fix: merge main, address code review feedback for security fix PR #816
- Merge origin/main into branch (resolve conflict in integrations_dashboard.html) - Add defensive JSON parsing with try/except for integration.config - Wrap tester() call in try/except to prevent 500 errors from bad config - Add i18n key integrations.connection_test_failed_fallback in en.json - Reference i18n key in template JS fallback message - Update SECURITY_AUDIT.md: add fix date (2026-03-23), update doc date - Remove accidental revert.sh file - Fix missing MagicMock/patch imports in test file - Add tests for invalid JSON config and tester exception error paths Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com> Agent-Logs-Url: https://github.com/christianlouis/DocuElevate/sessions/daebb70e-059a-4601-8864-88eef49f99cf
This commit is contained in:
@@ -769,6 +769,11 @@ class TestUploadRclone:
|
||||
cmd = mock_run.call_args[0][0]
|
||||
assert cmd[0] == "rclone"
|
||||
assert cmd[1] == "copyto"
|
||||
# SECURITY: Verify `--` end-of-options separator is present and precedes
|
||||
# the file path and destination to prevent option/argument injection.
|
||||
assert "--" in cmd
|
||||
fp_index = next(i for i, v in enumerate(cmd) if v == fp)
|
||||
assert cmd.index("--") < fp_index
|
||||
|
||||
def test_raises_on_rclone_nonzero_exit(self, tmp_path):
|
||||
fp = str(tmp_path / "doc.pdf")
|
||||
|
||||
Reference in New Issue
Block a user