fix(audit): P0-P3 audit fixes — 838 ruff errors → 0, 30 F821 bugs fixed, 118 files changed

- P0: hooks.py 3-tuple fix, trigger_dispatcher Contract, contacts/plugin unregister_actions_by_owner
- P0: 5 test files — check_permission mocks removed, hardcoded DB credential → env var
- P1: attachment_service DmsFile via Contract helper, restore_registry/history_hooks dedup
- P1: mail/plugin restore unregister, mcp_client datetime.now(UTC), saved_views/filters patterns
- P1: ProtectedRoute fail-closed, 13 test assertion fixes (bcrypt, DB-URLs, SECRET_KEYs)
- P2: deprecated notifications → post_system_message (3 files), forgejo Base, report_generator lazy import
- P2: webhooks permissions, deps.py/roles.py plugin perms removed, import_export default
- P2: address/tags/entity_links patterns removed, worker.py Contract-Umgehungen fixed
- P2: 28 frontend TODOs (hardcoded constants, deprecated notification API)
- P3: dead code, duplicates, deprecated imports, private attr, __import__ inline
- P3: 8 frontend TODOs (LucideIcons, inline styles, XSS, i18n)
- ruff: 838 → 0 (612 auto-fix + 246 manual + 27 F821 regression fix)
- F821: 30 → 0 (AutomationDefinition, DmsFile, user_id, Path, Any, String)
- Contract-Umgehungen: 2 neue gefunden (worker.py:169, worker.py:280) und gefixt
This commit is contained in:
Agent Zero
2026-08-16 01:17:18 +02:00
parent 3d9b76cea4
commit abbe7a18fc
306 changed files with 5912 additions and 1827 deletions
@@ -4,7 +4,6 @@ from __future__ import annotations
from app.config import settings
# Marketplace server URL — must be configured via env var MARKETPLACE_SERVER_URL
# Default: empty string means marketplace is not configured
MARKETPLACE_SERVER_URL: str = getattr(settings, "marketplace_server_url", "")
+2 -1
View File
@@ -6,7 +6,8 @@ import uuid
from datetime import UTC, datetime
from sqlalchemy import DateTime, Float, Index, Integer, String, Text
from sqlalchemy.dialects.postgresql import JSONB, UUID as PGUUID
from sqlalchemy.dialects.postgresql import JSONB
from sqlalchemy.dialects.postgresql import UUID as PGUUID
from sqlalchemy.orm import Mapped, mapped_column
from app.core.db import Base, TimestampMixin
@@ -3,7 +3,6 @@
from __future__ import annotations
import logging
from typing import Any
from app.plugins.base import BasePlugin
from app.plugins.manifest import PluginManifest, PluginRouteDef
+3 -5
View File
@@ -3,23 +3,21 @@
from __future__ import annotations
import logging
import uuid
from pathlib import Path
from fastapi import APIRouter, Depends, HTTPException, Query
from sqlalchemy.ext.asyncio import AsyncSession
import app.plugins.builtins.marketplace.services as marketplace_services
from app.core.db import get_db
from app.deps import require_admin, require_permission
from app.plugins.builtins.marketplace.schemas import (
MarketplaceCategoriesResponse,
MarketplaceInstallRequest,
MarketplaceInstallResponse,
MarketplaceListResponse,
MarketplaceListingRead,
MarketplaceListResponse,
MarketplaceVerifyResponse,
)
import app.plugins.builtins.marketplace.services as marketplace_services
logger = logging.getLogger(__name__)
@@ -51,7 +49,7 @@ async def list_marketplace_listings(
)
return MarketplaceListResponse(
listings=[MarketplaceListingRead(**l) for l in result["listings"]],
listings=[MarketplaceListingRead(**listing) for listing in result["listings"]],
total=result["total"],
page=result["page"],
page_size=result["page_size"],
+4 -7
View File
@@ -3,7 +3,6 @@
from __future__ import annotations
import logging
import os
import shutil
import tempfile
import zipfile
@@ -11,13 +10,12 @@ from pathlib import Path
from typing import Any
import httpx
from sqlalchemy import and_, func, select
from sqlalchemy import func, select
from sqlalchemy.ext.asyncio import AsyncSession
from app.plugins.builtins.marketplace.config import (
MARKETPLACE_DOWNLOAD_TIMEOUT,
MARKETPLACE_MAX_ZIP_SIZE,
MARKETPLACE_SERVER_URL,
)
from app.plugins.builtins.marketplace.models import MarketplaceListing
from app.plugins.signature import PluginSignature
@@ -70,7 +68,7 @@ async def fetch_listings(
listings = (await db.execute(query)).scalars().all()
return {
"listings": [_listing_to_response(l) for l in listings],
"listings": [_listing_to_response(listing) for listing in listings],
"total": total,
"page": page,
"page_size": page_size,
@@ -121,7 +119,7 @@ async def download_plugin(
# Validate it's a valid ZIP
if not zipfile.is_zipfile(zip_path):
shutil.rmtree(temp_dir, ignore_errors=True)
raise ValueError(f"Downloaded file is not a valid ZIP archive")
raise ValueError("Downloaded file is not a valid ZIP archive")
return zip_path
@@ -189,7 +187,6 @@ async def install_plugin(
try:
# 3. Verify signature if public key is available
if listing.signature_public_key:
public_key_bytes = listing.signature_public_key.encode("utf-8")
# We need the signature from the listing — for now, we verify
# that the ZIP hash matches the allowlist (basic integrity check)
file_hash = PluginSignature.compute_hash(zip_path)
@@ -204,7 +201,7 @@ async def install_plugin(
# Copy the ZIP to a temp location for the plugin service
# The plugin service expects a ZIP file to extract
install_result = await service.install_plugin_from_zip(
await service.install_plugin_from_zip(
db,
zip_path=str(zip_path),
tenant_id=tenant_id,