Skip to content

feat(submissions): submission processing, DOCX feedback and upload rules - #123

Open
Clupai8o0 wants to merge 2 commits into
thoth-tech:11.0.xfrom
ontrack-features-t2-2026:upstream-pr/submissions
Open

Clupai8o0 wants to merge 2 commits into
thoth-tech:11.0.xfrom
ontrack-features-t2-2026:upstream-pr/submissions

Conversation

@Clupai8o0

@Clupai8o0 Clupai8o0 commented Sep 27, 2026 •

Copy link
Copy Markdown

What this is

Makes submission processing visible and recoverable, lets feedback comments carry Word documents, and tightens upload rules. A task records whether its submission is queued, processing, ready or failed, and a failed or timed out conversion can be retried. Spreadsheets are now an accepted upload type. Most of the processing logic lives in task.rb, which ships in the notifications PR.

What is in it

  • portfolio_evidence_api.rb adds a retry endpoint for a failed or timed out conversion, and accept_submission_job.rb records the processing state.
  • file_helper.rb checks that a DOCX is a real Word package and keeps download names safe. comment_attachment_policy.rb and spreadsheet_upload_policy.rb decide which chat attachments and spreadsheets are accepted.
  • portfolio_api.rb enforces the configured file size limit and only accepts document, code or image parts.
  • project.rb returns each task's effective deadline and whether it has feedback when a project loads, and tells a student when they are moved to another tutorial.
  • test_attempt.rb stops a student's own browser data from setting their pass or score.
  • Four migrations: attachment metadata on task_comments, processing state and options on tasks, and a per-task resubmission extension setting on task_definitions.
  • Docs on submission history access, the effective resubmission deadline, the safe upload contract and the FILE-S01 upload threat model.
  • Tests for upload security, submission history access, processing state, DOCX attachments, spreadsheets and AcceptSubmissionJob.
  • Update, 28 Sep 2026: one more commit. Brings feat(notifications): land notification links, Unit Hub alerts and the digest email ontrack-features-t2-2026/doubtfire-api#178. It carries the project change for how often the summary email arrives.

How this set of PRs works

This is one of 24 PRs from the Thoth Tech T2 2026 Features team (9 api, 14 web, 1 deploy), one per feature per repo. Each one carries that feature's files, taken from our team org's 11.0.x branch, and applied straight onto thoth-tech 11.0.x. Every file is in exactly one PR. Some files are shared between features, so a PR on its own may not build. The demo PR in each repo (api #127, web doubtfire-lms#544) is imported by earlier PRs too, so it has to go in with the rest, not be dropped. Merged in the order below, the set equals our org 11.0.x minus team docs, evidence files, org-only CI and dev setup files. No app code or tests are left out.

On 28 Sep 2026 the set was brought up to our org's latest merges (api ontrack-features-t2-2026#178, web ontrack-features-t2-2026/doubtfire-web#281 and ontrack-features-t2-2026/doubtfire-web#282, deploy ontrack-features-t2-2026/doubtfire-deploy#41). Most PRs got one more commit for that. Two web PRs are new, panels (thoth-tech/doubtfire-web#546) and celebrate (thoth-tech/doubtfire-web#547), for files that were in no PR before.

Merge order, api first, then web, then deploy. In web, panels goes before the pages that use it, and celebrate goes after a11y, whose confetti service it needs.

Built against

  • api: thoth-tech 11.0.x @ dc76a5a0e, taken from org 11.0.x @ a9589b302
  • web: thoth-tech 11.0.x @ 20d1f380c, taken from org 11.0.x @ 0b8a20344
  • deploy: thoth-tech 11.0.x @ 58905969e, taken from org 11.0.x @ 8e560f7e0

Testing

Checked on 28 Sep 2026 with all the branches merged together. This PR was not tested on its own, see above.

  • web: with all 14 web branches merged onto thoth-tech 11.0.x, npm run test:ci runs 2603 tests in 290 files, all passing, and npm run lint and ng build pass. The merged set's app code is the same as our org 11.0.x after fix(profile): save a changed summary email cadence ontrack-features-t2-2026/doubtfire-web#282, where CI passed test, lint (22) and build (22).
  • api: the full Minitest suite passes on the nine api PRs merged onto thoth-tech 11.0.x. 1799 tests, 20182 assertions, 0 failures, 0 errors, 0 skips. It ran through our CI on branch check/upstream-combined-28sep (run), and the database schema check and RuboCop pass there too. The set differs from our org 11.0.x only by the left-out docs, evidence, CI and dev setup files, none of them app code.
  • deploy: production/tests/validate_test.sh, verify_pwa_test.py, publish_release_test.py and nginx_upload_test.py pass. The production compose file loads with docker compose config against .env.production.example, and the development and .devcontainer ones load as they are.

Contributors

Samridh Limbu, Maple Fox, Thirus224849242, Tan Tai, jmirchh75, anaghwadhwa123

This was referenced Sep 27, 2026
Brings the T2 2026 submissions work from ontrack-features-t2-2026 11.0.x (reviewed and merged work) onto thoth-tech 11.0.x.

Co-authored-by: maplefoxgit <s223932052@deakin.edu.au>
Co-authored-by: Thirus224849242 <s224849242@deakin.edu.au>
Co-authored-by: Tan Tai <s224621011@deakin.edu.au>
Co-authored-by: jmirchh75 <jmirch@live.com>
Co-authored-by: anaghwadhwa123 <s224458621@deakin.edu.au>
Brings #178 to the files this PR
already carries, so every file stays in exactly one PR. It carries the
project change for how often the summary email arrives.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants