fix(ocr): address code review - add subprocess security comment and type hints in tests

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
This commit is contained in:
copilot-swe-agent[bot]
2026-02-24 13:22:39 +00:00
parent fec032643b
commit 50573ec7be
2 changed files with 5 additions and 2 deletions
+3
View File
@@ -115,6 +115,9 @@ def embed_text_layer(input_pdf_path: str, output_pdf_path: str, *, language: str
logger.info(f"[embed_text_layer] Running: {' '.join(cmd)}")
# Security note: shell=False (the default) is used so no shell interpolation occurs.
# ocrmypdf_bin is resolved via shutil.which() (trusted system PATH).
# input_pdf_path / final_output are internal workdir paths, not raw user input.
try:
proc = subprocess.run(cmd, capture_output=True, text=True, timeout=600, check=False) # noqa: S603
except subprocess.TimeoutExpired:
+2 -2
View File
@@ -1131,7 +1131,7 @@ class TestEmbedTextLayer:
mock_proc.returncode = 0
mock_proc.stderr = ""
def fake_run(cmd, **kwargs): # noqa: ANN001
def fake_run(cmd: list[str], **kwargs: object) -> Mock:
# Simulate ocrmypdf writing to the temp output path.
out_path = cmd[-1]
with open(out_path, "wb") as fh:
@@ -1162,7 +1162,7 @@ class TestEmbedTextLayer:
real_mkstemp = __import__("tempfile").mkstemp
def fake_mkstemp(**kwargs): # noqa: ANN001
def fake_mkstemp(**kwargs: object) -> tuple[int, str]:
fd, path = real_mkstemp(**kwargs)
created_tmp.append(path)
# Write something so the cleanup code can find the file.