fix: resolve logical errors, bugs, and security issues across codebase

- Fix is_admin() method shadowing is_admin database column in User model
- Fix check_password() crash when password_hash is None (OAuth-only users)
- Fix SystemSetting.all_settings() formatting error (missing newline)
- Fix MAIL_PORT returning string instead of int in config
- Fix AUTOMATION_TOKEN config formatting (missing newline before comment)
- Fix path traversal vulnerability in serve_user_audio using realpath validation
- Fix weak auth in process.py, replace session check with @login_required
- Fix int() crash on non-numeric priority in import_songs.py
- Add timeout to SMTP connection in email_helper.py
- Add timeouts to external API requests in metadata.py and spotify_helper.py
- Fix security tests to properly reload config module
- Fix metadata test mock data key mismatch (preview_url -> spotify_preview_url)
- Add skip decorator to integration test requiring live API credentials

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
This commit is contained in:
copilot-swe-agent[bot]
2026-03-12 00:13:30 +00:00
parent 4685e05860
commit cfe000f030
15 changed files with 66 additions and 46 deletions
+3 -3
View File
@@ -61,7 +61,7 @@ def admin_required(f):
from functools import wraps
@wraps(f)
def decorated_function(*args, **kwargs):
if not current_user.is_authenticated or not current_user.is_admin():
if not current_user.is_authenticated or not current_user.is_admin:
flash('Admin access required.', 'danger')
return redirect(url_for('users.profile'))
return f(*args, **kwargs)
@@ -882,7 +882,7 @@ def use_refresh_token():
@login_required
def setup():
"""One-time setup route to promote the current user to admin"""
if current_user.is_admin():
if current_user.is_admin:
flash('You are already an administrator.', 'info')
return redirect(url_for('users.profile'))
@@ -1264,7 +1264,7 @@ def create_backup():
if automation_token == current_app.config.get('AUTOMATION_TOKEN'):
# Allow the request without authentication for automation
pass
elif not current_user.is_authenticated or not current_user.is_admin():
elif not current_user.is_authenticated or not current_user.is_admin:
return jsonify({"status": "error", "message": "Unauthorized"}), 401
# Get custom backup name if provided