mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-10-05 06:45:09 +00:00
chore(composer): silence Codacy's 18 findings, all of them false positives
Checked each one rather than blanket-suppressing. Python (Opengrep, 4). The Jinja2 environment disables autoescaping on purpose -- these templates emit Python, not HTML, and escaping a quote in a plugin name would corrupt the generated source. The safety comes from the values instead (_safe_int, _rgb_expr, _reject_source_breaking), which test_composer_code_injection.py covers. Both the Environment( line and the autoescape= line are reported separately, so each needs its own nosemgrep. The two "Flask route directly returning a formatted string" hits are not routes at all: _as_rgb_filter is a Jinja filter and _rgb_tuple a private helper, both emitting a Python tuple literal with every channel coerced to int first. JavaScript (Biome + ESLint, 14). useQwikValidLexicalScope fired five times on plain arrow-function consts -- it is a Qwik rule about the $() serialization boundary, and this is Alpine.js. noUnusedVariables flagged composerApp(), which the template calls as x-data="composerApp()", where the linter cannot see it. The eight detect-object-injection hits are array indices (this.elements[idx], rawVals[i]) or lookups on module-private maps keyed by an internal element type; none takes an attacker-supplied property name, so disabled per file with the reason rather than eight times inline. .codacy.yml only supports exclude_paths, so these have to be inline. Matches the repo's existing "eslint-disable-line <rule> -- <reason>" form. 372 composer tests pass, including the 14 JS contract tests that parse these two files. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_014RRtqXDCnvnY6EQwhT5CV9
This commit is contained in:
co-authored by
Claude Opus 5
parent
2f42d179f6
commit
ea54e56bed
@@ -69,7 +69,7 @@ def _get_jinja_env() -> jinja2.Environment:
|
||||
global _jinja_env
|
||||
if _jinja_env is None:
|
||||
template_dir = Path(__file__).parent.parent / 'templates' / 'v3' / 'composer'
|
||||
_jinja_env = jinja2.Environment( # nosec B701 - see below
|
||||
_jinja_env = jinja2.Environment( # nosec B701 - see below # nosemgrep
|
||||
loader=jinja2.FileSystemLoader(str(template_dir)),
|
||||
# These templates emit Python source, not HTML. Autoescaping would
|
||||
# turn a quote in a plugin name into " inside generated code
|
||||
@@ -79,7 +79,9 @@ def _get_jinja_env() -> jinja2.Environment:
|
||||
# string literal is rejected by _reject_source_breaking. Both are
|
||||
# covered by test/test_composer_code_injection.py, which is where
|
||||
# to look before relaxing any of it.
|
||||
autoescape=False,
|
||||
autoescape=False, # nosemgrep - deliberate; these templates
|
||||
# emit Python, not HTML, and the safety comes from the values
|
||||
# (_safe_int / _rgb_expr / _reject_source_breaking) instead.
|
||||
trim_blocks=True,
|
||||
lstrip_blocks=True,
|
||||
)
|
||||
@@ -92,7 +94,9 @@ def _as_rgb_filter(val) -> str:
|
||||
"""[r, g, b] → '(r, g, b)'"""
|
||||
if val is None:
|
||||
return 'None'
|
||||
return f'({int(val[0])}, {int(val[1])}, {int(val[2])})'
|
||||
# nosemgrep: not a Flask route -- a Jinja filter emitting a Python
|
||||
# tuple literal, with every channel coerced by int().
|
||||
return f'({int(val[0])}, {int(val[1])}, {int(val[2])})' # nosemgrep
|
||||
|
||||
|
||||
def _as_fill_filter(val) -> str:
|
||||
@@ -177,7 +181,9 @@ def _rgb_tuple(el: dict, keys, defaults) -> str:
|
||||
source, so they were an injection route exactly like an uncoerced
|
||||
dimension. Every channel now goes through _safe_int.
|
||||
"""
|
||||
return "(" + ", ".join(
|
||||
# nosemgrep: not a Flask route -- a private helper emitting a Python
|
||||
# tuple literal, with every channel clamped to 0-255 by _safe_int.
|
||||
return "(" + ", ".join( # nosemgrep
|
||||
str(_safe_int(el.get(k), d, 0, 255)) for k, d in zip(keys, defaults)
|
||||
) + ")"
|
||||
|
||||
|
||||
Reference in New Issue
Block a user