You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Delete unused configuration files with named confirmation - #296
Add a red minus action beside unused configuration files. Confirmation names the file and explains that deletion is permanent; the action uses a CSRF-protected POST.
Before deleting, validate the basename, extension, canonical path, regular-file status and symlink status. Protect configurations referenced by registered maps and stop when the database usage query fails. Report success only after unlink succeeds. Escape filename-bearing status messages for HTML and use the existing Cacti-compatible attribute helper for buttons and confirmation text.
Validation: 229 PHP 8.3 tests passed in an isolated fixture layout. Temporary-file tests cover successful deletion, in-use files, database false/null failures, invalid paths, symlinks and filesystem failures. An action-level regression verifies escaping in both successful and in-use messages; nonce/CSRF checks also pass. Tests only delete their own temporary files. Focused PHPStan level 8 passed for the deletion helper. Syntax, whitespace and manifest checks passed; measured changed-line coverage is 100%, with the existing management-entry exemption. Full running-installation permission integration remains unverified for this revision.
Latest review follow-up
Registration and deletion now take the same exclusive nonblocking config-file lock and fail safely when the file is busy or unavailable. The lock spans the usage check/unlink and registration insertion, verifies the opened inode still matches the path and releases in finally blocks. Regression checks invoke the actual registration function during deletion and attempt deletion during registration, plus missing-file and exception paths. Latest local validation: 230 PHP tests (5466 assertions), measured changed-line coverage 40/40 and PHPStan level 8 on the helper with installation symbols supplied. The translation template includes the retry message.
These follow-up checks use isolated local fixtures, not a running Cacti installation. PHP 8.3 syntax, whitespace, manifest and translation-template checks passed. GitHub CI must still confirm the revised commits.
Resolved the new changelog conflict after #292 merged. All 239 local tests pass (5549 assertions), with syntax, manifest and whitespace checks passing. The feature changes remain intact; validation uses isolated fixtures.
Suppress unlink warning to preserve redirect and avoid path disclosure
lib/editor.config-delete.php:128
When unlink() fails (for example because the directory is read-only or the file disappears concurrently), it emits an E_WARNING before this function returns failed. With error display enabled that output can expose the server path and prevent the subsequent Location header from being sent; the new failure test has to install an error handler specifically to hide it. Suppress this expected filesystem warning and rely on the return value for the user-facing failure message.
Addressed the latest review-summary finding about unlink warnings. Expected unlink failure is suppressed and still returns failed for the existing user-facing message. The read-only-directory regression now throws on any unsuppressed warning and asserts empty output, while verifying the file remains intact. All 249 local tests pass (5560 assertions); manifest and whitespace checks pass. These remain isolated fixture checks, not native Windows/live-installation verification.
Resolved the CHANGELOG.md conflict after #293 merged, preserving both entries. The feature code merged cleanly; all 250 local tests pass, plus manifest and whitespace checks. Validation uses isolated fixtures.
Updated again after #294 merged during the previous push. Resolved the changelog/translation metadata conflicts; code merged cleanly. All 276 local tests pass on this combined revision. Manifest and whitespace checks pass; validation uses isolated fixtures.
Resolved the latest CHANGELOG.md conflict after #295 merged, preserving both entries. Code merged cleanly. All 282 local tests pass (5684 assertions), including deletion/path/locking and new-map preset regressions; manifest and whitespace checks pass. Validation uses isolated fixtures.
Resolved the CHANGELOG.md conflict after #297 merged, preserving both entries in numerical order. The code merged cleanly. All 284 local tests pass (5689 assertions) on the combined revision; PHP syntax, manifest and whitespace checks pass. Validation uses isolated fixtures.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Add a red minus action beside unused configuration files. Confirmation names the file and explains that deletion is permanent; the action uses a CSRF-protected POST.
Before deleting, validate the basename, extension, canonical path, regular-file status and symlink status. Protect configurations referenced by registered maps and stop when the database usage query fails. Report success only after unlink succeeds. Escape filename-bearing status messages for HTML and use the existing Cacti-compatible attribute helper for buttons and confirmation text.
Validation: 229 PHP 8.3 tests passed in an isolated fixture layout. Temporary-file tests cover successful deletion, in-use files, database false/null failures, invalid paths, symlinks and filesystem failures. An action-level regression verifies escaping in both successful and in-use messages; nonce/CSRF checks also pass. Tests only delete their own temporary files. Focused PHPStan level 8 passed for the deletion helper. Syntax, whitespace and manifest checks passed; measured changed-line coverage is 100%, with the existing management-entry exemption. Full running-installation permission integration remains unverified for this revision.
Latest review follow-up
Registration and deletion now take the same exclusive nonblocking config-file lock and fail safely when the file is busy or unavailable. The lock spans the usage check/unlink and registration insertion, verifies the opened inode still matches the path and releases in finally blocks. Regression checks invoke the actual registration function during deletion and attempt deletion during registration, plus missing-file and exception paths. Latest local validation: 230 PHP tests (5466 assertions), measured changed-line coverage 40/40 and PHPStan level 8 on the helper with installation symbols supplied. The translation template includes the retry message.
These follow-up checks use isolated local fixtures, not a running Cacti installation. PHP 8.3 syntax, whitespace, manifest and translation-template checks passed. GitHub CI must still confirm the revised commits.