3.13.83
fix(security): swagger static gate, honest banner, declare logger/base64 (3.13.83)
-
Security: the bundled Swagger UI static assets now honour the swagger gate.
/swagger, /swagger/, /swagger/index.html and /swagger/oauth2-redirect.html
were served from the framework's own public directory BEFORE route matching,
with directory-index resolution turning /swagger into swagger/index.html, so
a production server with TINA4_SWAGGER_ENABLED=false still served the whole
UI while /swagger/openapi.json correctly 404'd. Static serving now checks the
gate before it resolves an index. Bite-verified lock-in test. (python#97) -
The startup banner advertises only a surface that answers. The Swagger: and
Dashboard: rows printed unconditionally, so a production log claimed a dev
surface was exposed and a developer following the link hit a 404. Both rows
now come from one pure helper of (port, swagger_enabled, dev_admin_enabled),
unit tested rather than inferred from stdout. (python#99) -
MQTT TLS tests verify the CA before trusting it. A stale CA file in the
shared temp directory made six TLS tests FAIL instead of skip, in all four
frameworks, pointing at TLS code that was correct. The suites now confirm the
CA actually validates the broker certificate before treating the TLS
environment as present. (python#98) -
Maintainer skill: a tenth working reflex, background work must narrate itself
(and the "Eight habits" miscount is fixed). -
The gemspec declares logger (
> 1.6) and base64 (> 0.2). Ruby 4 dropped both
from the default gems. tina4ruby requires logger and nothing in its transitive
closure provided it, so a fresh install on Ruby 4 could fail at require time.
base64 is satisfied through jwt today and is declared directly so a change
there cannot break us. ostruct is deliberately NOT declared - nothing requires
it.
Suite: 4106 examples, 0 failures, 71 pending (macOS, Ruby 3.4, live PG/Redis/Mongo/MQTT).