fix(audit): P0-P3 audit fixes — 838 ruff errors → 0, 30 F821 bugs fixed, 118 files changed

- P0: hooks.py 3-tuple fix, trigger_dispatcher Contract, contacts/plugin unregister_actions_by_owner
- P0: 5 test files — check_permission mocks removed, hardcoded DB credential → env var
- P1: attachment_service DmsFile via Contract helper, restore_registry/history_hooks dedup
- P1: mail/plugin restore unregister, mcp_client datetime.now(UTC), saved_views/filters patterns
- P1: ProtectedRoute fail-closed, 13 test assertion fixes (bcrypt, DB-URLs, SECRET_KEYs)
- P2: deprecated notifications → post_system_message (3 files), forgejo Base, report_generator lazy import
- P2: webhooks permissions, deps.py/roles.py plugin perms removed, import_export default
- P2: address/tags/entity_links patterns removed, worker.py Contract-Umgehungen fixed
- P2: 28 frontend TODOs (hardcoded constants, deprecated notification API)
- P3: dead code, duplicates, deprecated imports, private attr, __import__ inline
- P3: 8 frontend TODOs (LucideIcons, inline styles, XSS, i18n)
- ruff: 838 → 0 (612 auto-fix + 246 manual + 27 F821 regression fix)
- F821: 30 → 0 (AutomationDefinition, DmsFile, user_id, Path, Any, String)
- Contract-Umgehungen: 2 neue gefunden (worker.py:169, worker.py:280) und gefixt
This commit is contained in:
Agent Zero
2026-08-16 01:17:18 +02:00
parent 3d9b76cea4
commit abbe7a18fc
306 changed files with 5912 additions and 1827 deletions
@@ -5,8 +5,6 @@ Exposes the WebSocket manager and UI command schemas for other plugins.
from __future__ import annotations
from app.plugins.builtins.contracts import get_contract_registry
from app.plugins.builtins.ai_ui_control.websocket_manager import AIUIControlWSManager
from app.plugins.builtins.ai_ui_control.schemas import (
UICommand,
UICommandCreate,
@@ -16,6 +14,8 @@ from app.plugins.builtins.ai_ui_control.schemas import (
UICommandStatusResponse,
UICommandType,
)
from app.plugins.builtins.ai_ui_control.websocket_manager import AIUIControlWSManager
from app.plugins.builtins.contracts import get_contract_registry
class AiUiControlContract:
+8 -8
View File
@@ -11,12 +11,10 @@ import json
import logging
import uuid
from fastapi import APIRouter, WebSocket, WebSocketDisconnect, Depends, HTTPException, Request
from fastapi.responses import JSONResponse
from fastapi import APIRouter, Depends, HTTPException, Request, WebSocket, WebSocketDisconnect
from app.deps import require_permission
from app.plugins.builtins.ai_ui_control.schemas import (
UICommand,
UICommandCreate,
UICommandFeedback,
UICommandResponse,
@@ -45,7 +43,7 @@ async def send_ui_command(
Authentication: requires valid session (same-user commands only).
"""
from app.config import get_settings
from app.core.auth import get_session_data, get_redis
from app.core.auth import get_redis, get_session_data
from app.core.service_container import get_container
settings = get_settings()
@@ -117,7 +115,7 @@ async def get_command_status(
AI agents call this to check if the frontend has executed the command.
"""
from app.config import get_settings
from app.core.auth import get_session_data, get_redis
from app.core.auth import get_redis, get_session_data
from app.core.service_container import get_container
settings = get_settings()
@@ -173,7 +171,7 @@ async def get_command_status(
async def get_online_users(request: Request):
"""Check which users are currently online (have active frontend WS connections)."""
from app.config import get_settings
from app.core.auth import get_session_data, get_redis
from app.core.auth import get_redis, get_session_data
from app.core.service_container import get_container
settings = get_settings()
@@ -225,9 +223,11 @@ async def ai_ui_control_ws(websocket: WebSocket):
tenant_id = auth["tenant_id"]
# Plugin-Gate: check if ai_ui_control plugin is active (global + tenant)
from app.core.permission_registry import get_permission_registry
from sqlalchemy import text as sa_text
import uuid as _uuid
from sqlalchemy import text as sa_text
from app.core.permission_registry import get_permission_registry
try:
registry = get_permission_registry()
if not registry.is_plugin_active("ai_ui_control"):
@@ -2,13 +2,13 @@
from __future__ import annotations
from enum import Enum
from enum import StrEnum
from typing import Any
from pydantic import BaseModel, Field
class UICommandType(str, Enum):
class UICommandType(StrEnum):
"""Supported UI command types."""
navigate = "navigate"
filter = "filter"
@@ -18,7 +18,7 @@ class UICommandType(str, Enum):
settings = "settings"
class UICommandStatus(str, Enum):
class UICommandStatus(StrEnum):
"""Status of a UI command execution."""
pending = "pending"
delivered = "delivered"
@@ -15,6 +15,7 @@ import uuid
from typing import Any
from fastapi import WebSocket
from sqlalchemy.ext.asyncio import AsyncSession
from app.core.ws_helpers import (
authenticate_ws,
@@ -28,7 +29,6 @@ from app.core.ws_pubsub import (
get_tenant_channel,
subscribe_to_channel,
)
from sqlalchemy.ext.asyncio import AsyncSession
logger = logging.getLogger(__name__)
@@ -176,9 +176,9 @@ class AIUIControlWSManager:
if command_id:
self._feedback[command_id] = feedback
# Enforce max feedback entries (FIFO eviction)
MAX_FEEDBACK_ENTRIES = 100
if len(self._feedback) > MAX_FEEDBACK_ENTRIES:
keys_to_remove = list(self._feedback.keys())[:-MAX_FEEDBACK_ENTRIES]
max_feedback_entries = 100
if len(self._feedback) > max_feedback_entries:
keys_to_remove = list(self._feedback.keys())[:-max_feedback_entries]
for key in keys_to_remove:
del self._feedback[key]
logger.debug(f"AI UI Control: feedback stored for command {command_id}: {feedback.get('status')}")