Skip to content

fix: relax exact pins, keep image storage keys, drop pkg_resources (LP-913) - #36

Merged
djoseph-apphelix merged 1 commit into
mainfrom
lp-913/multi-release-deps
Sep 21, 2026
Merged

djoseph-apphelix merged 1 commit into
mainfrom
lp-913/multi-release-deps

Conversation

@djoseph-apphelix

@djoseph-apphelix djoseph-apphelix commented Sep 18, 2026 •

Copy link
Copy Markdown
Member

What

Three independent fixes in one commit.

1. Dependencies — relax the exact pins on django-waffle and edx-toggles

setup.py and requirements/base.txt pinned edx-toggles==5.4.1 and django-waffle==5.0.0. A current edx-platform ships edx-toggles 6.0.0, so pip install edx-games could not resolve there without downgrading a platform dependency. Both are now minimums (>=5.4.1, >=5.0.0), so the same release installs on release/ulmo and on master. The XBlock, web-fragments and Django floors are unchanged, so the CI matrix (Django 3.2 and 4.2) still applies. Declares python_requires>=3.9, which importlib.resources.files needs.

2. Handlers — keep the image storage keys when saving cards

save_settings rebuilt each card from a fixed list of fields, so the term_image_path and definition_image_path values the editor sends were dropped. After a reload the block no longer knew which stored file belonged to a card. The two keys are now part of CARD_FIELD and are persisted, defaulting to "" for content saved before this change. get_settings returns cards as stored, so the keys now round-trip.

The keys come from the client and the storage bucket is shared platform-wide, so own_storage_key accepts only keys of the form games/<this block's id>/<file>; any other key (another block's, a path traversal, a non-string) is stored as "". upload_image now returns the key storage actually used rather than the one requested, since storage may rename on collision.

The handler request/response shapes are otherwise unchanged; clients that do not send the keys are unaffected.

3. Resources — read bundled static files with importlib.resources instead of pkg_resources

CI on main has been red since 30 June: it upgrades setuptools before installing the package, setuptools 81+ no longer ships pkg_resources, and import games fails with No module named 'pkg_resources'. The student views read their templates, CSS and JS through it. A new games.utils.read_resource loads them with importlib.resources (standard library since Python 3.9), cached per process. The unused GamesXBlock.resource_string helper and its test are removed, and the tests that stubbed pkg_resources now stub read_resource. The README requirements table is updated to match.

Version

Bumps setup.py to 1.0.19.

Testing

  • tests/test_image_paths.py (new): the keys round-trip; cards without them get ""; keys for another block, traversals and non-strings are never persisted. The first fails against 1.0.18 and passes with this change.
  • tests/handlers/test_common_handlers.py: upload_image reports the key storage returned when it differs from the requested one.
  • tests/test_utils.py::TestReadResource (new): every file the views load is readable, and a missing one raises.
  • Full suite: 70 passed, coverage 94.94% (DJANGO_SETTINGS_MODULE=tests.settings python -m pytest), and the same 70 pass with pkg_resources made unimportable, which is the CI condition.
  • The editor's save payload was also run through the 1.0.18 handlers to confirm the unrelated frontend work does not depend on this PR.

@djoseph-apphelix djoseph-apphelix changed the title fix: relax exact dependency pins and keep image storage keys on save (LP-913) fix: relax exact pins, keep image storage keys, drop pkg_resources (LP-913) Sep 18, 2026
Comment thread setup.py
Comment thread games/handlers/common.py Outdated
Comment thread games/handlers/common.py
Comment thread games/handlers/common.py
Comment thread games/handlers/common.py
Comment thread games/games.py Outdated
Comment thread games/utils.py
Comment thread games/utils.py
Comment thread requirements/base.txt
Comment thread tests/handlers/test_flashcards_handlers.py Outdated
Comment thread tests/handlers/test_flashcards_handlers.py Outdated
Comment thread tests/handlers/test_matching_handlers.py Outdated
Comment thread tests/test_image_paths.py Outdated
Comment thread tests/test_image_paths.py Outdated
@djoseph-apphelix
djoseph-apphelix force-pushed the lp-913/multi-release-deps branch from 63a649c to 8e80a4e Compare September 18, 2026 15:26
Comment thread games/constants.py
Comment thread games/handlers/common.py Outdated
Comment thread games/handlers/common.py Outdated
Comment thread games/handlers/common.py Outdated
Comment thread games/handlers/common.py
Comment thread games/handlers/common.py
Comment thread games/handlers/common.py Outdated
Comment thread games/handlers/common.py Outdated
Comment thread tests/handlers/test_common_handlers.py Outdated
Comment thread tests/test_image_paths.py
…resources (LP-913)

Three fixes to the block's packaging and handlers.

- deps: setup.py pinned edx-toggles==5.4.1 and django-waffle==5.0.0. A
  current edx-platform ships edx-toggles 6.0.0, so `pip install edx-games`
  could not resolve there without downgrading a platform dependency. Both
  are now minimums with the pinned versions as the floor; the other floors
  are unchanged. Declares python_requires>=3.9.

- handlers: save_settings rebuilt each card from a fixed list of fields, so
  the term_image_path and definition_image_path values the editor sends
  were dropped and after a reload the block no longer knew which stored
  file belonged to a card. The two keys are now part of CARD_FIELD and are
  persisted, defaulting to "" for content saved before this change. They
  come from the client and the storage bucket is shared platform-wide, so
  only keys of the form games/<this block's id>/<image file> are accepted;
  any other key is stored as "". delete_image_handler applies the same
  check, so it can no longer delete another block's file, and it no longer
  returns exception text to the client. upload_image now returns the key
  storage actually used, since storage may rename on collision, and the
  allowed image extensions live in UPLOAD.ALLOWED_EXTENSIONS.

  save_settings also validates its input before writing anything: game_type
  must be a known type, is_shuffled and has_timer must be booleans, and
  cards must be a list. Card text fields and display_name that arrive as
  null or a non-string are stored as "" (or the default name); a stored
  None made student_view raise for every learner.

- resources: setuptools 81+ no longer ships pkg_resources and CI upgrades
  setuptools before installing the package, so `import games` has failed
  there since setuptools 84.0.0. The student views read their templates,
  CSS and JS through it. games.utils.read_resource now loads those files
  with importlib.resources (standard library since Python 3.9), cached per
  process. The unused GamesXBlock.resource_string helper is removed and
  tests that stubbed pkg_resources now stub read_resource.

Bumps the version to 1.0.19.
@djoseph-apphelix
djoseph-apphelix force-pushed the lp-913/multi-release-deps branch from 8e80a4e to 1f25268 Compare September 21, 2026 07:42

@abhalsod-sonata abhalsod-sonata left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

PR Approved,

@djoseph-apphelix
djoseph-apphelix merged commit 19af52e into main Sep 21, 2026
4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants