mirror of
https://github.com/ChuckBuilds/LEDMatrix.git
synced 2026-08-08 04:08:06 +00:00
* refactor(web): use canonical secret helpers in api_v3; make ConfigManager secret strip/merge array-aware
api_v3.py carried three inline nested copies of find_secret_fields/
separate_secrets (main-config save, plugin-config save, plugin-config
reset). They drifted from each other (one lacked isinstance guards) and
none supported the canonical module's array-item secrets
(accounts[].token). All three endpoints now import from
src/web_interface/secret_helpers.
Adopting the canonical behavior makes array-item secrets reachable, and
their parallel-placeholder shape ([{'token': ...}, {}] alongside the
regular list) was not survivable by ConfigManager's round-trip:
_strip_secrets_recursive dropped the whole key (losing the regular
fields from config.json) and _deep_merge replaced the regular list
wholesale on load. Both are now array-aware:
- strip removes the secret fields from each item and ALWAYS keeps the
list so indices survive for merge-on-load; whole-key secrets (scalar
lists, shape mismatches) still drop the key entirely — never leak.
- merge folds each secrets item into the config item at the same index,
skipping {} placeholders. The regular list's length is authoritative
in both directions: a user deleting an array item never has it
resurrected from a stale secrets entry (extras warn and are ignored).
api_v3's own deep_merge intentionally still replaces lists wholesale —
form posts carry complete arrays and index-merging would resurrect
deleted items; a comment now documents that.
Tests: the parity guard flips from 'exactly 3 inline copies' to 'zero,
and the canonical import must exist'; TestArraySecretStripAndMerge
covers the new strip/merge semantics incl. length-mismatch contracts;
new test_api_v3_secret_roundtrip.py drives all three endpoints through
a Flask client with a REAL ConfigManager+SchemaManager over tmp_path,
proving secrets land in config_secrets.json, config.json stays clean,
and a fresh load merges them back into the right array items.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NohXi78cwsAKtN1sCfxjUh
* fix: repair broken helper paths across display, cache, odds, logging, resolver, repos, config, validator
Nine fixes for bugs surfaced while writing coverage for previously
untested modules (plus the bool-duration quirk pinned in PR #441):
- base_plugin.get_display_duration: exclude bools from both numeric
branches — display_duration=True no longer reads as a 1-second slot;
it falls through to config, then the 15.0 default.
- display_helper: draw_error_message/draw_no_data_message called
_draw_centered_text with the wrong arguments and crashed with
AttributeError — both now delegate to draw_centered_text.
draw_scorebug_layout drew status and clock at the same y, overprinting
each other — they now share one combined top line.
draw_ticker_layout drew its text starting at x=display_width (fully
off-canvas), returning a blank frame every time — now draws at x=0;
scroll_speed stays accepted-but-unused and is documented as such.
- api_helper.clear_cache guarded on a nonexistent CacheManager.clear()
method, silently never clearing anything; it now uses the real surface
(clear_cache/delete/list_cache_files) and no-ops safely otherwise.
- base_odds_manager._extract_espn_data raised AttributeError when ESPN
sent explicit JSON nulls ("homeTeamOdds": null) — every level now
null-safes with 'or {}'. format_odds_summary gated on
is_odds_available, which deliberately ignores money lines, so
ML-only odds formatted as "No odds available" — it now gates only on
empty/no_odds data and formats money lines.
- logging_config.ContextualFormatter mutated record.msg in place, so a
second handler prepended the context prefix twice; it now formats a
copy. log_error hardcoded exc_info=True and raised TypeError when the
caller passed exc_info — now kwargs.setdefault.
- dynamic_team_resolver wrote its "shared" class cache through self,
creating instance shadows — the cache was per-instance and every
scoreboard refetched rankings. Writes now go through the class.
- saved_repositories cleaned URLs with an unanchored .replace('.git','')
that mangled URLs merely containing '.git' (my.github.io -> myhub.io);
now strips only a trailing suffix. add/remove also roll back the
in-memory list when the save fails, so memory always matches disk.
- config_helper.merge_configs shallow-copied the base, aliasing every
un-overridden nested dict into the result — now deep-copies.
- startup_validator.validate_all accumulated errors/warnings across
calls — now resets both lists per run.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NohXi78cwsAKtN1sCfxjUh
* test: cover the previously untested modules
Nine new suites plus an extension, asserting the Phase-1b fixed behavior
and pinning the quirks deliberately left alone:
- test_logging_config.py: formatters (JSON shape, no record mutation,
single prefix through two handlers), PluginLoggerAdapter precedence,
setup_logging handler hygiene and LEDMATRIX_DEBUG, log_error exc_info.
- test_startup_validator.py: exact messages, error-vs-warning split,
accessor split (load_config vs get_config), cache-dir branches with
os.access monkeypatched (root can write anything in CI), idempotence,
raise_on_errors classification precedence.
- test_config_helper.py (full): load/save round trips, dot-notation
get/set incl. silent-failure contract, post-fix no-aliasing merge,
schema validation branches, the '{id}_config' key pin, default-enabled
pin.
- test_saved_repositories.py: three load shapes, bare-list rewrite pin,
trailing-only .git strip (my.github.io regression), save-failure
rollback, type-classification case-sensitivity pin.
- test_api_helper.py: rate-limit math, cache-hit short circuit, ESPN
URL/key formats, exact User-Agent guard, retry adapter, post-fix
clear_cache against the real CacheManager surface, ttl-dropped pin.
- test_base_odds_manager.py: cache-key/URL construction, no_odds
sentinel round trip, stale-cache fallback, null-safe extraction,
ML-only formatting, is_odds_available truth table (ML-blind by
contract), config key/attr mismatch pin.
- test_dynamic_team_resolver.py: expansion/dedup/slicing, dropped
unknown-dynamic names (TOP_ substring hazard pinned), genuinely
shared class cache (second instance: zero HTTP), TTL expiry,
failure degradation without raising.
- test_display_helper.py (full): the fixed error/no-data renders,
combined scorebug top line, non-blank ticker with scroll_speed
no-op pin, composite upconversion, logo bleed positions, square
orientation pin.
- test_skin_runtime_cache.py: discovery-cache hit/invalidation
semantics (manifest mtime, .py edits pinned as non-invalidating),
sys.modules namespacing contract incl. bare-name restore and stdlib
shadowing, entry-module execute-once, API minor-version tolerance,
skin_matches_target table.
- test_sports_capabilities.py (extended): _draw_celebration_layout
executed for real (flash window, matrix-dims fallback, highlight
alternation, logo-failure isolation), _should_celebrate_for direct,
strict duration boundary, score_to_int edges, both-teams-score
precedence, expired-coalesce refire, disabled-win baseline
preservation, id-less prune.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NohXi78cwsAKtN1sCfxjUh
* test: real schedule/dim coverage for DisplayController; fix two vacuous schedule tests
New test_display_controller_schedule.py drives _check_schedule and
_check_dim_schedule on a bare controller stub: same-day and
midnight-crossing windows with inclusive boundaries, global vs per-day vs
legacy-inferred modes (and dim's global-only default — no legacy
inference), per-day disabled days, invalid %H:%M fallbacks, unknown
timezone -> UTC, dim_brightness default 30, inactive-display short
circuit, and the _was_display_active/_was_dimmed transition flags.
test_display_controller.py's test_schedule_disabled and
test_active_hours patched config_service.get_config — which
_check_schedule never reads — so both asserted the init-default value
and could not fail. Rewritten on the test_inactive_hours pattern
(inject controller.config['schedule'], reset the minute gate, flip the
flag to the opposite state first so the assertion has teeth).
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NohXi78cwsAKtN1sCfxjUh
* ci: raise coverage floor to 48%
Measured 50% with the new suites in place (was 47% baseline when the
gate was introduced at 45); floor stays two points under measured.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NohXi78cwsAKtN1sCfxjUh
* fix: address CodeQL alert and review findings
- config_manager: the "secrets list longer than config list" warning now
interpolates only config-side data (no key name or secrets-derived
values), resolving the CodeQL clear-text-logging alert.
- base_plugin: validate_config rejects bool display_duration, matching
get_display_duration (bool is an int subclass and would otherwise pass
as a positive number).
- config_helper: merge_configs deep-copies override values in the
non-recursive branch so mutating the merged result cannot reach back
into override_config.
- saved_repositories: saves are atomic (temp file + fsync + os.replace),
so a failed write can no longer truncate saved_repositories.json.
- tests: regression cases for each fix, plus a pin that whole-item
array secrets (key[] + key[].field both marked) strip to empty {}
skeletons — no secret values can reach config.json.
Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01NohXi78cwsAKtN1sCfxjUh
---------
Co-authored-by: Claude <noreply@anthropic.com>
241 lines
10 KiB
Python
241 lines
10 KiB
Python
"""
|
|
Tests for src/plugin_system/saved_repositories.py — pins the
|
|
SavedRepositoriesManager contract.
|
|
|
|
Covers: the three accepted on-disk load shapes (bare list, wrapped
|
|
{"repositories": [...]}, anything else -> []) and that saves always write
|
|
the bare-list form; add/remove/has round trips through a fresh manager;
|
|
URL normalization post-fix (_clean_url strips only a TRAILING '.git' after
|
|
trailing slashes — the old unanchored .replace('.git', '') mangled URLs
|
|
like my.github.io); name derivation and registry-vs-single type
|
|
classification (the ledmatrix-plugins check is lowercased, the
|
|
plugins.json check is case-sensitive); and the post-fix rollback of the
|
|
in-memory list when _save_repositories() fails, so memory never diverges
|
|
from disk.
|
|
"""
|
|
|
|
import json
|
|
|
|
from src.plugin_system.saved_repositories import SavedRepositoriesManager
|
|
|
|
|
|
def make_manager(path):
|
|
return SavedRepositoriesManager(config_path=str(path))
|
|
|
|
|
|
class TestLoading:
|
|
def test_missing_file_empty_and_not_created(self, tmp_path):
|
|
path = tmp_path / "repos.json"
|
|
manager = make_manager(path)
|
|
assert manager.get_all() == []
|
|
assert not path.exists()
|
|
|
|
def test_bare_list_shape(self, tmp_path):
|
|
path = tmp_path / "repos.json"
|
|
entries = [{'url': 'https://github.com/u/r', 'name': 'r', 'type': 'single'}]
|
|
path.write_text(json.dumps(entries))
|
|
assert make_manager(path).get_all() == entries
|
|
|
|
def test_wrapped_dict_shape(self, tmp_path):
|
|
path = tmp_path / "repos.json"
|
|
entries = [{'url': 'https://github.com/u/r', 'name': 'r', 'type': 'single'}]
|
|
path.write_text(json.dumps({'repositories': entries}))
|
|
assert make_manager(path).get_all() == entries
|
|
|
|
def test_other_shape_yields_empty(self, tmp_path):
|
|
path = tmp_path / "repos.json"
|
|
path.write_text(json.dumps({'x': 1}))
|
|
assert make_manager(path).get_all() == []
|
|
|
|
def test_malformed_json_yields_empty_no_raise(self, tmp_path):
|
|
path = tmp_path / "repos.json"
|
|
path.write_text("not json {{")
|
|
assert make_manager(path).get_all() == []
|
|
|
|
|
|
class TestSaveFormat:
|
|
def test_save_always_writes_bare_list(self, tmp_path):
|
|
# Even when loaded from the wrapped {"repositories": [...]} form,
|
|
# the next save normalizes the file to a bare JSON list.
|
|
path = tmp_path / "repos.json"
|
|
entries = [{'url': 'https://github.com/u/r', 'name': 'r', 'type': 'single'}]
|
|
path.write_text(json.dumps({'repositories': entries}))
|
|
manager = make_manager(path)
|
|
assert manager.add("https://github.com/u/r2") is True
|
|
on_disk = json.loads(path.read_text())
|
|
assert isinstance(on_disk, list)
|
|
assert len(on_disk) == 2
|
|
|
|
|
|
class TestAdd:
|
|
def test_round_trip_creates_parents_and_reloads(self, tmp_path):
|
|
path = tmp_path / "sub" / "repos.json"
|
|
manager = make_manager(path)
|
|
assert manager.add("https://github.com/user/repo") is True
|
|
assert path.exists()
|
|
entry = manager.get_all()[0]
|
|
assert entry['url'] == "https://github.com/user/repo"
|
|
assert entry['name'] == "repo"
|
|
assert entry['type'] == "single"
|
|
# A fresh manager on the same path sees the persisted entry.
|
|
fresh = make_manager(path)
|
|
assert fresh.get_all() == [entry]
|
|
|
|
def test_duplicate_returns_false_file_unchanged(self, tmp_path):
|
|
path = tmp_path / "repos.json"
|
|
manager = make_manager(path)
|
|
assert manager.add("https://github.com/user/repo") is True
|
|
before = path.read_text()
|
|
assert manager.add("https://github.com/user/repo") is False
|
|
assert path.read_text() == before
|
|
assert len(manager.get_all()) == 1
|
|
|
|
def test_trailing_git_and_slash_stripped(self, tmp_path):
|
|
manager = make_manager(tmp_path / "repos.json")
|
|
assert manager.add("https://github.com/user/repo.git/") is True
|
|
assert manager.get_all()[0]['url'] == "https://github.com/user/repo"
|
|
|
|
def test_interior_dot_git_not_mangled(self, tmp_path):
|
|
# Regression for the old unanchored .replace('.git', ''): a URL
|
|
# merely CONTAINING '.git' must be stored verbatim.
|
|
manager = make_manager(tmp_path / "repos.json")
|
|
url = "https://github.com/user/my.github.io"
|
|
assert manager.add(url) is True
|
|
assert manager.get_all()[0]['url'] == url
|
|
|
|
|
|
class TestNameExtraction:
|
|
def test_name_derived_from_last_path_segment(self, tmp_path):
|
|
manager = make_manager(tmp_path / "repos.json")
|
|
manager.add("https://github.com/user/football-scoreboard")
|
|
assert manager.get_all()[0]['name'] == "football-scoreboard"
|
|
|
|
def test_explicit_name_preserved(self, tmp_path):
|
|
manager = make_manager(tmp_path / "repos.json")
|
|
manager.add("https://github.com/user/repo", name="My Repo")
|
|
assert manager.get_all()[0]['name'] == "My Repo"
|
|
|
|
def test_url_without_slash_uses_whole_url(self, tmp_path):
|
|
manager = make_manager(tmp_path / "repos.json")
|
|
manager.add("standalone")
|
|
assert manager.get_all()[0]['name'] == "standalone"
|
|
|
|
|
|
class TestTypeClassification:
|
|
def _type_of(self, tmp_path, url):
|
|
manager = make_manager(tmp_path / "repos.json")
|
|
assert manager.add(url) is True
|
|
return manager.get_all()[0]['type']
|
|
|
|
def test_plugins_json_url_is_registry(self, tmp_path):
|
|
url = "https://raw.githubusercontent.com/x/main/plugins.json"
|
|
assert self._type_of(tmp_path, url) == "registry"
|
|
|
|
def test_ledmatrix_plugins_check_is_case_insensitive(self, tmp_path):
|
|
url = "https://github.com/ChuckBuilds/LEDMATRIX-PLUGINS"
|
|
assert self._type_of(tmp_path, url) == "registry"
|
|
|
|
def test_plugins_json_check_is_case_sensitive(self, tmp_path):
|
|
# Only the 'ledmatrix-plugins' check is lowercased; the
|
|
# 'plugins.json' substring check is case-sensitive. Pinned.
|
|
url = "https://example.com/PLUGINS.JSON"
|
|
assert self._type_of(tmp_path, url) == "single"
|
|
|
|
def test_plain_repo_is_single(self, tmp_path):
|
|
assert self._type_of(tmp_path, "https://github.com/user/repo") == "single"
|
|
|
|
def test_get_registry_repositories_filters(self, tmp_path):
|
|
manager = make_manager(tmp_path / "repos.json")
|
|
manager.add("https://github.com/user/repo")
|
|
manager.add("https://raw.githubusercontent.com/x/main/plugins.json")
|
|
registries = manager.get_registry_repositories()
|
|
assert len(registries) == 1
|
|
assert registries[0]['type'] == "registry"
|
|
|
|
|
|
class TestRemove:
|
|
def test_remove_present_persists(self, tmp_path):
|
|
path = tmp_path / "repos.json"
|
|
manager = make_manager(path)
|
|
manager.add("https://github.com/user/repo")
|
|
assert manager.remove("https://github.com/user/repo") is True
|
|
assert manager.get_all() == []
|
|
assert make_manager(path).get_all() == []
|
|
|
|
def test_remove_absent_false_no_write(self, tmp_path):
|
|
path = tmp_path / "repos.json"
|
|
manager = make_manager(path)
|
|
manager.add("https://github.com/user/repo")
|
|
before = path.read_text()
|
|
assert manager.remove("https://github.com/user/other") is False
|
|
assert path.read_text() == before
|
|
|
|
def test_remove_with_dirty_url_matches_clean_stored(self, tmp_path):
|
|
manager = make_manager(tmp_path / "repos.json")
|
|
manager.add("https://github.com/user/repo")
|
|
assert manager.remove("https://github.com/user/repo.git/") is True
|
|
assert manager.get_all() == []
|
|
|
|
|
|
class TestHas:
|
|
def test_has_applies_url_cleaning(self, tmp_path):
|
|
manager = make_manager(tmp_path / "repos.json")
|
|
manager.add("https://x/y")
|
|
assert manager.has("https://x/y.git/") is True
|
|
assert manager.has("https://x/z") is False
|
|
|
|
|
|
class TestSaveFailureRollback:
|
|
def test_add_rolls_back_on_save_failure(self, tmp_path, monkeypatch):
|
|
# Post-fix: a failed save must not leave a phantom in-memory entry.
|
|
path = tmp_path / "repos.json"
|
|
manager = make_manager(path)
|
|
monkeypatch.setattr(manager, "_save_repositories", lambda: False)
|
|
assert manager.add("https://github.com/user/repo") is False
|
|
assert manager.get_all() == []
|
|
assert not path.exists()
|
|
|
|
def test_remove_rolls_back_on_save_failure(self, tmp_path, monkeypatch):
|
|
path = tmp_path / "repos.json"
|
|
manager = make_manager(path)
|
|
manager.add("https://github.com/user/repo") # real save
|
|
monkeypatch.setattr(manager, "_save_repositories", lambda: False)
|
|
assert manager.remove("https://github.com/user/repo") is False
|
|
assert manager.get_all() == [
|
|
{'url': 'https://github.com/user/repo', 'name': 'repo', 'type': 'single'}
|
|
]
|
|
# Disk still has the entry too — memory and disk stay in sync.
|
|
assert len(json.loads(path.read_text())) == 1
|
|
|
|
def test_failed_write_leaves_existing_file_intact(self, tmp_path, monkeypatch):
|
|
# The save is atomic (temp file + os.replace): a write that dies
|
|
# mid-serialization must neither truncate the existing file nor
|
|
# leave a stray .tmp behind.
|
|
path = tmp_path / "repos.json"
|
|
manager = make_manager(path)
|
|
manager.add("https://github.com/user/repo") # real save
|
|
before = path.read_text()
|
|
|
|
def boom(*args, **kwargs):
|
|
raise OSError("disk full")
|
|
monkeypatch.setattr(json, "dump", boom)
|
|
assert manager.add("https://github.com/user/other") is False
|
|
|
|
assert path.read_text() == before
|
|
assert list(tmp_path.glob("*.tmp")) == []
|
|
|
|
|
|
class TestGetAllCopy:
|
|
def test_get_all_is_shallow_copy(self, tmp_path):
|
|
# Characterization: get_all() copies the LIST but not the entry
|
|
# dicts, so mutating a returned entry mutates internal state.
|
|
# Appending to the returned list, however, does not. Do not "fix"
|
|
# without auditing callers that rely on list-copy semantics.
|
|
manager = make_manager(tmp_path / "repos.json")
|
|
manager.add("https://github.com/user/repo")
|
|
returned = manager.get_all()
|
|
returned.append({'url': 'x'})
|
|
assert len(manager.get_all()) == 1 # list itself is copied
|
|
manager.get_all()[0]['name'] = 'hacked'
|
|
assert manager.get_all()[0]['name'] == 'hacked' # dicts are shared
|