mirror of
https://github.com/Matysh/houseplan-card
synced 2026-07-31 08:28:31 +00:00
feat v1.12.0: Quality Scale conformance (phases 7-8)
- entry.runtime_data (HouseplanData in store.py) instead of hass.data; WS answers not_ready without a loaded entry - test-before-setup (ConfigEntryNotReady), async_unload_entry, async_remove_entry (Lovelace resource cleanup), single_config_entry in manifest - Store minor_version + migration hook; diagnostics.py (redacted); repairs (broken_plan issues, en/ru); system_health.py; strings.json - quality_scale.yaml self-assessment; HA-harness tests (config flow, WS, upload) in CI on py3.13; CI backend job updated
This commit is contained in:
@@ -0,0 +1,49 @@
|
||||
"""HTTP upload endpoint tests (CI)."""
|
||||
from aiohttp import FormData
|
||||
from homeassistant.core import HomeAssistant
|
||||
from pytest_homeassistant_custom_component.common import MockConfigEntry
|
||||
from pytest_homeassistant_custom_component.typing import ClientSessionGenerator
|
||||
|
||||
from custom_components.houseplan.const import DOMAIN
|
||||
|
||||
|
||||
async def _setup(hass: HomeAssistant) -> None:
|
||||
entry = MockConfigEntry(domain=DOMAIN, title="House Plan", data={}, options={})
|
||||
entry.add_to_hass(hass)
|
||||
assert await hass.config_entries.async_setup(entry.entry_id)
|
||||
await hass.async_block_till_done()
|
||||
|
||||
|
||||
async def test_upload_ok(hass: HomeAssistant, hass_client: ClientSessionGenerator) -> None:
|
||||
await _setup(hass)
|
||||
client = await hass_client()
|
||||
fd = FormData()
|
||||
fd.add_field("marker_id", "m1")
|
||||
fd.add_field("file", b"%PDF-1.4 test", filename="manual.pdf", content_type="application/pdf")
|
||||
resp = await client.post("/api/houseplan/upload", data=fd)
|
||||
assert resp.status == 200
|
||||
body = await resp.json()
|
||||
assert body["ok"] and body["url"].startswith("/houseplan_files/files/m1/manual.pdf?v=")
|
||||
|
||||
|
||||
async def test_upload_bad_ext(hass: HomeAssistant, hass_client: ClientSessionGenerator) -> None:
|
||||
await _setup(hass)
|
||||
client = await hass_client()
|
||||
fd = FormData()
|
||||
fd.add_field("file", b"MZ", filename="evil.exe")
|
||||
resp = await client.post("/api/houseplan/upload", data=fd)
|
||||
assert resp.status == 400
|
||||
assert (await resp.json())["error"] == "bad_ext"
|
||||
|
||||
|
||||
async def test_upload_traversal_sanitized(hass: HomeAssistant, hass_client: ClientSessionGenerator) -> None:
|
||||
await _setup(hass)
|
||||
client = await hass_client()
|
||||
fd = FormData()
|
||||
fd.add_field("marker_id", "../../etc")
|
||||
fd.add_field("file", b"x", filename="../..//passwd.txt")
|
||||
resp = await client.post("/api/houseplan/upload", data=fd)
|
||||
assert resp.status == 200
|
||||
body = await resp.json()
|
||||
# both the marker dir and the filename must be flattened to safe names
|
||||
assert ".." not in body["url"]
|
||||
Reference in New Issue
Block a user