Commit Graph

426 Commits

Author SHA1 Message Date
Julien Neuhart
23d59f3133 refactor: adopt strings.Cut and strings.SplitSeq
Applies what go fix now proposes, so make fmt is a no-op on a clean tree
instead of dirtying these two files on every run. Both rewrites are
equivalent: Cut's first result matches SplitN(s, sep, 2)[0], and SplitSeq
iterates the same substrings without building the intermediate slice.
2026-09-03 19:22:23 +02:00
Julien Neuhart
0e83f737b4 docs(supervisor): point maybeRestartAfterTask at the timeout constant 2026-09-03 17:52:52 +02:00
Julien Neuhart
57b048c611 fix(supervisor): reset the request counter on a failed relaunch
restart() reset reqCounter only after a successful Launch, so a failed
one left it at the limit. maybeRestartAfterTask then re-fired on every
subsequent task, producing back-to-back restarts and, with planned
restarts now reporting healthy, a node that keeps restarting while
claiming health.

Reset on the attempt instead. A process that will not start is recovered
by ensureHealthy, which restarts synchronously and reports the failure.
2026-09-03 17:52:01 +02:00
Julien Neuhart
d79e174c6f fix(supervisor): bound the eager restart with a deadline
maybeRestartAfterTask ran its restart on a bare background context while
the drain loop in doRestartLocked selects only on ctx.Done(). A task that
never completed blocked the drain forever, pinning isRestarting. Since a
planned restart now reports healthy, that left the node claiming health
for good. LibreOffice escaped it because its concurrency of 1 drains no
slots, but Chromium defaults to 6.

Give that restart its own deadline. On expiry it aborts and the next task
retries it.
2026-09-03 16:10:16 +02:00
Julien Neuhart
88ddaed09b fix(supervisor): report healthy during planned process restarts
The eager restart fired after --chromium-restart-after or
--libreoffice-restart-after conversions made Healthy() report false,
so a client probing /health between two conversions got a 503 from an
otherwise serving node. Tasks arriving during that window are requeued
by acquireSlot, not rejected.

Track whether the in-flight restart is planned and keep reporting
healthy for those. Unplanned restarts still report unhealthy so load
balancers get honest information.

Closes #1648
2026-09-03 16:04:20 +02:00
Julien Neuhart
8944db131c fix(api): bound downloadFrom concurrency and entry count 2026-09-02 14:57:29 +02:00
Muhammad Haseeb
7dbff18e65 fix(chromium): fail fast with 503 when Chromium crashes (#1641) 2026-08-31 16:48:21 +02:00
Julien Neuhart
923e5f71eb style(api): remove redundant parentheses in type switch 2026-08-31 13:38:05 +02:00
Julien Neuhart
c636a52666 fix(otel): keep telemetry off unless an exporter is configured 2026-08-31 13:27:05 +02:00
Julien Neuhart
c0f487e333 feat(api): add OIDC bearer token authentication 2026-08-14 17:04:20 +02:00
Julien Neuhart
3de6932279 feat(pdfengines): apply multiple stamps and watermarks on every route 2026-08-14 16:36:40 +02:00
Julien Neuhart
e9a67132ec feat(pdfengines): apply multiple stamps in one request (#1601) 2026-08-14 15:52:14 +02:00
Julien Neuhart
65e5699b71 feat(pdfengines): generate document-title bookmarks when merging (#867) 2026-08-14 12:36:13 +02:00
Julien Neuhart
f90684e165 fix(chromium): add missing import for awaited waitForExpression 2026-08-14 11:58:19 +02:00
Niklas
90e614afa4 feat(chromium): await thenable waitForExpression (#1617) 2026-08-14 11:57:29 +02:00
Ilya Fedorov
38db892552 fix(libreoffice): accept the OOXML PowerPoint show extensions (#1626) 2026-08-14 11:43:12 +02:00
Julien Neuhart
1303e0ebc9 refactor(pdfengines): remove qpdf embed fallback (#1628) 2026-08-14 11:07:16 +02:00
Julien Neuhart
cc1341c3cf chore(deps): update pdfcpu to v0.15.0 (#1628) 2026-08-13 20:39:11 +02:00
Julien Neuhart
1ac1d9887e feat(pdfengines): optimize PDF images to reduce file size (#359) 2026-08-13 19:39:09 +02:00
Julien Neuhart
7a730cfdc2 feat(chromium): add --chromium-clear-storage to clear local storage between conversions (#919) 2026-08-13 14:56:46 +02:00
Julien Neuhart
b213f2ffed fix(chromium): fit the page to content for landscape single-page (#1390) 2026-08-13 14:14:48 +02:00
Julien Neuhart
8d1eeaa73a feat(chromium): screenshot a single element via the selector form field (#947) 2026-08-13 13:56:17 +02:00
Julien Neuhart
2f6818d3df fix(chromium): hint at --chromium-start-timeout when Chromium fails to start 2026-08-13 12:47:45 +02:00
Julien Neuhart
38f6e466d4 chore(libreoffice): drop the now-unneeded gosec nolint 2026-08-13 12:32:55 +02:00
Julien Neuhart
9b48d3f84e chore(libreoffice): silence a gosec G703 false positive on temp-file cleanup 2026-08-13 12:28:46 +02:00
Julien Neuhart
05bde96334 refactor(qpdf): make embed-metadata logging context-aware 2026-08-13 08:21:35 +02:00
Julien Neuhart
8b2c15d5de fix(api): classify client-cancelled requests as 499 instead of 500 2026-08-13 08:21:35 +02:00
Julien Neuhart
8d327a5196 fix(libreoffice): render scrolled workbooks in full for SinglePageSheets 2026-08-13 08:21:35 +02:00
Julien Neuhart
dc7c68152c fix(chromium): filter WebSocket handshakes against the outbound policy 2026-08-13 08:21:35 +02:00
Julien Neuhart
357c3b4a59 fix(outbound): return 403 instead of 500 for an unresolvable outbound host 2026-08-13 08:21:35 +02:00
Julien Neuhart
91f2587fef Merge commit from fork
Co-authored-by: Jacob Brackett <jbrackett@makenotion.com>
2026-08-13 08:08:28 +02:00
Julien Neuhart
de7f335791 fix(outbound): keep dial pinning for hops the environment proxy declines 2026-08-07 16:37:03 +02:00
Julien Neuhart
815f586315 fix(chromium): bound the total scope matching time per conversion 2026-08-07 16:29:55 +02:00
Julien Neuhart
b71df026f6 fix(api): sanitize the output filename header 2026-08-07 16:22:42 +02:00
Julien Neuhart
8d29638b74 fix(pdfcpu): pass --force when writing over the input file 2026-08-07 15:49:53 +02:00
Julien Neuhart
31fa392db2 fix(libreoffice)!: return 500 when a failure is not the client's fault 2026-08-07 15:33:44 +02:00
Julien Neuhart
bb0b874d16 fix(telemetry): align resource semconv with otel sdk 1.45 detectors 2026-08-07 14:04:37 +02:00
Julien Neuhart
a92a7fedba feat(outbound): support authenticated proxy from environment variables 2026-07-15 20:08:29 +02:00
Julien Neuhart
d0e3991d16 fix(chromium): serialize browser starts to prevent pinning proxy latch after a start timeout 2026-07-15 19:04:38 +02:00
Julien Neuhart
7b054da4e7 fix(chromium): generateDocumentOutline now implies generateTaggedPdf 2026-06-16 17:06:10 +02:00
Julien Neuhart
98fc403478 feat(libreoffice): block linked content from untrusted locations 2026-06-11 15:02:32 +02:00
Julien Neuhart
808a96f3d0 chore: rename factur x engine 2026-06-07 15:27:23 +02:00
Julien Neuhart
d4c20c6b39 feat(telemetry): record backing-binary versions on spans, captured at build time 2026-06-07 14:52:06 +02:00
Julien Neuhart
c0ed2dee3c feat(qpdf): record Factur-X and PDF/A attributes on traces 2026-06-06 19:26:22 +02:00
Julien Neuhart
f8905bac8c refactor: make client- and operator-facing error messages clearer and actionable 2026-06-06 19:23:46 +02:00
Julien Neuhart
3b1e4cbac4 feat(pdfengines): support owner-only encryption and document permissions 2026-06-06 14:05:46 +02:00
Julien Neuhart
287ee5be72 feat(pdfengines): redesign Factur-X API with dedicated form fields 2026-06-06 14:03:58 +02:00
Julien Neuhart
9ab39b6fca fix(libreoffice): suppress auto-generated page header for CSV conversions 2026-06-05 17:50:01 +02:00
Julien Neuhart
5558e43821 feat(pdfengines): inject Factur-X/ZUGFeRD XMP metadata 2026-06-05 17:50:01 +02:00
Julien Neuhart
3ab8c5920b feat(log): add log-std-level-case to control standard output level casing 2026-06-04 20:44:04 +02:00