue.bnf.fr` et `openlibrary.org` en HTTPS pour +pré-remplir les fiches à partir d'un ISBN. Sans accès sortant, l'application fonctionne, mais +toute saisie devient manuelle. diff --git a/doc/ADMIN_fr.md b/doc/ADMIN_fr.md new file mode 100644 index 0000000..473f9dd --- /dev/null +++ b/doc/ADMIN_fr.md @@ -0,0 +1,82 @@ +## Comment l'authentification fonctionne + +MaBibli n'a **pas de connexion propre**. L'identité vient entièrement du portail YunoHost : +nginx authentifie le visiteur, puis SSOwat injecte dans la requête les en-têtes `YNH_USER`, +`YNH_USER_EMAIL` et `YNH_USER_FULLNAME`, que l'application se contente de lire. + +Conséquences pratiques : + +- **Qui peut voir la bibliothèque se règle dans les permissions YunoHost** (`mabibli.main`), + pas dans l'application. +- La collection est **commune** à toutes les personnes autorisées. Chaque livre garde une trace + de qui l'a saisi, mais personne n'est cloisonné : c'est une bibliothèque de foyer. +- Les **statuts de lecture sont personnels** (chacun sa progression), les **prêts sont communs** + (un livre absent l'est pour tout le monde). +- Se déconnecter du portail YunoHost ne déconnecte pas nécessairement des applications : + chacune garde sa propre session. C'est une limite connue de YunoHost, pas de MaBibli. + +⚠️ **Ne pas exposer le port interne.** Le service écoute volontairement sur `127.0.0.1` +uniquement. L'application fait confiance à `YNH_USER` parce que SSOwat écrase cet en-tête à +chaque requête ; un service joignable directement permettrait à quiconque de forger +`YNH_USER` et de contourner le portail. Le port n'est pas ouvert au pare-feu, et +`ASPNETCORE_URLS` dans l'unité systemd ne doit jamais être élargi à `0.0.0.0` ou `*`. + +## Domaine entier obligatoire + +MaBibli s'installe **sur un domaine entier**, pas sous un sous-chemin (`/mabibli`). + +Le client est une application Blazor WebAssembly : son chemin de base et les empreintes +d'intégrité de son service worker sont figés **à la compilation**. Comme le paquet installe une +archive déjà compilée — et ne compile jamais rien sur le serveur — il n'existe pas de moyen +propre de les réécrire à l'installation. YunoHost refusera donc un changement d'URL vers un +sous-chemin. + +## Où vivent les données + +| Quoi | Où | +|---|---| +| Binaires et client web | `/var/www/mabibli` (appartient à `root`, l'application ne peut pas s'y écrire) | +| Base SQLite | `/home/yunohost.app/mabibli/mabibli.db` | +| Journaux | `journalctl -u mabibli` | + +La base est **délibérément séparée des binaires** : une mise à jour remplace intégralement +`/var/www/mabibli` sans jamais toucher aux données. Le schéma est migré automatiquement au +démarrage, il n'y a aucune commande à lancer après une mise à jour. + +## Sauvegarde + +La base tourne en mode **WAL**. C'est important pour qui voudrait bricoler une sauvegarde à la +main : à un instant donné, l'essentiel des données peut se trouver dans `mabibli.db-wal` et +**pas** dans `mabibli.db`. Mesuré sur une base fraîchement migrée, `mabibli.db` faisait 4 Ko — +et ne contenait **aucune table** — pendant que le fichier `-wal` en portait 205 Ko. + +Le script de sauvegarde du paquet ne copie donc pas les fichiers tels quels : il demande à +SQLite un instantané cohérent (`.backup`, l'API de sauvegarde en ligne), déposé à côté de la +base sous le nom `mabibli-instantane.db`. C'est ce fichier que la restauration remet en place, +en écartant au passage les `-wal` / `-shm` de l'archive, qui décrivaient l'état d'une autre +copie de la base. + +Le service **n'est pas arrêté** pendant la sauvegarde : l'API de sauvegarde en ligne garantit la +cohérence du fichier produit sans bloquer les lectures, et couper l'application à chaque +sauvegarde nocturne coûterait une indisponibilité pour rien. + +Pour une sauvegarde manuelle, la bonne commande est donc : + +```bash +sqlite3 /home/yunohost.app/mabibli/mabibli.db ".backup '/quelque/part/mabibli.db'" +``` + +et surtout pas un `cp` du seul fichier `.db`. + +## Le scan du code-barres exige HTTPS + +L'accès à la caméra n'est autorisé par les navigateurs que dans un contexte sécurisé. En +production, le certificat Let's Encrypt de YunoHost suffit. En revanche, joindre le serveur par +son IP locale (`http://192.168.x.x`) fera **toujours** échouer le scan : ce n'est pas un +contexte sécurisé. La saisie manuelle de l'ISBN reste disponible dans tous les cas. + +## Accès sortant nécessaire + +Le serveur doit pouvoir joindre `catalogue.bnf.fr` et `openlibrary.org` en HTTPS pour +pré-remplir les fiches à partir d'un ISBN. Sans accès sortant, l'application fonctionne, mais +toute saisie devient manuelle. diff --git a/doc/DESCRIPTION.md b/doc/DESCRIPTION.md new file mode 100644 index 0000000..324b2f4 --- /dev/null +++ b/doc/DESCRIPTION.md @@ -0,0 +1,9 @@ +MaBibli est une application de gestion de bibliothèque personnelle, pensée pour un foyer. + +- **Catalogue** des livres physiques et des ebooks (fiches uniquement, aucun fichier n'est hébergé). +- **Prêts** : à qui le livre a été confié, depuis quand, et l'historique complet des prêts passés. +- **Scan ISBN** au code-barres depuis le téléphone, ou saisie manuelle, avec pré-remplissage automatique du titre, de l'auteur, de l'éditeur et de la couverture. +- **Statuts de lecture** personnels : chaque membre du foyer suit sa propre progression sur une collection commune. +- **Consultation hors-ligne** : l'application est une PWA installable, et la bibliothèque reste consultable sans réseau. + +Les métadonnées viennent du catalogue de la **BnF** puis d'**OpenLibrary**, deux sources libres et sans clé d'API. Aucune dépendance à Google Books. diff --git a/doc/DESCRIPTION_fr.md b/doc/DESCRIPTION_fr.md new file mode 100644 index 0000000..324b2f4 --- /dev/null +++ b/doc/DESCRIPTION_fr.md @@ -0,0 +1,9 @@ +MaBibli est une application de gestion de bibliothèque personnelle, pensée pour un foyer. + +- **Catalogue** des livres physiques et des ebooks (fiches uniquement, aucun fichier n'est hébergé). +- **Prêts** : à qui le livre a été confié, depuis quand, et l'historique complet des prêts passés. +- **Scan ISBN** au code-barres depuis le téléphone, ou saisie manuelle, avec pré-remplissage automatique du titre, de l'auteur, de l'éditeur et de la couverture. +- **Statuts de lecture** personnels : chaque membre du foyer suit sa propre progression sur une collection commune. +- **Consultation hors-ligne** : l'application est une PWA installable, et la bibliothèque reste consultable sans réseau. + +Les métadonnées viennent du catalogue de la **BnF** puis d'**OpenLibrary**, deux sources libres et sans clé d'API. Aucune dépendance à Google Books. diff --git a/manifest.toml b/manifest.toml new file mode 100644 index 0000000..4126eb9 --- /dev/null +++ b/manifest.toml @@ -0,0 +1,115 @@ +#:schema https://raw.githubusercontent.com/YunoHost/apps/master/schemas/manifest.v2.schema.json + +packaging_format = 2 + +id = "mabibli" +name = "MaBibli" +description.fr = "Gestion de bibliothèque personnelle : catalogue, prêts et scan ISBN" +description.en = "Personal library manager: catalogue, loans and ISBN scanning" + +version = "0.1.0~ynh1" + +maintainers = ["mathieu"] + +[upstream] +license = "AGPL-3.0-or-later" +code = "https://gitea.example.org/mathieu/mabibli" + +[integration] +yunohost = ">= 12.1.38" +helpers_version = "2.1" + +# x86_64 uniquement : CLAUDE.md acte un serveur PC/VPS, et la chaîne de publication +# ne produit qu'un binaire `linux-x64`. Déclarer d'autres architectures promettrait +# des archives qui n'existent pas. +architectures = ["amd64"] + +# Une seule instance : la bibliothèque est commune au foyer (CLAUDE.md, « Portée des +# données »). Deux instances voudraient dire deux collections étanches, ce qui est +# exactement ce que le projet a écarté. +multi_instance = false + +# L'application ne parle pas à LDAP : elle lit l'identité dans les en-têtes que +# SSOwat injecte. C'est bien une intégration SSO, mais pas une intégration LDAP. +ldap = false +sso = true + +# ~170 Mo de publish self-contained (runtime .NET embarqué), plus la base et la marge +# de décompression de l'archive. +disk = "500M" +ram.build = "50M" +ram.runtime = "200M" + +[install] + + [install.domain] + type = "domain" + + # Pas de question `path` : MaBibli s'installe sur un domaine entier. + # + # Ce n'est pas un oubli. Le client Blazor WebAssembly fige son `` + # et les empreintes de `service-worker-assets.js` **à la compilation**. Servir + # l'application sous un sous-chemin demanderait de réécrire `index.html` sur le + # serveur, ce qui invaliderait les empreintes d'intégrité du service worker et + # casserait le mode hors-ligne. Comme le paquet ne compile rien sur le serveur, + # la seule option honnête est le domaine entier. + # + # Conséquence côté YunoHost : `resources.permissions.main.url` étant une chaîne, + # le cœur classe l'app en « full_domain » et refusera un changement d'URL vers + # un sous-chemin. + + [install.init_main_permission] + type = "group" + default = "all_users" + help.fr = "Qui peut accéder à la bibliothèque. MaBibli n'a pas de connexion propre : l'identité vient du portail YunoHost, et la collection est commune à toutes les personnes autorisées." + help.en = "Who may access the library. MaBibli has no login of its own: identity comes from the YunoHost portal, and the collection is shared between all allowed users." + +[resources] + + [resources.sources.main] + # Archive **déjà compilée** (publish self-contained linux-x64), produite par + # `build/publier-release.sh` et déposée en release sur le Gitea de l'utilisateur. + # Le SDK .NET n'est jamais installé sur le serveur : c'est tout l'intérêt du + # self-contained (CLAUDE.md, « Ne jamais compiler sur le serveur »). + # + # Ces deux valeurs sont réécrites par `build/publier-release.sh`. + amd64.url = "https://gitea.example.org/mathieu/mabibli/releases/download/v0.1.0/mabibli-0.1.0-linux-x64.tar.gz" + amd64.sha256 = "a202f59b4d55aac172d78defd7733bee30d8a115d899ed0da55cd935f6bf679d" + + # L'archive dépose ses fichiers à la racine, sans dossier intermédiaire. + in_subdir = false + + # Pas d'`autoupdate` : les releases sont déposées à la main sur un Gitea privé, + # aucune stratégie amont connue de YunoHost ne s'y applique. + + [resources.system_user] + + [resources.install_dir] + # Le service tourne sous `mabibli` mais ne doit **pas** pouvoir réécrire ses + # propres binaires : propriétaire root, application en lecture seule. Cela va de + # pair avec `ProtectSystem=strict` dans l'unité systemd. + owner = "root:rwx" + group = "__APP__:rx" + + [resources.data_dir] + # La base SQLite vit ici, et **pas** à côté du binaire : c'est ce qui permet à une + # mise à jour de remplacer intégralement `install_dir` sans toucher aux données. + owner = "__APP__:rwx" + group = "__APP__:rx" + + [resources.permissions] + # Toute l'application derrière le SSO, `/api` compris : la bibliothèque est + # familiale, rien n'a vocation à être public. `auth_header` vaut `true` par + # défaut, c'est lui qui autorise SSOwat à injecter `YNH_USER` — sans quoi + # l'application ne saurait jamais qui la consulte. + main.url = "/" + main.auth_header = true + + [resources.ports] + # Port interne uniquement. `exposed` vaut `false` par défaut : le pare-feu reste + # fermé, et l'unité systemd n'écoute que sur 127.0.0.1. + + [resources.apt] + # `sqlite3` sert aux sauvegardes : la base est en mode WAL (vérifié), un simple + # `cp` du fichier `.db` ne suffit pas. Voir `scripts/backup`. + packages = "sqlite3" diff --git a/scripts/_common.sh b/scripts/_common.sh new file mode 100755 index 0000000..65c130a --- /dev/null +++ b/scripts/_common.sh @@ -0,0 +1,87 @@ +#!/bin/bash + +#================================================= +# VARIABLES ET HELPERS PROPRES À MABIBLI +#================================================= + +# Nom du binaire produit par `dotnet publish MaBibli.Api`. +mabibli_binaire="MaBibli.Api" + +# Base SQLite. Doit rester cohérent avec `ConnectionStrings__MaBibli` dans +# conf/systemd.service. +mabibli_base="mabibli.db" + +# Copie cohérente déposée dans le répertoire de données au moment de la sauvegarde, +# puis reprise par le script de restauration. +mabibli_instantane="mabibli-instantane.db" + +#================================================= +# SAUVEGARDE À CHAUD DE LA BASE SQLITE +#================================================= +# +# Pourquoi ce n'est pas un simple `cp` : +# +# La base tourne en mode **WAL** (vérifié sur le publish réel : `PRAGMA journal_mode` +# renvoie `wal`, et le répertoire contient bien `mabibli.db-wal` / `mabibli.db-shm`). +# En WAL, les écritures récentes vivent dans le fichier `-wal` et **pas** dans le +# `.db`. Sur la base fraîchement migrée mesurée en local, le `.db` faisait 4 Ko pour +# un `-wal` de 205 Ko : copier le seul `.db` aurait sauvegardé une base à peu près +# vide. Copier les trois fichiers pendant que le service écrit ne vaut guère mieux, +# puisque rien ne garantit qu'ils soient capturés au même instant. +# +# `.backup` utilise l'API de sauvegarde en ligne de SQLite : elle produit un fichier +# unique, cohérent, sans arrêter le service ni bloquer les lectures. C'est la seule +# méthode correcte pour une sauvegarde à chaud, et elle évite d'imposer une coupure +# de service à chaque sauvegarde nocturne. +# +# usage : mabibli_instantane_base "$data_dir" +mabibli_instantane_base() { + local repertoire="$1" + local source="$repertoire/$mabibli_base" + local cible="$repertoire/$mabibli_instantane" + + # Un instantané laissé par une sauvegarde précédente n'a plus de valeur. + # (Il ne peut pas être effacé en fin de sauvegarde : `ynh_backup` ne fait que + # *déclarer* les chemins, la copie réelle a lieu plus tard, par le cœur de + # YunoHost.) + rm -f "$cible" + + if [ ! -f "$source" ]; then + ynh_print_warn "Aucune base à $source : rien à figer. Première sauvegarde avant tout démarrage ?" + return 0 + fi + + # `.backup` échoue proprement si la base est corrompue : mieux vaut interrompre + # la sauvegarde que d'archiver un fichier illisible en croyant être protégé. + sqlite3 "$source" ".backup '$cible'" + + chown "$app:$app" "$cible" + chmod 600 "$cible" +} + +#================================================= +# REPRISE DE L'INSTANTANÉ APRÈS RESTAURATION +#================================================= +# +# usage : mabibli_reprendre_instantane "$data_dir" +mabibli_reprendre_instantane() { + local repertoire="$1" + local instantane="$repertoire/$mabibli_instantane" + + if [ ! -f "$instantane" ]; then + ynh_print_warn "Pas d'instantané dans l'archive : la base est reprise telle quelle." + return 0 + fi + + # ⚠️ Les fichiers `-wal` et `-shm` de l'archive décrivent l'état d'une *autre* + # copie de la base. Les laisser à côté de l'instantané ferait rejouer à SQLite + # un journal qui ne lui correspond pas. Ils doivent disparaître. + rm -f "$repertoire/$mabibli_base" \ + "$repertoire/$mabibli_base-wal" \ + "$repertoire/$mabibli_base-shm" + + mv "$instantane" "$repertoire/$mabibli_base" + + chown "$app:$app" "$repertoire/$mabibli_base" + chmod 600 "$repertoire/$mabibli_base" +} diff --git a/scripts/backup b/scripts/backup new file mode 100755 index 0000000..58a1e94 --- /dev/null +++ b/scripts/backup @@ -0,0 +1,44 @@ +#!/bin/bash + +# Chemin imposé : dans le contexte d'exécution de backup/restore, `_common.sh` n'est +# pas dans le répertoire courant. +source ../settings/scripts/_common.sh +source /usr/share/yunohost/helpers + +#================================================= +# INSTANTANÉ COHÉRENT DE LA BASE +#================================================= +ynh_print_info "Capture d'une copie cohérente de la base SQLite..." + +# Voir `_common.sh` pour le détail : la base est en WAL, un `cp` du seul fichier +# `.db` sauvegarderait une base tronquée. `.backup` produit un fichier unique et +# cohérent sans arrêter le service. +# +# Le service continue de tourner pendant la sauvegarde. C'est un choix assumé : +# l'API de sauvegarde en ligne de SQLite garantit la cohérence du fichier produit, et +# l'alternative — couper le service à chaque sauvegarde nocturne — coûterait une +# indisponibilité pour un gain nul. +mabibli_instantane_base "$data_dir" + +#================================================= +# DÉCLARATION DES CHEMINS À SAUVEGARDER +#================================================= + +ynh_backup "$install_dir" + +# Emporte l'instantané cohérent. Les `mabibli.db`, `-wal` et `-shm` vivants s'y +# trouvent aussi : la restauration les ignore au profit de l'instantané. +# +# À noter : le cœur de YunoHost saute `data_dir` lors de la sauvegarde de sécurité +# qui précède une mise à jour (`BACKUP_CORE_ONLY`). Ce n'est pas gênant, une mise à +# jour ne touchant pas au répertoire de données. +ynh_backup "$data_dir" + +ynh_backup "/etc/nginx/conf.d/$domain.d/$app.conf" +ynh_backup "/etc/systemd/system/$app.service" + +#================================================= +# FIN DU SCRIPT +#================================================= + +ynh_print_info "Sauvegarde de $app préparée. (YunoHost copie maintenant ces fichiers dans l'archive.)" diff --git a/scripts/install b/scripts/install new file mode 100755 index 0000000..3ea2890 --- /dev/null +++ b/scripts/install @@ -0,0 +1,65 @@ +#!/bin/bash + +source _common.sh +source /usr/share/yunohost/helpers + +#================================================= +# TÉLÉCHARGEMENT ET VÉRIFICATION DES BINAIRES +#================================================= +ynh_script_progression "Installation des fichiers..." + +# `ynh_setup_source` télécharge l'archive déclarée dans le manifeste, **vérifie son +# sha256** et la décompresse. Aucune compilation n'a lieu ici : l'archive est un +# publish self-contained, elle embarque son propre runtime .NET. C'est ce qui évite +# d'installer le SDK .NET sur le serveur YunoHost. +# +# En cas d'empreinte incorrecte ou de téléchargement interrompu, le helper interrompt +# le script ; YunoHost déclenche alors `remove` pour nettoyer, et rien n'a encore été +# configuré à ce stade. +ynh_setup_source --dest_dir="$install_dir" + +# L'archive est un tar : le bit exécutable devrait survivre, mais un tar reconstruit +# à la main pourrait l'avoir perdu, et l'unité systemd échouerait sans raison lisible. +chmod +x "$install_dir/$mabibli_binaire" + +#================================================= +# RÉPERTOIRE DE DONNÉES +#================================================= +ynh_script_progression "Préparation du répertoire de données..." + +# `data_dir` est créé par la ressource du manifeste. La base y sera créée au premier +# démarrage : l'application applique ses migrations EF Core toute seule, il n'y a +# aucune étape d'initialisation manuelle. +chown "$app:$app" "$data_dir" +chmod 750 "$data_dir" + +#================================================= +# CONFIGURATION NGINX ET SYSTEMD +#================================================= +ynh_script_progression "Configuration de NGINX et du service..." + +ynh_config_add_nginx +ynh_config_add_systemd + +# Les journaux partent dans journald (cf. `StandardOutput=journal`), il n'y a donc +# pas de fichier de log à faire tourner par logrotate. +yunohost service add "$app" --description="Bibliothèque personnelle MaBibli" + +#================================================= +# DÉMARRAGE DU SERVICE +#================================================= +ynh_script_progression "Démarrage de $app..." + +# « Application started » est la ligne émise par ASP.NET Core une fois l'écoute +# ouverte — vérifié sur le publish réel. Attendre cette ligne plutôt qu'un simple +# `systemctl start` permet à l'installation d'échouer franchement si les migrations +# EF Core ne passent pas, au lieu de rendre la main sur un service en boucle de +# redémarrage. +ynh_systemctl --service="$app" --action="start" --log_path="systemd" \ + --wait_until="Application started" --timeout=60 + +#================================================= +# FIN DU SCRIPT +#================================================= + +ynh_script_progression "Installation de $app terminée" diff --git a/scripts/remove b/scripts/remove new file mode 100755 index 0000000..ccf2c27 --- /dev/null +++ b/scripts/remove @@ -0,0 +1,32 @@ +#!/bin/bash + +source _common.sh +source /usr/share/yunohost/helpers + +#================================================= +# RETRAIT DU SERVICE DE LA LISTE YUNOHOST +#================================================= +ynh_script_progression "Retrait de l'intégration systemd et NGINX..." + +# Ce script est aussi appelé pour nettoyer une installation qui a échoué à +# mi-chemin : chaque étape doit donc tolérer que la précédente n'ait jamais eu lieu. +# `ynh_hide_warnings` couvre le cas où `yunohost service add` n'a pas encore tourné. +if ynh_hide_warnings yunohost service status "$app" >/dev/null; then + yunohost service remove "$app" +fi + +# Les helpers `ynh_config_remove_*` sont sans effet si la configuration +# correspondante n'existe pas. +ynh_config_remove_systemd +ynh_config_remove_nginx + +#================================================= +# FIN DU SCRIPT +#================================================= +# +# Ni `install_dir` ni `data_dir` ne sont effacés ici : le cœur de YunoHost s'en +# charge à partir des ressources du manifeste. `data_dir` n'est d'ailleurs détruit +# qu'avec `--purge`, ce qui laisse une chance de récupérer la bibliothèque après une +# désinstallation faite trop vite. + +ynh_script_progression "Suppression de $app terminée" diff --git a/scripts/restore b/scripts/restore new file mode 100755 index 0000000..61690ee --- /dev/null +++ b/scripts/restore @@ -0,0 +1,58 @@ +#!/bin/bash + +# Chemin imposé : dans le contexte d'exécution de backup/restore, `_common.sh` n'est +# pas dans le répertoire courant. +source ../settings/scripts/_common.sh +source /usr/share/yunohost/helpers + +#================================================= +# RESTAURATION DES BINAIRES +#================================================= +ynh_script_progression "Restauration des fichiers de l'application..." + +ynh_restore "$install_dir" + +chmod +x "$install_dir/$mabibli_binaire" +chown -R root:"$app" "$install_dir" + +#================================================= +# RESTAURATION DES DONNÉES +#================================================= +ynh_script_progression "Restauration de la bibliothèque..." + +ynh_restore "$data_dir" + +# Remet l'instantané cohérent en place et écarte les `-wal` / `-shm` de l'archive, +# qui décrivaient l'état d'une autre copie de la base (voir `_common.sh`). +mabibli_reprendre_instantane "$data_dir" + +chown -R "$app:$app" "$data_dir" +chmod 750 "$data_dir" + +#================================================= +# RESTAURATION DE LA CONFIGURATION +#================================================= +ynh_script_progression "Restauration de la configuration système..." + +ynh_restore "/etc/nginx/conf.d/$domain.d/$app.conf" + +ynh_restore "/etc/systemd/system/$app.service" +systemctl enable "$app.service" --quiet + +yunohost service add "$app" --description="Bibliothèque personnelle MaBibli" + +#================================================= +# REDÉMARRAGE +#================================================= +ynh_script_progression "Redémarrage de $app..." + +ynh_systemctl --service="$app" --action="start" --log_path="systemd" \ + --wait_until="Application started" --timeout=120 + +ynh_systemctl --service=nginx --action=reload + +#================================================= +# FIN DU SCRIPT +#================================================= + +ynh_script_progression "Restauration de $app terminée" diff --git a/scripts/upgrade b/scripts/upgrade new file mode 100755 index 0000000..38e034f --- /dev/null +++ b/scripts/upgrade @@ -0,0 +1,62 @@ +#!/bin/bash + +source _common.sh +source /usr/share/yunohost/helpers + +#================================================= +# ARRÊT DU SERVICE +#================================================= +ynh_script_progression "Arrêt de $app..." + +# Arrêter avant de remplacer les binaires, et surtout avant que les nouvelles +# migrations EF Core ne s'appliquent au démarrage : deux processus sur la même base +# SQLite pendant une migration est exactement ce qu'il faut éviter. +ynh_systemctl --service="$app" --action="stop" --log_path="systemd" + +#================================================= +# MISE À JOUR DES BINAIRES +#================================================= +ynh_script_progression "Mise à jour des fichiers..." + +# `ynh_setup_source` remplace le contenu d'`install_dir` par la nouvelle archive, +# après vérification du sha256. +# +# Les données ne sont pas concernées : la base vit dans `data_dir` +# (`ConnectionStrings__MaBibli` dans l'unité systemd), qui n'est touché ni ici ni par +# les ressources du manifeste. C'est précisément pour cela que la base n'est pas +# posée à côté du binaire — sinon chaque mise à jour l'emporterait. +ynh_setup_source --dest_dir="$install_dir" + +chmod +x "$install_dir/$mabibli_binaire" + +#================================================= +# CONFIGURATION NGINX ET SYSTEMD +#================================================= +ynh_script_progression "Mise à jour de la configuration..." + +ynh_config_add_nginx +ynh_config_add_systemd + +yunohost service add "$app" --description="Bibliothèque personnelle MaBibli" + +#================================================= +# REDÉMARRAGE DU SERVICE +#================================================= +ynh_script_progression "Redémarrage de $app..." + +# Le délai est plus large qu'à l'installation : une mise à jour peut embarquer des +# migrations EF Core à appliquer sur une base déjà remplie, ce qui prend plus de +# temps que la création d'un schéma vide. +# +# Si le démarrage échoue, YunoHost restaure la sauvegarde de sécurité prise avant la +# mise à jour. Cette sauvegarde-là ne contient pas `data_dir` (le cœur saute les +# répertoires de données avec `BACKUP_CORE_ONLY`) — ce qui tombe bien, puisque +# `data_dir` n'a pas été touché et contient toujours la bibliothèque. +ynh_systemctl --service="$app" --action="start" --log_path="systemd" \ + --wait_until="Application started" --timeout=120 + +#================================================= +# FIN DU SCRIPT +#================================================= + +ynh_script_progression "Mise à jour de $app terminée"