mirror of
https://github.com/kevinveenbirkenbach/homepage.veen.world.git
synced 2026-08-24 05:04:33 +00:00
fix(app): stop trusting X-Forwarded-For, and pin what the audit found
ProxyFix defaults x_for to 1, so ProxyFix(app.wsgi_app, x_proto=1) never disabled it: request.remote_addr and the access log were forgeable by any client that reached the app directly. It is x_for=0 now, asserted rather than assumed. A mutation audit over the change set reverted 196 deliberate behaviours and found 47 that no test noticed. This closes the ones that carry damage: - apod_background lost its key check, its transport guard, its status guard and its media-type check without a single test failing. Each one turns a slow or unhappy NASA into a 500 on every page. - Untrusted values reached innerHTML through window.I18N, which the translation backend writes, and the modal's click handlers stacked so a later click opened an earlier popup's URL. - The sync tool could ask for HTML instead of text, translate from "auto" instead of English, run without a timeout, store an empty translation that marks the string done for good, abandon 28 languages because one could not be written, and report success after reaching nothing. - Neither the lint target, the CI jobs, the vendored RTL stylesheet, the documented environment keys, nor any of the four hardenings in scripts/run-e2e.sh was observed by anything. Three of the new tests passed for the wrong reason on their first cut — a mock that answered None whether or not the guard existed, a raise_for_status that was never called, a string that stayed in the file after the mutation. The audit found those too; all 24 reverts now fail. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -13,6 +13,9 @@ class TestNegotiate(unittest.TestCase):
|
||||
def test_regional_tag_beats_a_lower_ranked_exact_match(self):
|
||||
self.assertEqual(i18n.negotiate([("de-DE", 1.0), ("en", 0.8)]), "de")
|
||||
|
||||
def test_an_uppercase_tag_is_accepted(self):
|
||||
self.assertEqual(i18n.negotiate([("DE-DE", 1.0)]), "de")
|
||||
|
||||
def test_underscore_separated_tag_is_accepted(self):
|
||||
self.assertEqual(i18n.negotiate([("pt_BR", 1.0)]), "pt")
|
||||
|
||||
@@ -70,6 +73,11 @@ class TestTranslateTree(unittest.TestCase):
|
||||
self.assertEqual(card["url"], "A card")
|
||||
self.assertEqual(card["icon"]["class"], "Pictures")
|
||||
|
||||
def test_strings_inside_a_list_are_translated(self):
|
||||
translated = i18n.translate_tree({"text": ["A card", "Pictures"]}, "xx")
|
||||
|
||||
self.assertEqual(translated["text"], ["Eine Karte", "Bilder"])
|
||||
|
||||
def test_unknown_strings_keep_their_source_value(self):
|
||||
translated = i18n.translate_tree({"description": "Untranslated"}, "xx")
|
||||
|
||||
@@ -125,11 +133,16 @@ class TestReadCatalog(unittest.TestCase):
|
||||
|
||||
def test_non_string_entries_are_dropped(self):
|
||||
self.path.write_text(
|
||||
"Close: 42\nOpen:\nCopy: yes\nImprint: Impressum\n", encoding="utf-8"
|
||||
"Close: 42\nOpen:\nCopy: yes\n123: Zahl\nyes: Ja\nImprint: Impressum\n",
|
||||
encoding="utf-8",
|
||||
)
|
||||
|
||||
self.assertEqual(i18n.read_catalog(self.path), {"Imprint": "Impressum"})
|
||||
|
||||
def test_a_missing_catalog_is_silent(self):
|
||||
with self.assertNoLogs(level="WARNING"):
|
||||
i18n.read_catalog(self.directory / "absent.yaml")
|
||||
|
||||
|
||||
class TestCatalogMerge(unittest.TestCase):
|
||||
def setUp(self):
|
||||
|
||||
Reference in New Issue
Block a user