mirror of
https://github.com/maziggy/bambuddy.git
synced 2026-09-30 03:01:21 +02:00
Suppress two Bandit false positives in the new FTP and batch-order tests
The 1.2.5.3 code-scanning run flagged two new alerts, both in test files added this release, and both false positives. B402, the ftplib import in the #2780 connect-cleanup tests, is the HIGH finding that failed the check. The test imports ftplib to construct the exceptions BambuFTPClient.connect has to survive -- error_perm and error_temp, at lines 50, 51 and 75. Nothing in the file opens a connection, and bambu_ftp.py already carries the same marker on its own import. B108, the /tmp path in the batch-order archive fixture, is the MEDIUM one. The value is a string written into PrintArchive.file_path so the row has a path; nothing ever opens it. Every other archive fixture in the suite carries the same marker on the same idiom. Both markers follow the wording already in test_bambu_ftp.py and test_sjf_scheduling.py. Bandit's medium+ count over backend/ drops from 17 to 15, and neither file contributes to what is left.
This commit is contained in:
@@ -49,7 +49,7 @@ async def archive_factory(db_session):
|
||||
defaults = {
|
||||
"filename": f"batch_order_{counter}.3mf",
|
||||
"print_name": f"Batch Order {counter}",
|
||||
"file_path": f"/tmp/batch_order_{counter}.3mf",
|
||||
"file_path": f"/tmp/batch_order_{counter}.3mf", # nosec B108
|
||||
"file_size": 2048,
|
||||
"content_hash": f"batchhash{counter:08d}",
|
||||
"status": "completed",
|
||||
|
||||
@@ -18,7 +18,7 @@ These tests assert the socket is closed, not merely dereferenced, because
|
||||
dereferencing is what the old code did and it looked identical from outside.
|
||||
"""
|
||||
|
||||
import ftplib
|
||||
import ftplib # nosec B402 — tests need the real ftplib to construct its own error types
|
||||
import ssl
|
||||
from unittest.mock import MagicMock, patch
|
||||
|
||||
|
||||
Reference in New Issue
Block a user