Compare commits

..
Author SHA1 Message Date
MickLesk 12d81fa9d6 Radicale: enable the extras only once the code defines them
argon2 is an extra since v3.5.4 and uv refuses unknown extras, so patching
before the release update broke older installs. Patch after it instead,
and only when pyproject.toml defines the extra.
2026-10-09 20:44:46 +02:00
MickLesk d34989be9f Radicale: install the bcrypt and argon2 extras
The update replaces pyproject.toml and the venv, so a bcrypt or argon2
module added by hand was gone afterwards and Radicale refused to start
with htpasswd_encryption = bcrypt, argon2 or autodetect. The service now
runs uv with --extra bcrypt --extra argon2, which upstream already
defines. The update patches existing units and restarts the service.
2026-10-09 20:40:41 +02:00
6 changed files with 31 additions and 66 deletions
-14
View File
@@ -569,24 +569,10 @@ Exercise vigilance regarding copycat or coat-tailing sites that seek to exploit
### 🚀 Updated Scripts ### 🚀 Updated Scripts
- #### 🐞 Bug Fixes
- OpenCloud: fix Collabora embedding with Collabora 26.04.4 [@SimKaiLong](https://github.com/SimKaiLong) ([#17810](https://github.com/community-scripts/ProxmoxVE/pull/17810))
- #### 🔧 Refactor - #### 🔧 Refactor
- Immich: survive an interrupted update and a failing ML build [@MickLesk](https://github.com/MickLesk) ([#17798](https://github.com/community-scripts/ProxmoxVE/pull/17798)) - Immich: survive an interrupted update and a failing ML build [@MickLesk](https://github.com/MickLesk) ([#17798](https://github.com/community-scripts/ProxmoxVE/pull/17798))
### 💾 Core
- check_for_release: compare against the release marked as latest [@MickLesk](https://github.com/MickLesk) ([core#125](https://github.com/community-scripts/core/pull/125))
### 🧰 Tools
- #### ✨ New Features
- FileBrowser Quantum: migrate the config and database to v2 [@MickLesk](https://github.com/MickLesk) ([#17815](https://github.com/community-scripts/ProxmoxVE/pull/17815))
## 2026-10-08 ## 2026-10-08
### 🆕 New Scripts ### 🆕 New Scripts
-9
View File
@@ -31,15 +31,6 @@ function update_script() {
exit exit
fi fi
# Collabora 26.04.4 ignores frame-ancestors in content_security_policy; outside the release
# check so installs already on the current release get it too
if [[ -f /etc/coolwsd/coolwsd.xml ]] && ! grep -q '<frame_ancestors[^>]*>[^<[:space:]]' /etc/coolwsd/coolwsd.xml; then
msg_info "Allowing OpenCloud to embed Collabora"
$STD sudo -u cool coolconfig set net.frame_ancestors "$(sed -n 's/^OC_URL=//p' /etc/opencloud/opencloud.env)"
systemctl restart coolwsd
msg_ok "Allowed OpenCloud to embed Collabora"
fi
RELEASE="v8.1.0" RELEASE="v8.1.0"
if check_for_gh_release "OpenCloud" "opencloud-eu/opencloud" "${RELEASE}" "each release is tested individually before the version is updated. Please do not open issues for this"; then if check_for_gh_release "OpenCloud" "opencloud-eu/opencloud" "${RELEASE}" "each release is tested individually before the version is updated. Please do not open issues for this"; then
OLD_VERSION="$(cat ~/.opencloud 2>/dev/null)" OLD_VERSION="$(cat ~/.opencloud 2>/dev/null)"
+9 -1
View File
@@ -41,7 +41,7 @@ function update_script() {
if grep -q 'start.sh' /etc/systemd/system/radicale.service; then if grep -q 'start.sh' /etc/systemd/system/radicale.service; then
sed -i -e '/^Description/i[Unit]' \ sed -i -e '/^Description/i[Unit]' \
-e '\|^ExecStart|iWorkingDirectory=/opt/radicale' \ -e '\|^ExecStart|iWorkingDirectory=/opt/radicale' \
-e 's|^ExecStart=.*|ExecStart=/usr/local/bin/uv run -m radicale --config /etc/radicale/config|' /etc/systemd/system/radicale.service -e 's|^ExecStart=.*|ExecStart=/usr/local/bin/uv run --extra bcrypt --extra argon2 -m radicale --config /etc/radicale/config|' /etc/systemd/system/radicale.service
systemctl daemon-reload systemctl daemon-reload
fi fi
if [[ ! -f /etc/radicale/config ]]; then if [[ ! -f /etc/radicale/config ]]; then
@@ -70,6 +70,14 @@ EOF
msg_ok "Started service" msg_ok "Started service"
msg_ok "Updated Successfully!" msg_ok "Updated Successfully!"
fi fi
if grep -q 'uv run -m radicale' /etc/systemd/system/radicale.service && grep -q '^argon2 *=' /opt/radicale/pyproject.toml; then
msg_info "Enabling bcrypt/argon2 support"
sed -i 's|uv run -m radicale|uv run --extra bcrypt --extra argon2 -m radicale|' /etc/systemd/system/radicale.service
systemctl daemon-reload
systemctl restart radicale
msg_ok "Enabled bcrypt/argon2 support"
fi
exit exit
} }
+1 -1
View File
@@ -207,7 +207,7 @@ EOF
$STD sudo -u cool coolconfig set ssl.enable false $STD sudo -u cool coolconfig set ssl.enable false
$STD sudo -u cool coolconfig set ssl.termination true $STD sudo -u cool coolconfig set ssl.termination true
$STD sudo -u cool coolconfig set ssl.ssl_verification true $STD sudo -u cool coolconfig set ssl.ssl_verification true
$STD sudo -u cool coolconfig set net.frame_ancestors "https://${OPENCLOUD_FQDN}" sed -i "s|-Policy\">|&frame-ancestors https://${OPENCLOUD_FQDN}|" /etc/coolwsd/coolwsd.xml
useradd -r -M -s /usr/sbin/nologin opencloud useradd -r -M -s /usr/sbin/nologin opencloud
chown -R opencloud:opencloud "$CONFIG_DIR" "$DATA_DIR" chown -R opencloud:opencloud "$CONFIG_DIR" "$DATA_DIR"
sudo -u opencloud opencloud init --config-path "$CONFIG_DIR" --insecure no sudo -u opencloud opencloud init --config-path "$CONFIG_DIR" --insecure no
+1 -1
View File
@@ -58,7 +58,7 @@ Requires=network.target
[Service] [Service]
WorkingDirectory=/opt/radicale WorkingDirectory=/opt/radicale
ExecStart=/usr/local/bin/uv run -m radicale --config /etc/radicale/config ExecStart=/usr/local/bin/uv run --extra bcrypt --extra argon2 -m radicale --config /etc/radicale/config
Restart=on-failure Restart=on-failure
# User=radicale # User=radicale
# Deny other users access to the calendar data # Deny other users access to the calendar data
+20 -40
View File
@@ -96,27 +96,6 @@ if [[ -f "$LEGACY_DB" || -f "$LEGACY_BIN" && ! -f "$CONFIG_PATH" ]]; then
fi fi
fi fi
# v2 rejects v1 config keys and imports the BoltDB on its first start
migrate_v1_config() {
local dir="/usr/local/community-scripts" db=0
[[ -s "$dir/database.db" && ! -s "$dir/filebrowser.sqlite" ]] && db=1
((db)) || grep -qE 'conditionals:|indexingIntervalMinutes:' "$CONFIG_PATH" || return 0
cp "$CONFIG_PATH" "${CONFIG_PATH}.v1.bak"
((db)) && mv "$dir/database.db" "$dir/database.db.old"
awk -v db="$db" '
{ match($0, /^ */); ind = RLENGTH }
/^[^ #]/ { top = $1 }
cond && ind > ci { print substr($0, 3); next }
{ cond = 0 }
/^[[:space:]]*conditionals:[[:space:]]*$/ { cond = 1; ci = ind; next }
/^[[:space:]]*indexingIntervalMinutes:/ { next }
top == "server:" && /^ port:/ { port = $2; next }
{ print }
/^server:/ && db { print " database:"; print " migrateFrom: \"database.db.old\"" }
END { if (port != "") { print "http:"; print " port: " port } }
' "${CONFIG_PATH}.v1.bak" >"$CONFIG_PATH"
}
# Existing installation # Existing installation
if [[ -f "$INSTALL_PATH" ]]; then if [[ -f "$INSTALL_PATH" ]]; then
msg_warn "${APP} is already installed." msg_warn "${APP} is already installed."
@@ -147,7 +126,6 @@ if [[ -f "$INSTALL_PATH" ]]; then
mv -f /usr/local/bin/filebrowser-quantum "$INSTALL_PATH" mv -f /usr/local/bin/filebrowser-quantum "$INSTALL_PATH"
if [[ -f "$CONFIG_PATH" ]]; then if [[ -f "$CONFIG_PATH" ]]; then
sed -i '/^\s*disableIndexing:/d' "$CONFIG_PATH" sed -i '/^\s*disableIndexing:/d' "$CONFIG_PATH"
migrate_v1_config
fi fi
if [[ "$OS" == "Debian" ]]; then if [[ "$OS" == "Debian" ]]; then
systemctl restart filebrowser.service systemctl restart filebrowser.service
@@ -195,21 +173,22 @@ read -r noauth_prompt
# === YAML CONFIG GENERATION === # === YAML CONFIG GENERATION ===
if [[ "${noauth_prompt,,}" =~ ^(y|yes)$ ]]; then if [[ "${noauth_prompt,,}" =~ ^(y|yes)$ ]]; then
cat <<EOF >"$CONFIG_PATH" cat <<EOF >"$CONFIG_PATH"
http:
port: $PORT
server: server:
port: $PORT
sources: sources:
- path: "$SRC_DIR" - path: "$SRC_DIR"
name: "RootFS" name: "RootFS"
config: config:
denyByDefault: false denyByDefault: false
rules: indexingIntervalMinutes: 240
- neverWatchPath: "/proc" conditionals:
- neverWatchPath: "/sys" rules:
- neverWatchPath: "/dev" - neverWatchPath: "/proc"
- neverWatchPath: "/run" - neverWatchPath: "/sys"
- neverWatchPath: "/tmp" - neverWatchPath: "/dev"
- neverWatchPath: "/lost+found" - neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
auth: auth:
methods: methods:
noauth: true noauth: true
@@ -217,21 +196,22 @@ EOF
msg_ok "Configured with no authentication" msg_ok "Configured with no authentication"
else else
cat <<EOF >"$CONFIG_PATH" cat <<EOF >"$CONFIG_PATH"
http:
port: $PORT
server: server:
port: $PORT
sources: sources:
- path: "$SRC_DIR" - path: "$SRC_DIR"
name: "RootFS" name: "RootFS"
config: config:
denyByDefault: false denyByDefault: false
rules: indexingIntervalMinutes: 240
- neverWatchPath: "/proc" conditionals:
- neverWatchPath: "/sys" rules:
- neverWatchPath: "/dev" - neverWatchPath: "/proc"
- neverWatchPath: "/run" - neverWatchPath: "/sys"
- neverWatchPath: "/tmp" - neverWatchPath: "/dev"
- neverWatchPath: "/lost+found" - neverWatchPath: "/run"
- neverWatchPath: "/tmp"
- neverWatchPath: "/lost+found"
auth: auth:
adminUsername: admin adminUsername: admin
adminPassword: community-scripts.org adminPassword: community-scripts.org