fix: relax exact pins, keep image storage keys, drop pkg_resources (LP-913) - #36
Merged
Merged
Conversation
djoseph-apphelix
force-pushed
the
lp-913/multi-release-deps
branch
from
September 18, 2026 15:26
63a649c to
8e80a4e
Compare
…resources (LP-913) Three fixes to the block's packaging and handlers. - deps: setup.py pinned edx-toggles==5.4.1 and django-waffle==5.0.0. A current edx-platform ships edx-toggles 6.0.0, so `pip install edx-games` could not resolve there without downgrading a platform dependency. Both are now minimums with the pinned versions as the floor; the other floors are unchanged. Declares python_requires>=3.9. - handlers: save_settings rebuilt each card from a fixed list of fields, so the term_image_path and definition_image_path values the editor sends were dropped and after a reload the block no longer knew which stored file belonged to a card. The two keys are now part of CARD_FIELD and are persisted, defaulting to "" for content saved before this change. They come from the client and the storage bucket is shared platform-wide, so only keys of the form games/<this block's id>/<image file> are accepted; any other key is stored as "". delete_image_handler applies the same check, so it can no longer delete another block's file, and it no longer returns exception text to the client. upload_image now returns the key storage actually used, since storage may rename on collision, and the allowed image extensions live in UPLOAD.ALLOWED_EXTENSIONS. save_settings also validates its input before writing anything: game_type must be a known type, is_shuffled and has_timer must be booleans, and cards must be a list. Card text fields and display_name that arrive as null or a non-string are stored as "" (or the default name); a stored None made student_view raise for every learner. - resources: setuptools 81+ no longer ships pkg_resources and CI upgrades setuptools before installing the package, so `import games` has failed there since setuptools 84.0.0. The student views read their templates, CSS and JS through it. games.utils.read_resource now loads those files with importlib.resources (standard library since Python 3.9), cached per process. The unused GamesXBlock.resource_string helper is removed and tests that stubbed pkg_resources now stub read_resource. Bumps the version to 1.0.19.
djoseph-apphelix
force-pushed
the
lp-913/multi-release-deps
branch
from
September 21, 2026 07:42
8e80a4e to
1f25268
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What
Three independent fixes in one commit.
1. Dependencies — relax the exact pins on
django-waffleandedx-togglessetup.pyandrequirements/base.txtpinnededx-toggles==5.4.1anddjango-waffle==5.0.0. A current edx-platform shipsedx-toggles6.0.0, sopip install edx-gamescould not resolve there without downgrading a platform dependency. Both are now minimums (>=5.4.1,>=5.0.0), so the same release installs onrelease/ulmoand onmaster. TheXBlock,web-fragmentsandDjangofloors are unchanged, so the CI matrix (Django 3.2 and 4.2) still applies. Declarespython_requires>=3.9, whichimportlib.resources.filesneeds.2. Handlers — keep the image storage keys when saving cards
save_settingsrebuilt each card from a fixed list of fields, so theterm_image_pathanddefinition_image_pathvalues the editor sends were dropped. After a reload the block no longer knew which stored file belonged to a card. The two keys are now part ofCARD_FIELDand are persisted, defaulting to""for content saved before this change.get_settingsreturns cards as stored, so the keys now round-trip.The keys come from the client and the storage bucket is shared platform-wide, so
own_storage_keyaccepts only keys of the formgames/<this block's id>/<file>; any other key (another block's, a path traversal, a non-string) is stored as"".upload_imagenow returns the key storage actually used rather than the one requested, since storage may rename on collision.The handler request/response shapes are otherwise unchanged; clients that do not send the keys are unaffected.
3. Resources — read bundled static files with
importlib.resourcesinstead ofpkg_resourcesCI on
mainhas been red since 30 June: it upgrades setuptools before installing the package, setuptools 81+ no longer shipspkg_resources, andimport gamesfails withNo module named 'pkg_resources'. The student views read their templates, CSS and JS through it. A newgames.utils.read_resourceloads them withimportlib.resources(standard library since Python 3.9), cached per process. The unusedGamesXBlock.resource_stringhelper and its test are removed, and the tests that stubbedpkg_resourcesnow stubread_resource. The README requirements table is updated to match.Version
Bumps
setup.pyto 1.0.19.Testing
tests/test_image_paths.py(new): the keys round-trip; cards without them get""; keys for another block, traversals and non-strings are never persisted. The first fails against 1.0.18 and passes with this change.tests/handlers/test_common_handlers.py:upload_imagereports the key storage returned when it differs from the requested one.tests/test_utils.py::TestReadResource(new): every file the views load is readable, and a missing one raises.DJANGO_SETTINGS_MODULE=tests.settings python -m pytest), and the same 70 pass withpkg_resourcesmade unimportable, which is the CI condition.