Commit Graph
8 Commits
Author SHA1 Message Date
maziggy fc116f2f82 Removed unused i18next-http-backend 2026-04-23 08:51:12 +02:00
maziggy ffec267df1 Updated requirements-dev.txt 2026-04-22 19:44:59 +02:00
maziggy 407c9f84cf Bump pyOpenSSL and pyasn1 to fix 3 CVEs
pyOpenSSL 25.3.0 → 26.0.0 (CVE-2026-27448, CVE-2026-27459)
  pyasn1 0.6.2 → 0.6.3 (CVE-2026-30922)

  No breaking changes — Python 3.7 drop is irrelevant (we use 3.13),
  cryptography >=46.0.0 requirement already satisfied (we have 46.0.5),
  and we don't use set_tlsext_servername_callback (the behavioral change).
2026-03-22 13:24:36 +01:00
maziggy 5d0d249f1d Fix CI backend-tests failing to collect FTP test suite
CI only installed requirements.txt, missing pyOpenSSL from
requirements-dev.txt. This caused an ImportError on
TLS_FTPHandler during test collection, blocking all
unit/services tests. Also adds pytest-timeout to dev deps
instead of ad-hoc pip install in CI.
2026-02-10 17:50:32 +01:00
maziggy f2468077fe Add mock FTPS server and comprehensive FTP test suite (67 tests)
FTP bugs have been the #1 recurring issue across releases (0.1.8+).
This adds a real implicit FTPS mock server and 67 test cases covering
every known failure mode — connection, upload, download, delete, storage
info, model-specific SSL behavior, async wrappers, and failure injection.

New files:
- mock_ftp_server.py: implicit FTPS server on pyftpdlib with failure injection
- conftest.py: FTP test fixtures (certs, server, client factory)
- test_bambu_ftp.py: 67 tests across 10 test classes

Also adds pyOpenSSL to requirements-dev.txt (needed by pyftpdlib
TLS_FTPHandler in the Docker test image).
2026-02-07 10:55:05 +01:00
maziggy 53bd4fadb3 Fix safe security findings: hashlib, log injection, broad excepts
- Add usedforsecurity=False to MD5 (AMS fingerprint) and SHA1 (git blob
  hash) calls to silence Bandit B303 / CodeQL weak-crypto findings
- Convert ~996 f-string logging calls to parameterized %s-style across
  55 files to prevent log injection (Bandit G201 / CodeQL log-injection)
- Narrow ~199 broad except Exception blocks to specific types:
  OperationalError for DB migrations, OSError for network/file cleanup,
  (OSError, ftplib.error_reply) for FTP, and targeted tuples for
  ZIP/XML/JSON parsing — 36 intentionally left broad (mixed async,
  re-raise patterns)
2026-02-06 11:37:59 +01:00
maziggy 964be0eb26 Improved Docker tests 2026-02-05 10:28:06 +01:00
maziggy 58c98b1075 Added docker test suite
Test Summary:
  - Build tests: 3 passed (image build, backend imports, static files)
  - Backend unit tests: 378 passed (9 docker tests excluded)
  - Frontend unit tests: 137 passed
  - Integration tests: 9 passed (health, API endpoints, persistence, WebSocket)

  Changes made to fix the Docker test suite:
  1. Added curl to the production Dockerfile for integration tests
  2. Removed deprecated version attribute from docker-compose.test.yml
  3. Added --pull flag to all build commands to ensure fresh images
  4. Added explicit build step before starting integration container
  5. Fixed WebSocket test to accept 200 as a valid response
  6. Excluded docker-marked tests from backend unit test runs (-m "not docker")
2025-12-14 09:15:49 +01:00