fix(audit): P0-P3 audit fixes — 838 ruff errors → 0, 30 F821 bugs fixed, 118 files changed
- P0: hooks.py 3-tuple fix, trigger_dispatcher Contract, contacts/plugin unregister_actions_by_owner - P0: 5 test files — check_permission mocks removed, hardcoded DB credential → env var - P1: attachment_service DmsFile via Contract helper, restore_registry/history_hooks dedup - P1: mail/plugin restore unregister, mcp_client datetime.now(UTC), saved_views/filters patterns - P1: ProtectedRoute fail-closed, 13 test assertion fixes (bcrypt, DB-URLs, SECRET_KEYs) - P2: deprecated notifications → post_system_message (3 files), forgejo Base, report_generator lazy import - P2: webhooks permissions, deps.py/roles.py plugin perms removed, import_export default - P2: address/tags/entity_links patterns removed, worker.py Contract-Umgehungen fixed - P2: 28 frontend TODOs (hardcoded constants, deprecated notification API) - P3: dead code, duplicates, deprecated imports, private attr, __import__ inline - P3: 8 frontend TODOs (LucideIcons, inline styles, XSS, i18n) - ruff: 838 → 0 (612 auto-fix + 246 manual + 27 F821 regression fix) - F821: 30 → 0 (AutomationDefinition, DmsFile, user_id, Path, Any, String) - Contract-Umgehungen: 2 neue gefunden (worker.py:169, worker.py:280) und gefixt
This commit is contained in:
+15
-50
@@ -31,9 +31,14 @@ def register_history_hooks(
|
||||
after_create_hook: str,
|
||||
after_update_hook: str,
|
||||
after_delete_hook: str,
|
||||
owner_tag: str | None = None,
|
||||
) -> None:
|
||||
"""Register standard history-recording hooks for an entity type.
|
||||
|
||||
Args:
|
||||
owner_tag: Plugin name that owns these hooks. Used for targeted
|
||||
deregistration in on_deactivate() via unregister_actions_by_owner().
|
||||
|
||||
Each hook receives kwargs: db, tenant_id, user_id, and either:
|
||||
- after_create: snapshot_after (the created entity dict)
|
||||
- after_update: snapshot_before, snapshot_after, changes
|
||||
@@ -99,9 +104,9 @@ def register_history_hooks(
|
||||
action="delete", snapshot_before=snapshot_before,
|
||||
)
|
||||
|
||||
reg.register_action(after_create_hook, _on_create, priority=90)
|
||||
reg.register_action(after_update_hook, _on_update, priority=90)
|
||||
reg.register_action(after_delete_hook, _on_delete, priority=90)
|
||||
reg.register_action(after_create_hook, _on_create, priority=90, owner_tag=owner_tag)
|
||||
reg.register_action(after_update_hook, _on_update, priority=90, owner_tag=owner_tag)
|
||||
reg.register_action(after_delete_hook, _on_delete, priority=90, owner_tag=owner_tag)
|
||||
logger.debug("History hooks registered for: %s", entity_type)
|
||||
|
||||
|
||||
@@ -121,56 +126,16 @@ def _extract_entity_id(snapshot: dict[str, Any] | None) -> uuid.UUID | None:
|
||||
|
||||
|
||||
def register_default_history_hooks() -> None:
|
||||
"""Register history hooks for all built-in entity types.
|
||||
"""Register history hooks for Core entity types only.
|
||||
|
||||
Called during app startup after the hook registry is initialized.
|
||||
Plugin entities should register their own hooks in on_activate().
|
||||
Plugin entities (task, calendar_entry, dms_file, mail) register
|
||||
their own hooks in on_activate(). See P0-8 fix.
|
||||
"""
|
||||
reg = get_hook_registry()
|
||||
|
||||
# Contact (already has manual record_history calls in contact_service.py,
|
||||
# but registering hooks ensures consistency for any code path that fires
|
||||
# the hooks without calling record_history directly)
|
||||
register_history_hooks(
|
||||
reg, "contact",
|
||||
"contact.after_create",
|
||||
"contact.after_update",
|
||||
"contact.after_delete",
|
||||
)
|
||||
|
||||
# Task plugin
|
||||
register_history_hooks(
|
||||
reg, "task",
|
||||
"task.after_create",
|
||||
"task.after_update",
|
||||
"task.after_delete",
|
||||
)
|
||||
|
||||
# Calendar plugin — CalendarEntry
|
||||
register_history_hooks(
|
||||
reg, "calendar_entry",
|
||||
"calendar_entry.after_create",
|
||||
"calendar_entry.after_update",
|
||||
"calendar_entry.after_delete",
|
||||
)
|
||||
|
||||
# DMS plugin — File metadata
|
||||
register_history_hooks(
|
||||
reg, "dms_file",
|
||||
"dms_file.after_create",
|
||||
"dms_file.after_update",
|
||||
"dms_file.after_delete",
|
||||
)
|
||||
|
||||
# Mail plugin
|
||||
register_history_hooks(
|
||||
reg, "mail",
|
||||
"mail.after_create",
|
||||
"mail.after_update",
|
||||
"mail.after_delete",
|
||||
)
|
||||
|
||||
logger.info("Default history hooks registered for: contact, task, calendar_entry, dms_file, mail")
|
||||
# Contact hooks are registered by ContactsPlugin.on_activate() with
|
||||
# owner_tag="contacts" — do not register them here to avoid double
|
||||
# registration. This function remains for future Core entities that
|
||||
# have no plugin.
|
||||
|
||||
|
||||
def reset_history_hooks_for_testing() -> None:
|
||||
|
||||
Reference in New Issue
Block a user