Repository navigation
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. 📢 Thoughts on this report? Let us know! |
Bundle ReportBundle size has no change ✅ |
The DSM login spec expects synology in APP_AUTH_METHODS and signs the assertion with E2E_SYNOLOGY_SECRET. The in-process Playwright server sets both. The compose overlay used by the database matrix did not, so the admin checkbox stayed off and all three jobs failed.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Replace the Synology container wrapper with a native DSM 7.2+ x86_64 package containing the eXeLearning standalone server and its required runtime assets. Users install the SPK in Package Center and open eXeLearning from DSM using their existing DSM session, without entering their password again.
Native runtime and persistence
127.0.0.1:8085. DSM nginx exposes/exelearning/, including WebSockets and project uploads.SYNOPKG_PKGVAR, independently of the immutable application files.DSM authentication
The isolated package bridge obtains the current session's DSM CSRF token and supplies it only to the package CGI. Synology's server-side
authenticate.cgivalidates the session and determines the username; browser-supplied identities are never trusted.Short-lived signed assertions are state-bound and replay-checked, then exchanged through the existing eXeLearning authentication/session infrastructure. Users map to stable
synology:<username>identities, receiveROLE_USER, and are marked as externally authenticated. Local password management is unavailable for these accounts; administrator promotion is an explicit local operation.Packaging and releases
make package-synology VERSION=<version> PACKAGE_REVISION=<revision>builds an architecture-specific SPK and SHA-256 checksum. The package validates its archive, runtime assets and service files, preserves the upstream SemVer, and normalizes DSM metadata versions separately.The release workflow builds from the checked-out release tag and attaches stable, beta or RC packages to that same GitHub release. Manual runs require an existing version tag and publish workflow artifacts only. The workflow does not look up the latest upstream release.
Demo
Real DS918+ running DSM 7.2.2: manual SPK update, opening eXeLearning with the DSM session, importing an ELP file and previewing its contents. 39 seconds, 720p, approximately 560 KB, no audio. Edited capture with waits shortened; this demonstrates an upgrade of an existing installation, not a fresh install.
synology-native-demo.mp4
Validation
make fix, ShellCheck, archive/checksum validation, architecture checksThe complete E2E suites ran during implementation; the final handshake changes were additionally checked with the focused browser suites and on the NAS. No tests were disabled for this change. Compilation/lifecycle wrappers are exercised through package and device checks; the coverage figure above is the focused LCOV scope, not a claim about every shell or browser-script line.
Verified on physical hardware: DS918+, Celeron J3455 (SSE4.2, no AVX2), DSM 7.2.2-72806 Update 9. Native installation/upgrades, unprivileged service, loopback binding, nginx registration, service recovery, persistent data/configuration, real DSM-session SSO, project save/reopen, ELP import, ELPX download, preview and same-account two-tab WebSocket synchronization passed. The extracted native package also passed executable/SQLite/template/static-asset smoke checks as the package account.
Remaining verification: collaboration between independent DSM users, large uploads, administrator bootstrap, application logout without DSM logout, uninstall/reinstall retention, other NAS models and actual release/prerelease artifact attachment. ARM support is not advertised. Immediately after the recorded upgrade, the first browser request reached DSM's temporary 404 page; reloading succeeded while nginx registered the route. Fresh SQLite initialization on this NAS can take several minutes during Btrfs fsync; durability settings were not weakened.
Local test artifact:
exelearning-4.0.5-9-x86_64.spk(86,480,384 bytes). This was built from the development working tree, not a published upstream release.Documentation