From 3b5d219860784f20b7d3df668178866ea2a833ca Mon Sep 17 00:00:00 2001 From: maziggy Date: Sun, 2 Aug 2026 11:08:50 +0200 Subject: [PATCH] Suppress Bandit B104 false positive in the SSRF guard tests The parametrize list feeds "0.0.0.0" to TasmotaService._validate_ip and asserts it is refused. B104 matches the literal wherever it occurs and cannot distinguish a rejection fixture from a bind address. Split the list across lines so the token carries its own nosec with the reason; the single-line form was 117 chars against a 120 limit. --- backend/tests/unit/test_outbound_url_ssrf_guards.py | 11 ++++++++++- 1 file changed, 10 insertions(+), 1 deletion(-) diff --git a/backend/tests/unit/test_outbound_url_ssrf_guards.py b/backend/tests/unit/test_outbound_url_ssrf_guards.py index 2d716234c..5d913d149 100644 --- a/backend/tests/unit/test_outbound_url_ssrf_guards.py +++ b/backend/tests/unit/test_outbound_url_ssrf_guards.py @@ -436,7 +436,16 @@ def test_ha_guard_keeps_ipv6_literals_bracketed(): assert HomeAssistantService._validate_url("http://[fd00::1]:8123/api") == "http://[fd00::1]:8123/api" -@pytest.mark.parametrize("ip", ["169.254.169.254", "100.100.100.200", "fd00:ec2::254", "0.0.0.0", "239.255.255.250"]) +@pytest.mark.parametrize( + "ip", + [ + "169.254.169.254", + "100.100.100.200", + "fd00:ec2::254", + "0.0.0.0", # nosec B104 — rejection fixture, not a bind address: the assertion below is that the guard refuses it + "239.255.255.250", + ], +) def test_tasmota_guard_rejects_metadata_and_misuse_addresses(ip: str): """Tasmota keeps its own stricter rule (bare IP literals only, loopback rejected — a plug is always a separate LAN device), but must not miss the