style: format the last 10 files that ruff format disagreed with
ruff.toml has declared `quote-style = "single"` and line-length 120 since the lint job landed, and 118 of 128 files follow it. The panel backend and the netbox configuration were written in black/prettier style instead, so a `ruff format --check` would have failed on them from the start. Bring them onto the style the repository already declares, which is what makes the check adoptable at all. Formatting only: apart from quote style the diff is multi-line expressions joined where they fit inside 120 columns. Both suites still pass afterwards (25 pytest, and ruff check is clean). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
fddd82704f
commit
0ae0df7473
10 files changed
+320
-334
No files matched your search
@@ -6,43 +6,43 @@ from app.main import spa_fallback
|
||||
|
||||
@pytest.fixture
|
||||
def static_dir(tmp_path: Path, monkeypatch: pytest.MonkeyPatch) -> Path:
|
||||
static = tmp_path / "static"
|
||||
static = tmp_path / 'static'
|
||||
static.mkdir()
|
||||
(static / "index.html").write_text("<html>index</html>", encoding="utf-8")
|
||||
(static / "app.js").write_text("console.log('app')", encoding="utf-8")
|
||||
secret = tmp_path / "secret.txt"
|
||||
secret.write_text("TOP SECRET", encoding="utf-8")
|
||||
monkeypatch.setattr("app.main.static_dir", static)
|
||||
(static / 'index.html').write_text('<html>index</html>', encoding='utf-8')
|
||||
(static / 'app.js').write_text("console.log('app')", encoding='utf-8')
|
||||
secret = tmp_path / 'secret.txt'
|
||||
secret.write_text('TOP SECRET', encoding='utf-8')
|
||||
monkeypatch.setattr('app.main.static_dir', static)
|
||||
return static
|
||||
|
||||
|
||||
def static_index(static_dir: Path) -> Path:
|
||||
return static_dir / "index.html"
|
||||
return static_dir / 'index.html'
|
||||
|
||||
|
||||
def test_returns_existing_file(static_dir: Path) -> None:
|
||||
response = spa_fallback("app.js")
|
||||
assert response.path == static_dir / "app.js"
|
||||
response = spa_fallback('app.js')
|
||||
assert response.path == static_dir / 'app.js'
|
||||
|
||||
|
||||
def test_unknown_path_falls_back_to_index(static_dir: Path) -> None:
|
||||
response = spa_fallback("does/not/exist.js")
|
||||
response = spa_fallback('does/not/exist.js')
|
||||
assert response.path == static_index(static_dir)
|
||||
|
||||
|
||||
def test_traversal_does_not_leak_outside_static(static_dir: Path) -> None:
|
||||
response = spa_fallback("../secret.txt")
|
||||
response = spa_fallback('../secret.txt')
|
||||
assert response.path == static_index(static_dir)
|
||||
|
||||
response = spa_fallback("%2e%2e/secret.txt")
|
||||
response = spa_fallback('%2e%2e/secret.txt')
|
||||
assert response.path == static_index(static_dir)
|
||||
|
||||
|
||||
def test_symlink_outside_static_is_blocked(static_dir: Path, tmp_path: Path) -> None:
|
||||
target = tmp_path / "outside.txt"
|
||||
target.write_text("secret", encoding="utf-8")
|
||||
link = static_dir / "leak.txt"
|
||||
target = tmp_path / 'outside.txt'
|
||||
target.write_text('secret', encoding='utf-8')
|
||||
link = static_dir / 'leak.txt'
|
||||
link.symlink_to(target)
|
||||
|
||||
response = spa_fallback("leak.txt")
|
||||
response = spa_fallback('leak.txt')
|
||||
assert response.path == static_index(static_dir)
|
||||
Reference in new issue
Block a user