feedBack/tests/test_version_endpoint.py
Bret Mogilefsky af2949677a
rename: slopsmith → feedBack, byron → got-feedBack (#537)
* Update GitHub repo references from feedback* to feedBack*

* rename: slopsmith -> feedBack, byron -> got-feedBack

Renames across the entire codebase:
- slopsmith/Slopsmith/SLOPSMITH/SlopSmith -> feedBack/FeedBack/FEEDBACK/FeedBack
- byron/Byron/Byrongamatos -> got-feedBack/got-feedBack/got-feedBack
- /home/byron/ -> /opt/got-feedBack/
- byron@ougsoft.com -> hi@got-feedBack.org
- github.com/byrongamatos/ -> github.com/got-feedback/
- com.byron. -> com.got-feedback.
- SLOPSMITH_ env vars -> FEEDBACK_ with backward-compat fallback
- Protocol/storage strings migrated with read-old/write-new pattern
- window.slopsmith JS API -> window.feedBack (canonical) + backward-compat alias

Refs: #rename-slopsmith

* rename: complete regen against current main + fix backward-compat alias

Regenerated the slopsmith->feedBack / byron->got-feedBack rename on top of
current main (3 commits had landed since the branch: #572/#554/#574),
resolving the four content conflicts in favour of main's newer content
(autoplay/auto-exit, accuracy-badge, Virtuoso re-home, feedpak badge).

Completion fixes on top of the mechanical rename:
- Re-apply rename to post-branch content the original rename never saw:
  window.slopsmith(.Tour) consumers in lessons.js / notifications.js /
  onboarding-tour.js, and the matching JS + python tests (autoplay_exit,
  progression_*, test_feedpak_extension FEEDBACK_* env vars). The test env
  vars now match server.py (which reads FEEDBACK_SYNC_STARTUP /
  FEEDBACK_SKIP_STARTUP_TASKS), so the sync-startup test exercises the real
  path again.
- Restore the window.slopsmith backward-compat alias dropped during conflict
  resolution, and move the bus aliases to AFTER the _feedBackExisting merge
  block so they reference the fully-assembled object (also fixes the
  loop_api.test.js API-surface regex, which the original PR latently broke).
- Drop the stray empty data/web_library.db (runtime DB lives in CONFIG_DIR)
  and gitignore it.
- Fix stale tone-source test: feed[dB]ack -> fee[dB]ack to match shipped
  source labels.

Verified locally (org CI billing-blocked): JS 819/819 pass; pytest 1669
passed / 1683 collected with 0 import errors; zero residual slopsmith/byron
except the two intentional window.slopsmith aliases.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* rename: implement advertised backward-compat + prune dead community plugins

Address gaps where PR #537's "Backward compatibility" section was advertised
but not implemented, and clean up the community plugin list.

Env vars (FEEDBACK_* canonical, legacy SLOPSMITH_* honoured):
- New lib/env_compat.py (getenv_compat / env_flag_compat) + tests. server.py
  (_env_flag + all FEEDBACK_* reads), diagnostics_hardware, gp2midi and
  tailwind_rebuild now resolve the legacy alias, so existing SLOPSMITH_UI /
  SLOPSMITH_PLUGINS_DIR / etc. deployments keep working.
- Fix the rename collapsing plugins/__init__.py and minigames/routes.py from
  `FEEDBACK_PLUGINS_DIR or SLOPSMITH_PLUGINS_DIR` into a redundant
  `FEEDBACK_ or FEEDBACK_` (the fallback was silently lost).

Storage (app.js update-channel):
- Read feedBack-update-channel, fall back to legacy slopsmith-update-channel,
  and clear the legacy key on write — so a user's update-channel preference
  survives the rename instead of resetting to "stable".

Community plugin list (README): the rename rewrote third-party repo URLs we
don't own. Probed every one; their owners never renamed, so:
- Restore the 13 live community plugins to their real slopsmith-* names.
- Prune 6 that are 404 to the public (topkoa splitscreen/stems, OmikronApex
  tuner, Jafz2001 nam-rig-builder, DeathlySin song-preview, Erikcb91 shuffle).
- Fix a pre-existing Guitar Theory clone-command typo (nam-tone -> guitar-theory).

Verified: env_compat 7/7, JS 819/819, pytest 1690 collected / 0 import errors,
rename-sensitive + startup suites green.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: byrongamatos <xasiklas@gmail.com>
Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-06-23 11:03:01 +02:00

175 lines
6.7 KiB
Python

"""Tests for the `GET /api/version` endpoint.
Covers the configurable `APP_SOURCE_URL` / `APP_LICENSE_URL` env vars
introduced during the AGPL-3.0 relicense: the default values, the
empty/whitespace fallback, trailing-slash stripping, and — most importantly
— the URL guard (http(s) scheme + non-empty host) that prevents a
misconfigured/hostile env var from smuggling `javascript:` / `data:` /
malformed URLs onto the About-page `<a href>`.
"""
import importlib
import sys
import pytest
from fastapi.testclient import TestClient
DEFAULT_SOURCE_URL = "https://github.com/got-feedback/feedBack"
DEFAULT_LICENSE_URL = DEFAULT_SOURCE_URL + "/blob/main/LICENSE"
@pytest.fixture()
def client(tmp_path, monkeypatch):
"""Minimal server TestClient, with background I/O suppressed.
Mirrors the fixture pattern used by `test_correlation_id.py` — fresh
server import per test so module-level env captures (if any are ever
added) don't leak between tests.
"""
monkeypatch.setenv("CONFIG_DIR", str(tmp_path))
monkeypatch.setenv("FEEDBACK_SYNC_STARTUP", "1")
# Clear ambient overrides so the default-URL assertions are deterministic
# regardless of the caller's shell / CI environment. Individual tests
# re-set these via their own monkeypatch calls as needed.
monkeypatch.delenv("APP_SOURCE_URL", raising=False)
monkeypatch.delenv("APP_LICENSE_URL", raising=False)
sys.modules.pop("server", None)
server = importlib.import_module("server")
monkeypatch.setattr(server, "load_plugins", lambda *a, **kw: None)
monkeypatch.setattr(server, "startup_scan", lambda: None)
with TestClient(server.app) as tc:
try:
yield tc
finally:
conn = getattr(getattr(server, "meta_db", None), "conn", None)
if conn is not None:
conn.close()
def _get(client):
r = client.get("/api/version")
assert r.status_code == 200, r.text
return r.json()
def test_default_urls_when_envs_unset(client, monkeypatch):
"""No env vars set → both URLs are the documented defaults."""
monkeypatch.delenv("APP_SOURCE_URL", raising=False)
monkeypatch.delenv("APP_LICENSE_URL", raising=False)
body = _get(client)
assert body["source_url"] == DEFAULT_SOURCE_URL
assert body["license_url"] == DEFAULT_LICENSE_URL
assert "version" in body
def test_empty_source_url_falls_back_to_default(client, monkeypatch):
monkeypatch.setenv("APP_SOURCE_URL", "")
body = _get(client)
assert body["source_url"] == DEFAULT_SOURCE_URL
assert body["license_url"] == DEFAULT_LICENSE_URL
def test_whitespace_source_url_falls_back_to_default(client, monkeypatch):
monkeypatch.setenv("APP_SOURCE_URL", " \t ")
body = _get(client)
assert body["source_url"] == DEFAULT_SOURCE_URL
def test_configured_source_url_used(client, monkeypatch):
monkeypatch.setenv("APP_SOURCE_URL", "https://gitlab.example.com/me/fork")
body = _get(client)
assert body["source_url"] == "https://gitlab.example.com/me/fork"
# license_url defaults to the GitHub-style suffix off the configured source
assert body["license_url"] == "https://gitlab.example.com/me/fork/blob/main/LICENSE"
def test_source_url_trailing_slash_stripped(client, monkeypatch):
monkeypatch.setenv("APP_SOURCE_URL", "https://example.com/repo/")
body = _get(client)
assert body["source_url"] == "https://example.com/repo"
assert body["license_url"] == "https://example.com/repo/blob/main/LICENSE"
@pytest.mark.parametrize(
"hostile",
[
"javascript:alert(1)",
"JAVASCRIPT:alert(1)", # case-insensitive scheme guard
"data:text/html,<script>alert(1)</script>",
"vbscript:msgbox(1)",
"file:///etc/passwd",
"ftp://example.com/repo",
"//evil.example.com/repo", # protocol-relative
"evil.example.com/repo", # no scheme
"https://", # http(s) prefix but no host
"http://",
"https:///path/only", # empty host, has path
"http://:80/path", # port-only "netloc", empty hostname
"https://:8080",
],
)
def test_non_http_source_url_rejected(client, monkeypatch, hostile):
"""Non-http(s) APP_SOURCE_URL values fall back to the safe default — the
UI assigns the result straight to `<a href>`, so this is XSS-relevant.
"""
monkeypatch.setenv("APP_SOURCE_URL", hostile)
body = _get(client)
assert body["source_url"] == DEFAULT_SOURCE_URL
# license_url must follow the (safe) source, never the hostile input
assert body["license_url"] == DEFAULT_LICENSE_URL
def test_configured_license_url_used(client, monkeypatch):
"""APP_LICENSE_URL overrides the constructed GitHub-style default — for
non-GitHub hosts or non-`main` default branches.
"""
monkeypatch.setenv("APP_LICENSE_URL", "https://gitlab.example.com/me/fork/-/blob/trunk/LICENSE")
body = _get(client)
assert body["license_url"] == "https://gitlab.example.com/me/fork/-/blob/trunk/LICENSE"
def test_license_url_overrides_independently_of_source_url(client, monkeypatch):
"""When both envs are set, APP_LICENSE_URL wins (doesn't derive from source)."""
monkeypatch.setenv("APP_SOURCE_URL", "https://example.com/src")
monkeypatch.setenv("APP_LICENSE_URL", "https://example.org/license.txt")
body = _get(client)
assert body["source_url"] == "https://example.com/src"
assert body["license_url"] == "https://example.org/license.txt"
def test_license_url_trailing_slash_stripped(client, monkeypatch):
monkeypatch.setenv("APP_LICENSE_URL", "https://example.com/license/")
body = _get(client)
assert body["license_url"] == "https://example.com/license"
@pytest.mark.parametrize(
"hostile",
[
"javascript:alert(1)",
"data:text/html,foo",
"vbscript:msgbox(1)",
"file:///etc/passwd",
"//evil.example.com/license",
"license.html", # no scheme
"https://", # http(s) prefix but no host
"http://",
"https:///path", # empty host, has path
"http://:80/path", # port-only "netloc", empty hostname
"https://:8080",
],
)
def test_non_http_license_url_rejected(client, monkeypatch, hostile):
monkeypatch.setenv("APP_LICENSE_URL", hostile)
body = _get(client)
# Falls back to source_url + /blob/main/LICENSE (the constructed default)
assert body["license_url"] == DEFAULT_LICENSE_URL
def test_empty_license_url_falls_back_to_constructed(client, monkeypatch):
monkeypatch.setenv("APP_SOURCE_URL", "https://example.com/repo")
monkeypatch.setenv("APP_LICENSE_URL", "")
body = _get(client)
assert body["license_url"] == "https://example.com/repo/blob/main/LICENSE"