Merge remote-tracking branch 'origin/main' into 0.2.4.6

This commit is contained in:
maziggy
2026-06-09 13:28:38 +02:00
4 changed files with 7 additions and 7 deletions
+2 -2
View File
File diff suppressed because one or more lines are too long
@@ -1651,7 +1651,7 @@ class TestUploadSourceThreeMF:
archive = await archive_factory(
printer.id,
print_name="Corrupt Path",
file_path="/tmp/totally_outside.gcode.3mf",
file_path="/tmp/totally_outside.gcode.3mf", # nosec B108
filename="totally_outside.gcode.3mf",
)
@@ -1661,4 +1661,4 @@ class TestUploadSourceThreeMF:
assert response.status_code == 500
assert "outside the data directory" in response.json()["detail"]
# Did not write anything under the bogus /tmp/source/ either.
assert not (Path("/tmp") / "source").exists() or not (Path("/tmp") / "source" / "totally_outside.3mf").exists()
assert not (Path("/tmp") / "source").exists() or not (Path("/tmp") / "source" / "totally_outside.3mf").exists() # nosec B108
@@ -78,11 +78,11 @@ async def test_attach_timelapse_rejects_absolute_filename(tmp_path: Path, monkey
result = await service.attach_timelapse(
archive_id=1,
timelapse_data=b"x",
filename="/tmp/owned_via_absolute",
filename="/tmp/owned_via_absolute", # nosec B108
)
assert result is False
assert not Path("/tmp/owned_via_absolute").exists()
assert not Path("/tmp/owned_via_absolute").exists() # nosec B108
@pytest.mark.asyncio
+1 -1
View File
@@ -1162,7 +1162,7 @@ class TestBindAddressAutoResolve:
async def test_rewrite_arms_via_auto_resolved_host_ip(self):
"""When bind_address is 0.0.0.0, fall back to the host interface in
the target printer's subnet and rewrite to that IP."""
server = _make_server(bind_address="0.0.0.0")
server = _make_server(bind_address="0.0.0.0") # nosec B104
bridge = _make_bridge(server)
with patch(
"backend.app.services.virtual_printer.mqtt_bridge._resolve_host_interface_for_target",