feat: Add security hardening, agentic coding infrastructure, and test framework
- Add SECRET_KEY and ENCRYPTION_KEY validation on startup - Implement security headers middleware (X-Frame-Options, CSP, HSTS) - Add CSRF protection middleware - Create comprehensive GitHub issue templates and PR template - Add Makefile with common development tasks - Configure pre-commit hooks (black, ruff, mypy, bandit, detect-secrets) - Create docs/CODING_PATTERNS.md with best practices - Create docs/ERRORS.md documenting all error codes - Add Architecture Decision Records (ADR) for Celery and Fernet encryption - Create CHANGELOG.md for version tracking - Set up pytest test infrastructure with fixtures and factories - Add sample unit tests for security and config validation - Create CI/CD workflows (test, lint, security) - Add comprehensive TODO.md with milestones and progress tracking Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
This commit is contained in:
@@ -0,0 +1,42 @@
|
||||
---
|
||||
name: Bug Report
|
||||
about: Report a bug to help us improve
|
||||
title: '[BUG] '
|
||||
labels: bug
|
||||
assignees: ''
|
||||
---
|
||||
|
||||
## Bug Description
|
||||
<!-- A clear and concise description of what the bug is -->
|
||||
|
||||
## Steps to Reproduce
|
||||
1. Go to '...'
|
||||
2. Click on '...'
|
||||
3. See error
|
||||
|
||||
## Expected Behavior
|
||||
<!-- What you expected to happen -->
|
||||
|
||||
## Actual Behavior
|
||||
<!-- What actually happened -->
|
||||
|
||||
## Environment
|
||||
- **Component**: [e.g., Backend API, Worker, Docker, pop3_forwarder.py]
|
||||
- **Version**: [e.g., v1.0.0, main branch]
|
||||
- **Deployment**: [e.g., Docker, Kubernetes, local]
|
||||
- **OS**: [e.g., Ubuntu 22.04, macOS, Windows]
|
||||
- **Python Version**: [e.g., 3.11]
|
||||
|
||||
## Logs/Error Messages
|
||||
```
|
||||
Paste relevant logs or error messages here
|
||||
```
|
||||
|
||||
## Additional Context
|
||||
<!-- Any other context about the problem -->
|
||||
|
||||
## Possible Solution
|
||||
<!-- Optional: suggest a fix or workaround -->
|
||||
|
||||
## Related Issues
|
||||
<!-- Link any related issues -->
|
||||
@@ -0,0 +1,38 @@
|
||||
---
|
||||
name: Feature Request
|
||||
about: Suggest a new feature or enhancement
|
||||
title: '[FEATURE] '
|
||||
labels: enhancement
|
||||
assignees: ''
|
||||
---
|
||||
|
||||
## Feature Description
|
||||
<!-- A clear and concise description of the feature -->
|
||||
|
||||
## Problem Statement
|
||||
<!-- What problem does this solve? -->
|
||||
|
||||
## Proposed Solution
|
||||
<!-- How would you like this to work? -->
|
||||
|
||||
## Alternative Solutions
|
||||
<!-- Any alternative approaches you've considered -->
|
||||
|
||||
## Use Case
|
||||
<!-- Describe a specific scenario where this would be useful -->
|
||||
|
||||
## Implementation Notes
|
||||
<!-- Optional: Technical details, API design, architecture considerations -->
|
||||
|
||||
## Acceptance Criteria
|
||||
<!-- How would we know this feature is complete? -->
|
||||
- [ ] Criterion 1
|
||||
- [ ] Criterion 2
|
||||
- [ ] Documentation updated
|
||||
- [ ] Tests added
|
||||
|
||||
## Priority
|
||||
<!-- Low / Medium / High / Critical -->
|
||||
|
||||
## Related To
|
||||
<!-- Link to roadmap items, other issues, or discussions -->
|
||||
@@ -0,0 +1,49 @@
|
||||
---
|
||||
name: Test Needed
|
||||
about: Identify code that needs test coverage
|
||||
title: '[TEST] '
|
||||
labels: testing, help wanted
|
||||
assignees: ''
|
||||
---
|
||||
|
||||
## Code to Test
|
||||
<!-- What code needs test coverage? -->
|
||||
- **File**: `path/to/file.py`
|
||||
- **Function/Class**: `function_name` or `ClassName`
|
||||
- **Lines**: [e.g., lines 50-100]
|
||||
|
||||
## Current Coverage
|
||||
<!-- What's the current test coverage for this code? -->
|
||||
- [ ] No tests exist
|
||||
- [ ] Partial coverage (describe what's tested)
|
||||
|
||||
## Test Type Needed
|
||||
- [ ] Unit tests
|
||||
- [ ] Integration tests
|
||||
- [ ] End-to-end tests
|
||||
- [ ] Performance tests
|
||||
- [ ] Security tests
|
||||
|
||||
## Test Scenarios
|
||||
<!-- List specific scenarios that should be tested -->
|
||||
1. Happy path:
|
||||
2. Error handling:
|
||||
3. Edge cases:
|
||||
4. Boundary conditions:
|
||||
|
||||
## Dependencies
|
||||
<!-- What needs to be mocked or stubbed? -->
|
||||
- External API:
|
||||
- Database:
|
||||
- File system:
|
||||
- Environment variables:
|
||||
|
||||
## Acceptance Criteria
|
||||
- [ ] All scenarios covered
|
||||
- [ ] Edge cases tested
|
||||
- [ ] Error paths tested
|
||||
- [ ] Coverage increased by X%
|
||||
- [ ] Tests documented
|
||||
|
||||
## Related Code
|
||||
<!-- Link to related functions, classes, or issues -->
|
||||
@@ -0,0 +1,71 @@
|
||||
## Description
|
||||
<!-- Provide a clear description of the changes -->
|
||||
|
||||
## Related Issue
|
||||
<!-- Link to the issue this PR addresses -->
|
||||
Closes #
|
||||
|
||||
## Type of Change
|
||||
- [ ] Bug fix (non-breaking change which fixes an issue)
|
||||
- [ ] New feature (non-breaking change which adds functionality)
|
||||
- [ ] Breaking change (fix or feature that would cause existing functionality to not work as expected)
|
||||
- [ ] Documentation update
|
||||
- [ ] Refactoring (no functional changes)
|
||||
- [ ] Performance improvement
|
||||
- [ ] Security fix
|
||||
|
||||
## Changes Made
|
||||
<!-- List the main changes -->
|
||||
-
|
||||
-
|
||||
-
|
||||
|
||||
## Testing
|
||||
<!-- Describe the tests you ran -->
|
||||
- [ ] Unit tests added/updated
|
||||
- [ ] Integration tests added/updated
|
||||
- [ ] Manual testing completed
|
||||
- [ ] All tests pass locally
|
||||
|
||||
## Security Considerations
|
||||
<!-- Any security implications? -->
|
||||
- [ ] No security impact
|
||||
- [ ] Security scan passed
|
||||
- [ ] Credentials properly handled
|
||||
- [ ] Input validation added
|
||||
- [ ] Authentication/authorization checked
|
||||
|
||||
## Documentation
|
||||
- [ ] Code comments added/updated
|
||||
- [ ] README updated
|
||||
- [ ] API documentation updated
|
||||
- [ ] CHANGELOG updated
|
||||
- [ ] Migration guide created (if breaking change)
|
||||
|
||||
## Checklist
|
||||
- [ ] Code follows the project's style guidelines
|
||||
- [ ] Self-review completed
|
||||
- [ ] No new warnings introduced
|
||||
- [ ] Tests added for new functionality
|
||||
- [ ] All existing tests pass
|
||||
- [ ] Documentation is up-to-date
|
||||
- [ ] No secrets or credentials committed
|
||||
|
||||
## Screenshots (if applicable)
|
||||
<!-- Add screenshots for UI changes -->
|
||||
|
||||
## Performance Impact
|
||||
<!-- Any performance implications? -->
|
||||
- [ ] No performance impact
|
||||
- [ ] Performance improved
|
||||
- [ ] Benchmarks added
|
||||
|
||||
## Deployment Notes
|
||||
<!-- Special deployment instructions? -->
|
||||
- [ ] No special deployment needed
|
||||
- [ ] Database migration required
|
||||
- [ ] Environment variables added/changed
|
||||
- [ ] Configuration changes needed
|
||||
|
||||
## Additional Context
|
||||
<!-- Any other information -->
|
||||
@@ -0,0 +1,38 @@
|
||||
name: Code Quality
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ main, develop ]
|
||||
pull_request:
|
||||
branches: [ main, develop ]
|
||||
|
||||
jobs:
|
||||
lint:
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@v5
|
||||
with:
|
||||
python-version: '3.11'
|
||||
|
||||
- name: Install dependencies
|
||||
run: |
|
||||
python -m pip install --upgrade pip
|
||||
pip install black ruff mypy
|
||||
pip install -r backend/requirements.txt
|
||||
|
||||
- name: Check code formatting with Black
|
||||
run: |
|
||||
black --check backend/
|
||||
|
||||
- name: Lint with Ruff
|
||||
run: |
|
||||
ruff check backend/
|
||||
|
||||
- name: Type check with mypy
|
||||
run: |
|
||||
mypy backend/app --ignore-missing-imports
|
||||
continue-on-error: true
|
||||
@@ -0,0 +1,45 @@
|
||||
name: Security Scan
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ main, develop ]
|
||||
pull_request:
|
||||
branches: [ main, develop ]
|
||||
schedule:
|
||||
- cron: '0 0 * * 0' # Weekly on Sunday
|
||||
|
||||
jobs:
|
||||
security:
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@v5
|
||||
with:
|
||||
python-version: '3.11'
|
||||
|
||||
- name: Install dependencies
|
||||
run: |
|
||||
python -m pip install --upgrade pip
|
||||
pip install bandit safety
|
||||
pip install -r backend/requirements.txt
|
||||
|
||||
- name: Run Bandit security scan
|
||||
run: |
|
||||
bandit -r backend/app -ll
|
||||
continue-on-error: true
|
||||
|
||||
- name: Check dependencies for known vulnerabilities
|
||||
run: |
|
||||
safety check --json
|
||||
continue-on-error: true
|
||||
|
||||
- name: Run CodeQL Analysis
|
||||
uses: github/codeql-action/init@v3
|
||||
with:
|
||||
languages: python
|
||||
|
||||
- name: Perform CodeQL Analysis
|
||||
uses: github/codeql-action/analyze@v3
|
||||
@@ -0,0 +1,69 @@
|
||||
name: Tests
|
||||
|
||||
on:
|
||||
push:
|
||||
branches: [ main, develop ]
|
||||
pull_request:
|
||||
branches: [ main, develop ]
|
||||
|
||||
jobs:
|
||||
test:
|
||||
runs-on: ubuntu-latest
|
||||
|
||||
services:
|
||||
postgres:
|
||||
image: postgres:15
|
||||
env:
|
||||
POSTGRES_USER: postgres
|
||||
POSTGRES_PASSWORD: postgres
|
||||
POSTGRES_DB: pop3_forwarder_test
|
||||
options: >-
|
||||
--health-cmd pg_isready
|
||||
--health-interval 10s
|
||||
--health-timeout 5s
|
||||
--health-retries 5
|
||||
ports:
|
||||
- 5432:5432
|
||||
|
||||
redis:
|
||||
image: redis:7-alpine
|
||||
options: >-
|
||||
--health-cmd "redis-cli ping"
|
||||
--health-interval 10s
|
||||
--health-timeout 5s
|
||||
--health-retries 5
|
||||
ports:
|
||||
- 6379:6379
|
||||
|
||||
steps:
|
||||
- uses: actions/checkout@v4
|
||||
|
||||
- name: Set up Python
|
||||
uses: actions/setup-python@v5
|
||||
with:
|
||||
python-version: '3.11'
|
||||
cache: 'pip'
|
||||
|
||||
- name: Install dependencies
|
||||
run: |
|
||||
python -m pip install --upgrade pip
|
||||
pip install -r backend/requirements.txt
|
||||
pip install pytest pytest-asyncio pytest-cov httpx
|
||||
|
||||
- name: Run tests with coverage
|
||||
env:
|
||||
DATABASE_URL: postgresql+asyncpg://postgres:postgres@localhost:5432/pop3_forwarder_test
|
||||
REDIS_URL: redis://localhost:6379/0
|
||||
SECRET_KEY: test-secret-key-for-ci-cd-at-least-32-chars
|
||||
ENCRYPTION_KEY: test-encryption-key-for-ci-cd-at-least-32-chars
|
||||
run: |
|
||||
cd backend
|
||||
pytest tests/ -v --cov=app --cov-report=xml --cov-report=term
|
||||
|
||||
- name: Upload coverage to Codecov
|
||||
uses: codecov/codecov-action@v3
|
||||
with:
|
||||
file: ./backend/coverage.xml
|
||||
flags: unittests
|
||||
name: codecov-umbrella
|
||||
fail_ci_if_error: false
|
||||
Reference in New Issue
Block a user