Skip to content

Releases: MuaraAI/UBSI-API

v1.1.0 — Security, Remote Ingress & Architectural Refactor

Choose a tag to compare

@Curzyori Curzyori released this 26 Sep 12:17

What's Changed in v1.1.0

👥 Contributors in this Release


🔀 Merged Pull Requests

  • PR #2: feat: pool sesi per NIM dan endpoint dashboard paralel by @MyKineID in #2
  • PR #3: feat: elearning pool + native async, stale-while-revalidate, metrics by @MyKineID in #3
  • PR #4: refactor: helper cached_endpoint, hapus duplikasi 223 baris by @MyKineID in #4

🔒 Security & Mandatory Authentication

  • Mandatory X-API-Key: Full access protection across all private endpoints using constant-time comparison (secrets.compare_digest) to prevent timing attacks.
  • Fail-Fast Startup: Server terminates boot with an informative error if API_KEY is not provided in production .env.
  • Selective Health Probe Whitelist: /health remains accessible without keys for monitoring probes (Uptime Kuma, Caddy, Cloudflare, deploy script), with trailing-slash resilience (/health/).
  • Strict File Permissions: Automated chmod 600 enforcement on .env files across deployment pipelines.

🌐 Dual-Path Remote Access & Reverse Proxy Support

  • Dual Remote Ingress: Production-ready configuration templates provided for Caddy (automated Let's Encrypt HTTPS), Nginx, and Cloudflare Tunnel (cloudflared). See docs/remote-access.md.
  • Real Client IP Rate Limiter: Multi-tier header resolution (CF-Connecting-IP -> X-Forwarded-For -> client host) validated against TRUSTED_PROXIES to ensure fair 60 req/min limits without IP collision.
  • Integrated CORS Support: Fully configurable CORSMiddleware enabling modern browser-based web dashboards.

🧹 Architectural Refactoring & Unified SWR

  • Generic Cached Endpoint Helper: Adopted cached_endpoint() across all 6 campus modules (studentv2, elearning, elibrary, news, repository, ejournal), eliminating over 300 lines of duplicated caching/locking boilerplate.
  • Full Stale-While-Revalidate (SWR): Sub-35ms instant response times using Last-Known-Good offline cache while refreshing data in the background.
  • Automated Session Cleanup: Background eviction task running every 5 minutes in lifespan to evict idle per-NIM scraper sessions and prevent memory leaks.
  • Unified Awaitable Execution: Generic support for both native async coroutines and threadpool executors via inspect.isawaitable.

🧪 Test Suite & Quality

  • Total 71 Automated Tests PASSED (100% Green, 0 Warnings).
  • Full offline HTML fixtures and transparent autouse test harness.

Full Changelog (Diff & Compare): v1.0.0...v1.1.0

v1.0.0 — Initial Production Release

Choose a tag to compare

@Curzyori Curzyori released this 26 Sep 08:03

UBSI API v1.0.0 — Initial Production Release

Rilis perdana resmi UBSI API (Unofficial REST API Aggregator untuk layanan kampus Universitas Bina Sarana Informatika).

✨ Fitur & Layanan Utama (6 Modul)

  • StudentV2 (SIAKAD): Jadwal kuliah semester aktif, nilai murni lengkap, pengumuman internal PDF, dan arsip berita.
  • MyBest LMS (Elearning): Kartu matkul, pemecah math captcha login otomatis, presensi hadir perkuliahan, tugas aktif & riwayat nilai/submission, berkas silabus/modul ZIP, dan kuis online.
  • Elibrary (Perpustakaan): Pencarian katalog OPAC, detail metadata buku, dan ketersediaan stok fisik rak dengan 60s exponential retry.
  • News Portal: Integrasi native WordPress REST API (news.bsi.ac.id/wp-json/wp/v2/posts?_embed=1) untuk artikel berita kampus.
  • Repository: Publikasi penelitian dan tugas akhir mahasiswa di EPrints.
  • EJournal: Katalog 16 jurnal ilmiah akademik resmi UBSI via jalur OAI bypass.

🛡️ Keamanan & Anti-Ban

  • Localhost Security Boundary: Binds eksklusif ke 127.0.0.1:8300 (nol port terbuka ke publik).
  • Two-Tier Redis Cache (DB 2): TTL berjenjang (Jadwal 2j, Nilai 30m, Tugas 10m) + Last-Known-Good offline fallback (stale: true).
  • Single-Flight Mutex: Mencegah spamming paralel terhadap server kampus.
  • Chrome TLS Impersonation: Menggunakan Scrapling & curl-cffi dengan fingerprint Chrome desktop asli.
  • Rate Limiting: 60 req/menit via Redis sliding window counter.

📚 Dokumentasi & Legalitas

  • Dokumentasi modular di folder docs/ (api.md, architecture.md, anti-ban.md, deploy.md).
  • Berkas legal lengkap: SECURITY.md, DMCA.md, CONTRIBUTING.md, dan LICENSE (MIT).
  • Author: Yuken Velino (@Curzyori) — NIM 15260767, Kelas 15.1C.30, Informatika, FTI UBSI Kampus Kota Pontianak.

🧪 Pengujian

  • 46 unit & integration tests lulus 100% via Pytest.
  • Live CLI Smoke Test lulus 7/7 checks.