From 907de4d64d553dabada4e32db0fa5bc7b9888b6c Mon Sep 17 00:00:00 2001 From: maziggy Date: Sat, 15 Aug 2026 16:09:20 +0200 Subject: [PATCH] Suppress two Bandit false positives in the new FTP and batch-order tests The 1.2.5.3 code-scanning run flagged two new alerts, both in test files added this release, and both false positives. B402, the ftplib import in the #2780 connect-cleanup tests, is the HIGH finding that failed the check. The test imports ftplib to construct the exceptions BambuFTPClient.connect has to survive -- error_perm and error_temp, at lines 50, 51 and 75. Nothing in the file opens a connection, and bambu_ftp.py already carries the same marker on its own import. B108, the /tmp path in the batch-order archive fixture, is the MEDIUM one. The value is a string written into PrintArchive.file_path so the row has a path; nothing ever opens it. Every other archive fixture in the suite carries the same marker on the same idiom. Both markers follow the wording already in test_bambu_ftp.py and test_sjf_scheduling.py. Bandit's medium+ count over backend/ drops from 17 to 15, and neither file contributes to what is left. --- backend/tests/integration/test_print_batch_orders.py | 2 +- .../tests/unit/services/test_ftp_failed_connect_cleanup_2780.py | 2 +- 2 files changed, 2 insertions(+), 2 deletions(-) diff --git a/backend/tests/integration/test_print_batch_orders.py b/backend/tests/integration/test_print_batch_orders.py index c4d38f1f2..6ffe75485 100644 --- a/backend/tests/integration/test_print_batch_orders.py +++ b/backend/tests/integration/test_print_batch_orders.py @@ -49,7 +49,7 @@ async def archive_factory(db_session): defaults = { "filename": f"batch_order_{counter}.3mf", "print_name": f"Batch Order {counter}", - "file_path": f"/tmp/batch_order_{counter}.3mf", + "file_path": f"/tmp/batch_order_{counter}.3mf", # nosec B108 "file_size": 2048, "content_hash": f"batchhash{counter:08d}", "status": "completed", diff --git a/backend/tests/unit/services/test_ftp_failed_connect_cleanup_2780.py b/backend/tests/unit/services/test_ftp_failed_connect_cleanup_2780.py index 52997acae..e04685c8e 100644 --- a/backend/tests/unit/services/test_ftp_failed_connect_cleanup_2780.py +++ b/backend/tests/unit/services/test_ftp_failed_connect_cleanup_2780.py @@ -18,7 +18,7 @@ These tests assert the socket is closed, not merely dereferenced, because dereferencing is what the old code did and it looked identical from outside. """ -import ftplib +import ftplib # nosec B402 — tests need the real ftplib to construct its own error types import ssl from unittest.mock import MagicMock, patch