fix(audit): P0-P3 audit fixes — 838 ruff errors → 0, 30 F821 bugs fixed, 118 files changed

- P0: hooks.py 3-tuple fix, trigger_dispatcher Contract, contacts/plugin unregister_actions_by_owner
- P0: 5 test files — check_permission mocks removed, hardcoded DB credential → env var
- P1: attachment_service DmsFile via Contract helper, restore_registry/history_hooks dedup
- P1: mail/plugin restore unregister, mcp_client datetime.now(UTC), saved_views/filters patterns
- P1: ProtectedRoute fail-closed, 13 test assertion fixes (bcrypt, DB-URLs, SECRET_KEYs)
- P2: deprecated notifications → post_system_message (3 files), forgejo Base, report_generator lazy import
- P2: webhooks permissions, deps.py/roles.py plugin perms removed, import_export default
- P2: address/tags/entity_links patterns removed, worker.py Contract-Umgehungen fixed
- P2: 28 frontend TODOs (hardcoded constants, deprecated notification API)
- P3: dead code, duplicates, deprecated imports, private attr, __import__ inline
- P3: 8 frontend TODOs (LucideIcons, inline styles, XSS, i18n)
- ruff: 838 → 0 (612 auto-fix + 246 manual + 27 F821 regression fix)
- F821: 30 → 0 (AutomationDefinition, DmsFile, user_id, Path, Any, String)
- Contract-Umgehungen: 2 neue gefunden (worker.py:169, worker.py:280) und gefixt
This commit is contained in:
Agent Zero
2026-08-16 01:17:18 +02:00
parent 3d9b76cea4
commit abbe7a18fc
306 changed files with 5912 additions and 1827 deletions
+15 -50
View File
@@ -31,9 +31,14 @@ def register_history_hooks(
after_create_hook: str,
after_update_hook: str,
after_delete_hook: str,
owner_tag: str | None = None,
) -> None:
"""Register standard history-recording hooks for an entity type.
Args:
owner_tag: Plugin name that owns these hooks. Used for targeted
deregistration in on_deactivate() via unregister_actions_by_owner().
Each hook receives kwargs: db, tenant_id, user_id, and either:
- after_create: snapshot_after (the created entity dict)
- after_update: snapshot_before, snapshot_after, changes
@@ -99,9 +104,9 @@ def register_history_hooks(
action="delete", snapshot_before=snapshot_before,
)
reg.register_action(after_create_hook, _on_create, priority=90)
reg.register_action(after_update_hook, _on_update, priority=90)
reg.register_action(after_delete_hook, _on_delete, priority=90)
reg.register_action(after_create_hook, _on_create, priority=90, owner_tag=owner_tag)
reg.register_action(after_update_hook, _on_update, priority=90, owner_tag=owner_tag)
reg.register_action(after_delete_hook, _on_delete, priority=90, owner_tag=owner_tag)
logger.debug("History hooks registered for: %s", entity_type)
@@ -121,56 +126,16 @@ def _extract_entity_id(snapshot: dict[str, Any] | None) -> uuid.UUID | None:
def register_default_history_hooks() -> None:
"""Register history hooks for all built-in entity types.
"""Register history hooks for Core entity types only.
Called during app startup after the hook registry is initialized.
Plugin entities should register their own hooks in on_activate().
Plugin entities (task, calendar_entry, dms_file, mail) register
their own hooks in on_activate(). See P0-8 fix.
"""
reg = get_hook_registry()
# Contact (already has manual record_history calls in contact_service.py,
# but registering hooks ensures consistency for any code path that fires
# the hooks without calling record_history directly)
register_history_hooks(
reg, "contact",
"contact.after_create",
"contact.after_update",
"contact.after_delete",
)
# Task plugin
register_history_hooks(
reg, "task",
"task.after_create",
"task.after_update",
"task.after_delete",
)
# Calendar plugin — CalendarEntry
register_history_hooks(
reg, "calendar_entry",
"calendar_entry.after_create",
"calendar_entry.after_update",
"calendar_entry.after_delete",
)
# DMS plugin — File metadata
register_history_hooks(
reg, "dms_file",
"dms_file.after_create",
"dms_file.after_update",
"dms_file.after_delete",
)
# Mail plugin
register_history_hooks(
reg, "mail",
"mail.after_create",
"mail.after_update",
"mail.after_delete",
)
logger.info("Default history hooks registered for: contact, task, calendar_entry, dms_file, mail")
# Contact hooks are registered by ContactsPlugin.on_activate() with
# owner_tag="contacts" — do not register them here to avoid double
# registration. This function remains for future Core entities that
# have no plugin.
def reset_history_hooks_for_testing() -> None: