Releases: MuaraAI/UBSI-API
Releases · MuaraAI/UBSI-API
Release list
v1.1.0 — Security, Remote Ingress & Architectural Refactor
What's Changed in v1.1.0
👥 Contributors in this Release
- Yuken Velino (@Curzyori) — Lead Developer & Creator
- Verzio (@MyKineID) — Contributor (PR #2, PR #3, PR #4)
🔀 Merged Pull Requests
- PR #2: feat: pool sesi per NIM dan endpoint dashboard paralel by @MyKineID in #2
- PR #3: feat: elearning pool + native async, stale-while-revalidate, metrics by @MyKineID in #3
- PR #4: refactor: helper cached_endpoint, hapus duplikasi 223 baris by @MyKineID in #4
🔒 Security & Mandatory Authentication
- Mandatory X-API-Key: Full access protection across all private endpoints using constant-time comparison (
secrets.compare_digest) to prevent timing attacks. - Fail-Fast Startup: Server terminates boot with an informative error if
API_KEYis not provided in production.env. - Selective Health Probe Whitelist:
/healthremains accessible without keys for monitoring probes (Uptime Kuma, Caddy, Cloudflare, deploy script), with trailing-slash resilience (/health/). - Strict File Permissions: Automated
chmod 600enforcement on.envfiles across deployment pipelines.
🌐 Dual-Path Remote Access & Reverse Proxy Support
- Dual Remote Ingress: Production-ready configuration templates provided for Caddy (automated Let's Encrypt HTTPS), Nginx, and Cloudflare Tunnel (
cloudflared). See docs/remote-access.md. - Real Client IP Rate Limiter: Multi-tier header resolution (
CF-Connecting-IP->X-Forwarded-For-> client host) validated againstTRUSTED_PROXIESto ensure fair 60 req/min limits without IP collision. - Integrated CORS Support: Fully configurable
CORSMiddlewareenabling modern browser-based web dashboards.
🧹 Architectural Refactoring & Unified SWR
- Generic Cached Endpoint Helper: Adopted
cached_endpoint()across all 6 campus modules (studentv2,elearning,elibrary,news,repository,ejournal), eliminating over 300 lines of duplicated caching/locking boilerplate. - Full Stale-While-Revalidate (SWR): Sub-35ms instant response times using Last-Known-Good offline cache while refreshing data in the background.
- Automated Session Cleanup: Background eviction task running every 5 minutes in
lifespanto evict idle per-NIM scraper sessions and prevent memory leaks. - Unified Awaitable Execution: Generic support for both native async coroutines and threadpool executors via
inspect.isawaitable.
🧪 Test Suite & Quality
- Total 71 Automated Tests PASSED (100% Green, 0 Warnings).
- Full offline HTML fixtures and transparent autouse test harness.
Full Changelog (Diff & Compare): v1.0.0...v1.1.0
v1.0.0 — Initial Production Release
UBSI API v1.0.0 — Initial Production Release
Rilis perdana resmi UBSI API (Unofficial REST API Aggregator untuk layanan kampus Universitas Bina Sarana Informatika).
✨ Fitur & Layanan Utama (6 Modul)
- StudentV2 (SIAKAD): Jadwal kuliah semester aktif, nilai murni lengkap, pengumuman internal PDF, dan arsip berita.
- MyBest LMS (Elearning): Kartu matkul, pemecah math captcha login otomatis, presensi hadir perkuliahan, tugas aktif & riwayat nilai/submission, berkas silabus/modul ZIP, dan kuis online.
- Elibrary (Perpustakaan): Pencarian katalog OPAC, detail metadata buku, dan ketersediaan stok fisik rak dengan 60s exponential retry.
- News Portal: Integrasi native WordPress REST API (
news.bsi.ac.id/wp-json/wp/v2/posts?_embed=1) untuk artikel berita kampus. - Repository: Publikasi penelitian dan tugas akhir mahasiswa di EPrints.
- EJournal: Katalog 16 jurnal ilmiah akademik resmi UBSI via jalur OAI bypass.
🛡️ Keamanan & Anti-Ban
- Localhost Security Boundary: Binds eksklusif ke
127.0.0.1:8300(nol port terbuka ke publik). - Two-Tier Redis Cache (DB 2): TTL berjenjang (Jadwal 2j, Nilai 30m, Tugas 10m) + Last-Known-Good offline fallback (
stale: true). - Single-Flight Mutex: Mencegah spamming paralel terhadap server kampus.
- Chrome TLS Impersonation: Menggunakan Scrapling & curl-cffi dengan fingerprint Chrome desktop asli.
- Rate Limiting: 60 req/menit via Redis sliding window counter.
📚 Dokumentasi & Legalitas
- Dokumentasi modular di folder
docs/(api.md,architecture.md,anti-ban.md,deploy.md). - Berkas legal lengkap:
SECURITY.md,DMCA.md,CONTRIBUTING.md, danLICENSE(MIT). - Author: Yuken Velino (@Curzyori) — NIM 15260767, Kelas 15.1C.30, Informatika, FTI UBSI Kampus Kota Pontianak.
🧪 Pengujian
- 46 unit & integration tests lulus 100% via Pytest.
- Live CLI Smoke Test lulus 7/7 checks.