feat: configure Gitea deployment and environment-managed WorldQuant credentials
Deploy production / deploy (push) Has been cancelled

This commit is contained in:
yuxuanhui
2026-09-09 09:58:09 +08:00
parent 20645d6d17
commit b8429efa3d
18 changed files with 430 additions and 45 deletions
+13 -3
View File
@@ -26,7 +26,7 @@ def cipher(settings) -> Fernet:
async def bootstrap(db, settings):
"""Only initialize missing singleton records; deployments never reset existing passwords."""
"""Initialize singletons and apply environment credentials without resetting the admin password."""
if not await db.get(Admin, 1):
db.add(
Admin(
@@ -35,8 +35,18 @@ async def bootstrap(db, settings):
password_hash=password_hasher.hash(settings.admin_password.get_secret_value()),
)
)
if not await db.get(Account, 1):
db.add(Account(id=1))
account = await db.get(Account, 1)
if account is None:
account = Account(id=1)
db.add(account)
if settings.wq_email:
# The environment must not bypass the single-account data ownership boundary.
if account.wq_user_id and (account.email or "").casefold() != settings.wq_email.casefold():
raise ValueError("WQ_EMAIL conflicts with the bound WorldQuant account")
account.email = settings.wq_email
account.password_encrypted = cipher(settings).encrypt(
settings.wq_password.get_secret_value().encode()
).decode()
await db.execute(delete(LoginSession).where(LoginSession.expires_at < now()))
await db.commit()