Re-audit round 4: 5 blind reviewers over the new surface — 24 fixes, +28 tests
The findings clustered exactly where prediction said: the unreviewed web layer. The big ones: decisions made while an extract/resolve job runs are now refused with a 409 (the job's end-of-run rewrite from a start-of-run snapshot would silently revert them); a cross-origin guard blocks preflight-free mutations from hostile webpages (bodyless run triggers, cross-site photo form posts); the JobRunner sets terminal status in a finally catching BaseException (a greenlet death could wedge every future run behind 409s) and writes tracebacks into the visible job log; and a boot token lets clients accept the revision reset after a server restart instead of freezing forever. Even the thrice-audited core yielded one HIGH: an unvetoed bare typo-read sibling of a confident row duplicated its add when the game wasn't in the collection — diff now treats it as satisfied. Second-copy adds carry a flag through to_add.csv and the upload log so verify honestly reports them unverifiable instead of OK. Also: merged_into chains collapse transitively; diff/enrich treat a BGG queue timeout like a missing token; enrich prunes orphaned games.json keys; the wizard shell-quotes .env values and creates the file 0600 from the first byte; fsio stats the tmp inode before replace and uses unique tmp names; an explicit missing --config errors; storage state is owner-only; extract re-extracts corrupt caches, aborts on 3 identical failures, and exits nonzero when nothing succeeded; torn JSON artifacts degrade with in-browser warnings instead of 500ing every page; photo uploads are atomic with cache-invalidation ordered first; the pipeline page computes `running` before the buttons that depend on it; the photo dropzone alerts on network failure; and lost-contact banners clear on recovery everywhere. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
@@ -466,3 +466,28 @@ def test_run_upload_verify_wiring(tmp_path, capsys):
|
||||
)
|
||||
assert client.calls == [{"username": "tester", "refresh": True}]
|
||||
assert "Verification OK" in capsys.readouterr().out
|
||||
|
||||
|
||||
def test_verify_marks_second_copy_adds_unverifiable():
|
||||
log = [
|
||||
{**_log_row(action="add", bgg_id="13", status="added"), "second_copy": "1"},
|
||||
]
|
||||
problems = verify_uploads(log, [_item(13, 900, version_id=7)])
|
||||
(problem,) = problems
|
||||
assert "can't be verified" in problem and "confirm by eye" in problem
|
||||
|
||||
|
||||
def test_drift_warning_suppressed_for_multi_edition_partial_run(tmp_path, capsys):
|
||||
# run 1 added edition A; edition B is still queued alongside A's row:
|
||||
# that's a two-edition game mid-way, not a re-review drift
|
||||
cfg = _cfg(tmp_path)
|
||||
_seed_data(
|
||||
tmp_path,
|
||||
to_add=[
|
||||
_add_row(bgg_id="13", name="Catan", version_id="1", version_name="A"),
|
||||
_add_row(bgg_id="13", name="Catan", version_id="2", version_name="B"),
|
||||
],
|
||||
log=[_log_row(action="add", bgg_id="13", version_id="1", status="added")],
|
||||
)
|
||||
run_upload(cfg, uploader=FakeUploader(), sleep=lambda s: None, now=_now)
|
||||
assert "manual correction" not in capsys.readouterr().out
|
||||
|
||||
Reference in New Issue
Block a user