mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-04 22:35:08 +00:00
refactor(web): split api_v3/plugins.py by area (#658)
* refactor(web): split api_v3/plugins.py by area
web_interface/blueprints/api_v3/plugins.py (3,285 lines) becomes:
- plugins.py: installed list, enable/disable, plugin actions
- plugin_store.py: install, update, uninstall, store, saved repositories
- plugin_config.py: config get/save, schema, reset
- plugin_assets.py: asset uploads and plugin static files
- plugin_health.py: health, metrics, limits
- plugin_operations.py: operation history, state reconciliation
- plugin_calendar.py: calendar credentials and auth
Pure move: all 44 functions and 38 route decorators are byte-identical
(checked with ast), URLs and endpoint names are unchanged (url-map test).
Each module imports only what it uses. Tests and config.py that reached
into plugins.py for moved names now import from the new module.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(web): keep exception text out of calendar responses; annotate moved code
The split made scanners report existing findings in the moved code as new:
- CodeQL: the calendar auth and calendar-list routes returned exception
text (redacted, but still derived from the exception). Both now log the
exception and return a fixed message pointing at the log.
- MD5 in the asset upload only makes a filename unique: usedforsecurity=False.
- pickle reads/writes the calendar plugin's own OAuth token (as before):
annotated. Token-status labels and a log line naming the secrets path are
false positives: annotated with the repo's nosec/nosemgrep convention.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(web): name uploaded assets with SHA-256 instead of MD5
The hash only makes an uploaded image's filename unique. Codacy flags MD5
even with usedforsecurity=False, and SHA-256 does the job as well; existing
files keep their names.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
* fix(web): keep the redacted exception detail in calendar errors
Reverts the calendar part of 5e695b7c. The project's policy
(test_no_api_v3_handler_discards_its_exception) is that an API error
carries the redacted exception detail -- describe_exception runs it
through the credential redactor -- so a failure is diagnosable from the web
UI. Dropping it for CodeQL broke that; CodeQL can't see the redaction, so
its two alerts here are false positives, like the existing ones on main.
Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
---------
Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -25,7 +25,7 @@ PNG = b"\x89PNG\r\n\x1a\n" + b"0" * 20
|
||||
|
||||
@pytest.fixture
|
||||
def project(tmp_path, api_v3_module, monkeypatch):
|
||||
import web_interface.blueprints.api_v3.plugins as plugins_module
|
||||
import web_interface.blueprints.api_v3.plugin_assets as plugins_module
|
||||
monkeypatch.setattr(plugins_module, "PROJECT_ROOT", tmp_path)
|
||||
return tmp_path / "assets" / "plugins" / "static-image" / "uploads"
|
||||
|
||||
|
||||
@@ -281,7 +281,7 @@ class TestPluginAssetRoutes:
|
||||
|
||||
@pytest.fixture
|
||||
def project(self, tmp_path, api_v3_module, monkeypatch):
|
||||
import web_interface.blueprints.api_v3.plugins as plugins_module
|
||||
import web_interface.blueprints.api_v3.plugin_assets as plugins_module
|
||||
|
||||
monkeypatch.setattr(plugins_module, "PROJECT_ROOT", tmp_path)
|
||||
(tmp_path / "config").mkdir()
|
||||
|
||||
@@ -15,7 +15,7 @@ import logging
|
||||
|
||||
import pytest
|
||||
|
||||
from web_interface.blueprints.api_v3.plugins import (
|
||||
from web_interface.blueprints.api_v3.plugin_config import (
|
||||
_prepare_plugin_config_for_save,
|
||||
)
|
||||
|
||||
|
||||
Reference in New Issue
Block a user