fix: merge main, address code review feedback for security fix PR #816
- Merge origin/main into branch (resolve conflict in integrations_dashboard.html) - Add defensive JSON parsing with try/except for integration.config - Wrap tester() call in try/except to prevent 500 errors from bad config - Add i18n key integrations.connection_test_failed_fallback in en.json - Reference i18n key in template JS fallback message - Update SECURITY_AUDIT.md: add fix date (2026-03-23), update doc date - Remove accidental revert.sh file - Fix missing MagicMock/patch imports in test file - Add tests for invalid JSON config and tester exception error paths Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com> Agent-Logs-Url: https://github.com/christianlouis/DocuElevate/sessions/daebb70e-059a-4601-8864-88eef49f99cf
This commit is contained in:
@@ -289,7 +289,8 @@ class TestNotifySettingsUpdated:
|
||||
call_args = mock_redis_instance.set.call_args[0]
|
||||
assert call_args[0] == SETTINGS_VERSION_KEY
|
||||
|
||||
def test_does_not_raise_on_redis_failure(self):
|
||||
@patch("app.utils.settings_sync.logger")
|
||||
def test_does_not_raise_on_redis_failure(self, mock_logger):
|
||||
"""notify_settings_updated must not propagate Redis errors."""
|
||||
from app.utils.settings_sync import notify_settings_updated
|
||||
|
||||
@@ -297,6 +298,35 @@ class TestNotifySettingsUpdated:
|
||||
mock_redis_module.from_url.side_effect = Exception("Redis down")
|
||||
# Should not raise
|
||||
notify_settings_updated()
|
||||
mock_logger.warning.assert_any_call("Could not publish settings update to Redis: Redis down")
|
||||
|
||||
@patch("app.utils.settings_sync.logger")
|
||||
def test_does_not_raise_on_reload_failure(self, mock_logger):
|
||||
"""notify_settings_updated must not propagate settings reload errors."""
|
||||
from app.utils.settings_sync import notify_settings_updated
|
||||
|
||||
with patch("app.utils.config_loader.reload_settings_from_db") as mock_reload:
|
||||
mock_reload.side_effect = Exception("Reload error")
|
||||
# We mock redis so that we skip over the redis block, and mock ensure_ocr_languages_async to prevent its side effects.
|
||||
with patch("app.utils.settings_sync.redis"):
|
||||
with patch("app.utils.ocr_language_manager.ensure_ocr_languages_async"):
|
||||
# Should not raise
|
||||
notify_settings_updated()
|
||||
mock_logger.warning.assert_any_call("Could not reload in-process settings: Reload error")
|
||||
|
||||
@patch("app.utils.settings_sync.logger")
|
||||
def test_does_not_raise_on_ocr_language_check_failure(self, mock_logger):
|
||||
"""notify_settings_updated must not propagate OCR language check errors."""
|
||||
from app.utils.settings_sync import notify_settings_updated
|
||||
|
||||
with patch("app.utils.ocr_language_manager.ensure_ocr_languages_async") as mock_ensure:
|
||||
mock_ensure.side_effect = Exception("OCR error")
|
||||
# We mock redis and reload_settings_from_db so we only test the OCR block failure.
|
||||
with patch("app.utils.settings_sync.redis"):
|
||||
with patch("app.utils.config_loader.reload_settings_from_db"):
|
||||
# Should not raise
|
||||
notify_settings_updated()
|
||||
mock_logger.warning.assert_any_call("Could not schedule OCR language check: OCR error")
|
||||
|
||||
|
||||
@pytest.mark.unit
|
||||
|
||||
Reference in New Issue
Block a user