feat: streamline Story Arcs and harden import and torrent recovery - #142
Conversation
Share Comic Vine provider setup and result-cover rendering between series and story arcs, with persistent caching for arc discovery. Bring the reading-order preview onto the standard table, pagination, footer, and action contracts. Replace position inputs with shared reorder chevrons, preserve choices across pages and retries, and remove the review checkbox requirement. Keep Add Story Arc available with actionable submission feedback and duplicate-request protection. Include browser and route regressions for the updated workflows.
Share the series search result layout with story arc discovery and preserve template user context across provider transactions. Save reading-order chevron changes directly without a confirmation step, retain file safety and interrupted-operation recovery, and preserve the page, focus, and live controller state during updates. Remove placement preview and durable state cards from the normal detail page and avoid their unnecessary file inspection work.
Keep background placement processing and saved diagnostics unchanged while simplifying the detail page.
Add a previewed Follow-up action for files whose saved series and issue identities agree, while preserving skips, safety decisions, ownership, and genuine conflicts. Queue approved recovery through the existing background import workflow. Preserve successful partial import outcomes during exhausted retries and prevent unresolved legacy identity failures from entering futile retry loops. Bound and optimize mixed-folder recovery queries for large libraries. Document recovery behavior and add regression coverage for Mylar and folder imports, preview safety, API handoff, and large-library lookups.
Fetch and validate HTTP torrent descriptors inside Pullbox before uploading them to the selected torrent client. Preserve magnet handoffs and use the shared path for grabs, automatic acquisition, intervention approval, and retries. Resolve persisted Prowlarr source IDs through the aggregate without duplicating searches, and validate manual source availability independently of health tracking. Fail clearly without URL fallback when metadata cannot be retrieved. Reuse bounded bencode validation, enforce redirect policy, and add regression coverage including a simulated remote seedbox upload. No additional validation run for this commit as requested.
Renew only eight previously reviewed CVE/package pairs for the current DHI runtime versions with explicit maintainer risk acceptance. Preserve the High-severity gate, cached-image exceptions, and existing review deadlines. Add exact-scope regression coverage and document the remaining glibc and Expat uncertainty. Verified with failing regression checks before renewal, 72 focused security-contract tests, and the complete local CI pipeline including both browsers and Docker smoke tests.
Codex Review SummaryThis comment shows the latest Codex review activity on this pull request.
ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings. |
There was a problem hiding this comment.
💡 Codex Review
Here are some automated review suggestions for this pull request.
Reviewed commit: 095ec31b24
ℹ️ About Codex in GitHub
Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you
- Open a pull request for review
- Mark a draft as ready
- Comment "@codex review".
If Codex has suggestions, it will comment; otherwise it will react with 👍.
Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".
Keep conflicting Comic Vine issue identities in follow-up even when separate legacy series claim them. Normalize saved numeric and string IDs before counting, with Mylar and folder-import regression coverage. Include the Story Arc detail controller in the main shell asset fingerprint so script-only deployments invalidate cached clients. Verified intended regression failures, 130 focused tests, and make validate with 11,091 passing tests.
|
Codex Review: Didn't find any major issues. What shall we delve into next? Reviewed commit: ℹ️ About Codex in GitHubYour team has set up Codex to review pull requests in this repo. Reviews are triggered when you
If Codex has suggestions, it will comment; otherwise it will react with 👍. Codex can also answer questions or update the PR. Try commenting "@codex address that feedback". |
Summary
I'm preparing the next edge build with a more consistent Story Arc workflow and fixes for import recovery and remote torrent clients.
Changes
Validation
The full local CI results below cover the initial PR revision
095ec31.make ci-fullpassed in 13 minutes 35 seconds, including all seven Docker smoke tests.Review Follow-Up
story-arc-detail.jsin the shared shell cache fingerprint so deployments that change only that controller invalidate cached browser code.make validatewith 11,091 passed, 13 skipped, and one expected failure. Coverage includes both Mylar and folder-import recovery and script-only cache invalidation.f023c6fand their threads are resolved. The second and final review completed on that commit with no new findings. No further review passes will be requested for this PR; CI validation continues independently.f023c6f: CI (Python 3.12, 3.13, and 3.14; Chromium and Firefox; accessibility), Security (including CodeQL), Workflow Hygiene, and Production Docker Validate. The PR is ready for the merge decision; no merge or edge publication has been performed.Accepted Security Risk
I approved renewing only the eight existing CVE/package combinations reported after the DHI base refresh: one
libc6finding, threelibexpat1findings, and fourlibuuid1findings. These are exceptions, not vulnerability fixes. Their exact versions, advisory links, and unchanged review deadlines are recorded in.grype.yaml; all other High findings remain blocking. The existing deadlines are September 30 for glibc, October 4 for libuuid, and October 7 for Expat, or the next base refresh if earlier. Fixed stable packages should replace these exceptions as soon as available.The inspected ARM64 image does not contain the
mountornsenterexecutables involved in the libuuid source-package findings. That does not establish glibc or Expat safety: third-party reachability remains unproven, and the separately bundled Python Expat 2.8.2 parser is not proven safe against the newer Expat advisories by the existing minimum-version guard. Other architectures still require their normal image validation.Release Notes
develop. Application version remains1.3.0-dev; there are no new migrations in this PR.develop, run the four required validation workflows on the exact merged commit, then dispatch Docker Release fromdevelopto publish and verify the newedgeand immutable build tags in both registries. Do not updatelatestor create a stable-release tag.