-
Notifications
You must be signed in to change notification settings - Fork 1.9k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
feat: add issue attachment v1 endpoint #6307
Conversation
WalkthroughThe changes in the Changes
Sequence DiagramsequenceDiagram
participant Client
participant IssueAttachmentEndpoint
participant FileAsset
participant S3Storage
Client->>IssueAttachmentEndpoint: POST attachment
IssueAttachmentEndpoint->>IssueAttachmentEndpoint: Validate attachment
IssueAttachmentEndpoint->>FileAsset: Create FileAsset
FileAsset-->>IssueAttachmentEndpoint: Return asset details
IssueAttachmentEndpoint-->>S3Storage: Generate presigned URL
IssueAttachmentEndpoint-->>Client: Return upload details
Poem
Thank you for using CodeRabbit. We offer it for free to the OSS community and would appreciate your support in helping us grow. If you find it useful, would you consider giving us a shout-out on your favorite social media? 🪧 TipsChatThere are 3 ways to chat with CodeRabbit:
Note: Be mindful of the bot's finite context window. It's strongly recommended to break down tasks such as reading entire modules into smaller chunks. For a focused discussion, use review comments to chat about specific files and their changes, instead of using the PR comments. CodeRabbit Commands (Invoked using PR comments)
Other keywords and placeholders
CodeRabbit Configuration File (
|
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Actionable comments posted: 0
🧹 Nitpick comments (3)
apiserver/plane/api/views/issue.py (3)
948-1032
: Solid attachment creation logic with a few suggestions.
Size-Capping vs. Rejection
At line 961, the logic silently caps the file size usingmin(size, settings.FILE_SIZE_LIMIT)
, which might confuse users expecting an error if size exceeds the limit. Consider explicitly rejecting oversized files to align with typical behavior and user expectations.File name sanitization
At lines 949–950, we accept user-derivedname
andtype
. Although this is partially mitigated by random prefixing (line 973), you might want to ensure there's no path-traversal risk (e.g.,../
). A quick check or sanitization can help avoid any edge-case vulnerabilities.Long line warning
Static analysis flagged line 997 (> 88 chars). Consider wrapping or splitting it per the project’s style:- "error": "Issue with the same external id and external source already exists", + "error": ( + "Issue with the same external id " + "and external source already exists" + ),Overall
The rest of the logic—validating required fields, creating theFileAsset
, generating a presigned URL, and returning it—appears consistent and robust.🧰 Tools
🪛 Ruff (0.8.2)
997-997: Line too long (98 > 88)
(E501)
1035-1057
: Soft-delete approach is reasonable but can be improved.
Consolidating saves
The method callsissue_attachment.save()
at lines 1041 and again at 1057. Merging these into a single save call after setting all desired fields can reduce overhead and minimize the risk of stale data between saves.Soft-delete vs. S3 deletion
Settingis_deleted
toTrue
(lines 1039-1041) does not remove the object from storage. This may be intentional. If you eventually need to free S3 space, consider scheduling or providing a separate process to delete the file from S3.Optional check for
is_deleted
Because we rely on soft deletes, you might also want to exclude such attachments from future listings (e.g., inget
methods) to ensure consistent user experience.
1094-1122
: Patch method effectively finalizes uploads with a minor naming concern.
Event naming
At lines 1102–1113, you trigger"attachment.activity.created"
. Consider leveraging"attachment.activity.uploaded"
(or similar) to more accurately depict the event.Idempotent design
Checkingif not issue_attachment.is_uploaded:
ensures you only log the event once. This is a good approach to prevent duplicated notifications.Test coverage
If coverage is lacking, consider adding tests to ensure the patch operation consistently setsis_uploaded
and triggers the correct activity log.
📜 Review details
Configuration used: CodeRabbit UI
Review profile: CHILL
Plan: Pro
📒 Files selected for processing (1)
apiserver/plane/api/views/issue.py
(4 hunks)
🧰 Additional context used
🪛 Ruff (0.8.2)
apiserver/plane/api/views/issue.py
997-997: Line too long (98 > 88)
(E501)
🔇 Additional comments (2)
apiserver/plane/api/views/issue.py (2)
3-3
: All new or updated imports appear correct.These additions (e.g.,
uuid
,DjangoJSONEncoder
, and references tosettings
,Workspace
,S3Storage
,get_asset_object_metadata
) support the new attachment workflow. No immediate concerns.Also applies to: 6-7, 23-23, 54-54, 56-57
1060-1093
: Confirm visibility of soft-deleted attachments.
Filtering out
is_deleted
The listing at lines 1084–1090 does not exclude files marked as deleted (is_deleted=True
). If the intention is to hide soft-deleted records from users, addis_deleted=False
in the filter.Presigned URL redirect
Lines 1074–1080 properly redirect to a presigned URL. This approach is straightforward. Just verify that returning an HTTP redirect is acceptable for your client’s workflow and security model (e.g., handling sensitive attachments).
* WIP * WIP * WIP * WIP * Create home preference if not exist * chore: handled the unique state name validation (#6299) * fix: changed the response structure (#6301) * [WEB-1964]chore: cycles actions restructuring (#6298) * chore: cycles quick actions restructuring * chore: added additional actions to cycle list actions * chore: cycle quick action structure * chore: added additional actions to cycle list actions * chore: added end cycle hook * fix: updated end cycle export --------- Co-authored-by: gurusinath <[email protected]> * fix: active cycle graph tooltip and endpoint validation (#6306) * [WEB-2870]feat: language support (#6215) * fix: adding language support package * fix: language support implementation using mobx * fix: adding more languages for support * fix: profile settings translations * feat: added language support for sidebar and user settings * feat: added language support for deactivation modal * fix: added project sync after transfer issues (#6200) * code refactor and improvement (#6203) * chore: package code refactoring * chore: component restructuring and refactor * chore: comment create improvement * refactor: enhance workspace and project wrapper modularity (#6207) * [WEB-2678]feat: added functionality to add labels directly from dropdown (#6211) * enhancement:added functionality to add features directly from dropdown * fix: fixed import order * fix: fixed lint errors * chore: added common component for project activity (#6212) * chore: added common component for project activity * fix: added enum * fix: added enum for initiatives * - Do not clear temp files that are locked. (#6214) - Handle edge cases in sync workspace * fix: labels empty state for drop down (#6216) * refactor: remove cn helper function from the editor package (#6217) * * feat: added language support to issue create modal in sidebar * fix: project activity type * * fix: added missing translations * fix: modified translation for plurals * fix: fixed spanish translation * dev: language type error in space user profile types * fix: type fixes * chore: added alpha tag --------- Co-authored-by: sriram veeraghanta <[email protected]> Co-authored-by: Anmol Singh Bhatia <[email protected]> Co-authored-by: Prateek Shourya <[email protected]> Co-authored-by: Akshita Goyal <[email protected]> Co-authored-by: Satish Gandham <[email protected]> Co-authored-by: Aaryan Khandelwal <[email protected]> Co-authored-by: gurusinath <[email protected]> * feat: introduced stacked bar chart and tree map chart. (#6305) * feat: add issue attachment external endpoint (#6307) * [PE-97] chore: re-order pages options (#6303) * chore: re-order pages dropdown options * chore: re-order pages dropdown options * fix: remove localdb tracing * [WEB-2937] feat: home recent activies list endpoint (#6295) * Crud for wuick links * Validate quick link existence * Add custom method for destroy and retrieve * Add List method * Remove print statements * List all the workspace quick links * feat: endpoint to get recently active items * Resolve conflicts * Resolve conflicts * Add filter to only list required entities * Return required fields * Add filter * Add filter * fix: remove emoji edit for uneditable pages (#6304) * Removed duplicate imports * feat: patch api * Enable sort order to be updatable * Return key name only insert missing keys use serializer to return data * Remove random generation of sort_order * Remove name field Remove random generation of sort_order --------- Co-authored-by: Bavisetti Narayan <[email protected]> Co-authored-by: Vamsi Krishna <[email protected]> Co-authored-by: gurusinath <[email protected]> Co-authored-by: Anmol Singh Bhatia <[email protected]> Co-authored-by: sriram veeraghanta <[email protected]> Co-authored-by: Prateek Shourya <[email protected]> Co-authored-by: Akshita Goyal <[email protected]> Co-authored-by: Satish Gandham <[email protected]> Co-authored-by: Aaryan Khandelwal <[email protected]> Co-authored-by: Nikhil <[email protected]>
Description
Added the IssueAttachment endpoint to create and fetch attachments from v1 apis.
Type of Change
Summary by CodeRabbit
New Features
Bug Fixes
Improvements