mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-04 06:15:09 +00:00
fix(web): plugin dir resolver in routes, nmcli AP detection, daemon config reload, upload safety, BDF preview (#655)
* fix(web): plugin dir resolver in routes, nmcli AP detection, daemon config reload, upload safety - Route plugin lookups (installed list, update, recorded version, config form, web UI pages) through the plugin manager's resolver so plugins in ledmatrix-<id> directories work. - Captive-portal detection also sees the nmcli fallback AP (cached). - WiFi monitor daemon re-reads wifi_config.json when its mtime changes. - Drop the AP check in disconnect_from_network that could never fire. - LED status file per WiFiManager; config path falls back to this checkout. - BDF font preview via src.common.bdf_font. - Asset uploads validate every file before saving; metadata and calendar credentials written atomically; no absolute path in the response; asset delete answers 400 for a missing body. - Coerce string booleans in plugin toggle, on-demand start and AP force. - SSE broadcaster clears its thread handle before exiting. - start.py log filter handles every exc_info form. - Cleanups: unused plugins/fonts partial work, duplicate backup catch-alls, raw-config error helper, update-route tidy, redundant imports. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): request BDF font previews now that the server renders them The Fonts tab skipped the preview request for .bdf files because the server used to refuse them; /fonts/preview now draws BDF with the shared loader. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): take the update route's plugin directory from a directory listing CodeQL flagged the path built from the request's plugin_id (the id was already validated with safe_path_component, which CodeQL doesn't model; the same flow on main is alerts 738/739). The directory is now the entry of plugins_dir matched by name, so nothing built from user input reaches the filesystem; an id with nothing installed goes to the store manager, which reports it not found as before. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> * fix(web): read the blueprint's plugin_manager defensively in _plugin_directory _get_plugin_version now goes through _plugin_directory, which read api_v3.plugin_manager directly; the attribute exists only once the app sets it, so test_path_traversal_guards::test_a_real_manifest_is_read failed when run on its own (order-dependent in the full suite). Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> --------- Co-authored-by: Claude Opus 5.5 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,76 @@
|
||||
"""Boolean request fields are coerced, not used raw.
|
||||
|
||||
``bool("false")`` is True. /plugins/toggle stored a JSON ``"enabled": "false"``
|
||||
as-is in config.json (a truthy string the display then treats as enabled) and
|
||||
passed it to the Starlark toggle the same way, and /display/on-demand/start
|
||||
pinned the mode and restarted the service for ``"pinned": "false"`` /
|
||||
``"start_service": "false"``.
|
||||
"""
|
||||
|
||||
import sys
|
||||
from pathlib import Path
|
||||
from unittest.mock import MagicMock, patch
|
||||
|
||||
import pytest
|
||||
|
||||
sys.path.insert(0, str(Path(__file__).parent.parent))
|
||||
|
||||
from test._api_v3_test_helpers import api_v3_client, api_v3_module # noqa: F401,E402
|
||||
|
||||
|
||||
class TestPluginToggle:
|
||||
@pytest.fixture
|
||||
def saved(self, api_v3_module, monkeypatch):
|
||||
monkeypatch.setattr(api_v3_module, '_discovered_plugin_manifests',
|
||||
lambda *a, **k: {'clock': {}})
|
||||
api_v3_module.api_v3.config_manager.load_config = MagicMock(return_value={})
|
||||
captured = {}
|
||||
|
||||
def save(config_manager, config, create_backup=True):
|
||||
captured.update(config)
|
||||
return True, None
|
||||
monkeypatch.setattr(api_v3_module, '_save_config_atomic', save)
|
||||
return captured
|
||||
|
||||
@pytest.mark.parametrize("raw,expected", [
|
||||
("false", False), ("true", True), (False, False), (True, True), (0, False),
|
||||
])
|
||||
def test_enabled_is_stored_as_a_real_bool(self, api_v3_client, saved, raw, expected):
|
||||
response = api_v3_client.post('/api/v3/plugins/toggle',
|
||||
json={'plugin_id': 'clock', 'enabled': raw})
|
||||
assert response.status_code == 200, response.get_json()
|
||||
assert saved['clock']['enabled'] is expected
|
||||
|
||||
def test_a_starlark_app_gets_the_coerced_value(self, api_v3_client, api_v3_module):
|
||||
toggle = MagicMock(return_value=({'status': 'success'}, 200))
|
||||
with patch('web_interface.blueprints.api_v3.plugins._toggle_starlark_app', toggle):
|
||||
api_v3_client.post('/api/v3/plugins/toggle',
|
||||
json={'plugin_id': 'starlark:clock', 'enabled': 'false'})
|
||||
toggle.assert_called_once_with('clock', False)
|
||||
|
||||
|
||||
class TestOnDemandStart:
|
||||
@pytest.fixture
|
||||
def service(self, api_v3_module):
|
||||
api_v3_module.api_v3.plugin_manager = None
|
||||
api_v3_module.api_v3.config_manager = None
|
||||
with patch("web_interface.blueprints.api_v3.display._get_display_service_status",
|
||||
return_value={"active": True}), \
|
||||
patch("web_interface.blueprints.api_v3.display._stop_display_service") as stop, \
|
||||
patch("web_interface.blueprints.api_v3.display._ensure_display_service_running",
|
||||
return_value={"active": True}) as ensure:
|
||||
yield stop, ensure
|
||||
|
||||
def test_string_false_neither_pins_nor_restarts(self, api_v3_client, service):
|
||||
stop, ensure = service
|
||||
response = api_v3_client.post('/api/v3/display/on-demand/start', json={
|
||||
'plugin_id': 'weather', 'pinned': 'false', 'start_service': 'false'})
|
||||
assert response.status_code == 200, response.get_json()
|
||||
assert response.get_json()['data']['pinned'] is False
|
||||
stop.assert_not_called()
|
||||
ensure.assert_not_called()
|
||||
|
||||
def test_string_true_pins(self, api_v3_client, service):
|
||||
response = api_v3_client.post('/api/v3/display/on-demand/start', json={
|
||||
'plugin_id': 'weather', 'pinned': 'true', 'start_service': False})
|
||||
assert response.get_json()['data']['pinned'] is True
|
||||
Reference in New Issue
Block a user