fix: resolve logical errors, bugs, and security issues across codebase

- Fix is_admin() method shadowing is_admin database column in User model
- Fix check_password() crash when password_hash is None (OAuth-only users)
- Fix SystemSetting.all_settings() formatting error (missing newline)
- Fix MAIL_PORT returning string instead of int in config
- Fix AUTOMATION_TOKEN config formatting (missing newline before comment)
- Fix path traversal vulnerability in serve_user_audio using realpath validation
- Fix weak auth in process.py, replace session check with @login_required
- Fix int() crash on non-numeric priority in import_songs.py
- Add timeout to SMTP connection in email_helper.py
- Add timeouts to external API requests in metadata.py and spotify_helper.py
- Fix security tests to properly reload config module
- Fix metadata test mock data key mismatch (preview_url -> spotify_preview_url)
- Add skip decorator to integration test requiring live API credentials

Co-authored-by: christianlouis <361235+christianlouis@users.noreply.github.com>
This commit is contained in:
copilot-swe-agent[bot]
2026-03-12 00:13:30 +00:00
parent 4685e05860
commit cfe000f030
15 changed files with 66 additions and 46 deletions
+23 -16
View File
@@ -2,6 +2,7 @@
import pytest
import os
import re
import importlib
class TestSecurityConfiguration:
@@ -14,14 +15,17 @@ class TestSecurityConfiguration:
if secret_key:
del os.environ['SECRET_KEY']
# Import should fail if SECRET_KEY not set
with pytest.raises(ValueError, match="SECRET_KEY environment variable must be set"):
from musicround.config import Config
_ = Config.SECRET_KEY
# Restore environment
if secret_key:
os.environ['SECRET_KEY'] = secret_key
try:
# Force module reload to re-evaluate class-level checks
import musicround.config
with pytest.raises(ValueError, match="SECRET_KEY environment variable must be set"):
importlib.reload(musicround.config)
finally:
# Restore environment
if secret_key:
os.environ['SECRET_KEY'] = secret_key
# Reload with correct env so other tests work
importlib.reload(musicround.config)
def test_automation_token_required(self):
"""Test that AUTOMATION_TOKEN must be set."""
@@ -30,14 +34,17 @@ class TestSecurityConfiguration:
if token:
del os.environ['AUTOMATION_TOKEN']
# Import should fail if AUTOMATION_TOKEN not set
with pytest.raises(ValueError, match="AUTOMATION_TOKEN environment variable must be set"):
from musicround.config import Config
_ = Config.AUTOMATION_TOKEN
# Restore environment
if token:
os.environ['AUTOMATION_TOKEN'] = token
try:
# Force module reload to re-evaluate class-level checks
import musicround.config
with pytest.raises(ValueError, match="AUTOMATION_TOKEN environment variable must be set"):
importlib.reload(musicround.config)
finally:
# Restore environment
if token:
os.environ['AUTOMATION_TOKEN'] = token
# Reload with correct env so other tests work
importlib.reload(musicround.config)
def test_no_credentials_in_code(self):
"""Test that no credentials are hardcoded in Python files."""