mirror of
https://github.com/got-feedBack/feedBack.git
synced 2026-08-11 11:19:24 +00:00
* Update GitHub repo references from feedback* to feedBack* * rename: slopsmith -> feedBack, byron -> got-feedBack Renames across the entire codebase: - slopsmith/Slopsmith/SLOPSMITH/SlopSmith -> feedBack/FeedBack/FEEDBACK/FeedBack - byron/Byron/Byrongamatos -> got-feedBack/got-feedBack/got-feedBack - /home/byron/ -> /opt/got-feedBack/ - byron@ougsoft.com -> hi@got-feedBack.org - github.com/byrongamatos/ -> github.com/got-feedback/ - com.byron. -> com.got-feedback. - SLOPSMITH_ env vars -> FEEDBACK_ with backward-compat fallback - Protocol/storage strings migrated with read-old/write-new pattern - window.slopsmith JS API -> window.feedBack (canonical) + backward-compat alias Refs: #rename-slopsmith * rename: complete regen against current main + fix backward-compat alias Regenerated the slopsmith->feedBack / byron->got-feedBack rename on top of current main (3 commits had landed since the branch: #572/#554/#574), resolving the four content conflicts in favour of main's newer content (autoplay/auto-exit, accuracy-badge, Virtuoso re-home, feedpak badge). Completion fixes on top of the mechanical rename: - Re-apply rename to post-branch content the original rename never saw: window.slopsmith(.Tour) consumers in lessons.js / notifications.js / onboarding-tour.js, and the matching JS + python tests (autoplay_exit, progression_*, test_feedpak_extension FEEDBACK_* env vars). The test env vars now match server.py (which reads FEEDBACK_SYNC_STARTUP / FEEDBACK_SKIP_STARTUP_TASKS), so the sync-startup test exercises the real path again. - Restore the window.slopsmith backward-compat alias dropped during conflict resolution, and move the bus aliases to AFTER the _feedBackExisting merge block so they reference the fully-assembled object (also fixes the loop_api.test.js API-surface regex, which the original PR latently broke). - Drop the stray empty data/web_library.db (runtime DB lives in CONFIG_DIR) and gitignore it. - Fix stale tone-source test: feed[dB]ack -> fee[dB]ack to match shipped source labels. Verified locally (org CI billing-blocked): JS 819/819 pass; pytest 1669 passed / 1683 collected with 0 import errors; zero residual slopsmith/byron except the two intentional window.slopsmith aliases. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> * rename: implement advertised backward-compat + prune dead community plugins Address gaps where PR #537's "Backward compatibility" section was advertised but not implemented, and clean up the community plugin list. Env vars (FEEDBACK_* canonical, legacy SLOPSMITH_* honoured): - New lib/env_compat.py (getenv_compat / env_flag_compat) + tests. server.py (_env_flag + all FEEDBACK_* reads), diagnostics_hardware, gp2midi and tailwind_rebuild now resolve the legacy alias, so existing SLOPSMITH_UI / SLOPSMITH_PLUGINS_DIR / etc. deployments keep working. - Fix the rename collapsing plugins/__init__.py and minigames/routes.py from `FEEDBACK_PLUGINS_DIR or SLOPSMITH_PLUGINS_DIR` into a redundant `FEEDBACK_ or FEEDBACK_` (the fallback was silently lost). Storage (app.js update-channel): - Read feedBack-update-channel, fall back to legacy slopsmith-update-channel, and clear the legacy key on write — so a user's update-channel preference survives the rename instead of resetting to "stable". Community plugin list (README): the rename rewrote third-party repo URLs we don't own. Probed every one; their owners never renamed, so: - Restore the 13 live community plugins to their real slopsmith-* names. - Prune 6 that are 404 to the public (topkoa splitscreen/stems, OmikronApex tuner, Jafz2001 nam-rig-builder, DeathlySin song-preview, Erikcb91 shuffle). - Fix a pre-existing Guitar Theory clone-command typo (nam-tone -> guitar-theory). Verified: env_compat 7/7, JS 819/819, pytest 1690 collected / 0 import errors, rename-sensitive + startup suites green. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> --------- Co-authored-by: byrongamatos <xasiklas@gmail.com> Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
113 lines
4.1 KiB
Python
113 lines
4.1 KiB
Python
"""Endpoint tests for path-traversal rejection on the sloppak file route.
|
|
|
|
`GET /api/sloppak/{filename:path}/file/{rel_path:path}` serves files from
|
|
inside a sloppak bundle. Both params are attacker-controlled `:path`
|
|
segments, so the handler must (1) contain `filename` under DLC_DIR,
|
|
(2) only serve actual `.sloppak` bundles, and (3) contain `rel_path`
|
|
inside the resolved sloppak. These tests pin that contract so future
|
|
refactors of `resolve_source_dir`/routing can't reintroduce the
|
|
arbitrary-file-read class of bug (feedBack#638).
|
|
"""
|
|
|
|
import importlib
|
|
import sys
|
|
|
|
import pytest
|
|
from fastapi.testclient import TestClient
|
|
|
|
|
|
@pytest.fixture()
|
|
def dlc_client(tmp_path, monkeypatch):
|
|
"""Spin up a TestClient with a temp DLC_DIR; sync startup, no scan."""
|
|
dlc = tmp_path / "dlc"
|
|
dlc.mkdir()
|
|
config = tmp_path / "cfg"
|
|
config.mkdir()
|
|
monkeypatch.setenv("DLC_DIR", str(dlc))
|
|
monkeypatch.setenv("CONFIG_DIR", str(config))
|
|
monkeypatch.setenv("FEEDBACK_SYNC_STARTUP", "1")
|
|
sys.modules.pop("server", None)
|
|
server = importlib.import_module("server")
|
|
# The sloppak source-dir cache is module-level and survives the
|
|
# server re-import; clear it so a prior test's filename key can't
|
|
# shadow this test's temp DLC_DIR.
|
|
server.sloppak_mod._source_cache.clear()
|
|
monkeypatch.setattr(server, "load_plugins", lambda *a, **kw: None)
|
|
monkeypatch.setattr(server, "startup_scan", lambda: None)
|
|
static_tmp = tmp_path / "static"
|
|
static_tmp.mkdir()
|
|
monkeypatch.setattr(server, "STATIC_DIR", static_tmp)
|
|
tc = TestClient(server.app, client=("127.0.0.1", 50000))
|
|
try:
|
|
yield tc, server, dlc
|
|
finally:
|
|
tc.close()
|
|
meta_db = getattr(server, "meta_db", None)
|
|
conn = getattr(meta_db, "conn", None)
|
|
if conn is not None:
|
|
conn.close()
|
|
|
|
|
|
def _make_sloppak(dlc, name="song.sloppak"):
|
|
"""Create a minimal directory-form sloppak with one served file."""
|
|
pak = dlc / name
|
|
(pak / "stems").mkdir(parents=True)
|
|
(pak / "stems" / "full.ogg").write_bytes(b"OggS-fake")
|
|
return pak
|
|
|
|
|
|
def test_filename_dotdot_traversal_is_403(dlc_client):
|
|
tc, _server, _dlc = dlc_client
|
|
# `filename` escapes DLC_DIR — must 403 before any filesystem read,
|
|
# never serve /etc/passwd (the original report).
|
|
r = tc.get("/api/sloppak/..%2F..%2F..%2F..%2Fetc/file/passwd")
|
|
assert r.status_code == 403, r.text
|
|
|
|
|
|
def test_rel_path_dotdot_traversal_is_403(dlc_client):
|
|
"""A real sloppak is present, but `rel_path` escapes it — 403."""
|
|
tc, _server, dlc = dlc_client
|
|
_make_sloppak(dlc)
|
|
# Drop a secret as a sibling of the sloppak inside DLC_DIR.
|
|
(dlc / "secret.txt").write_text("top secret")
|
|
r = tc.get("/api/sloppak/song.sloppak/file/..%2Fsecret.txt")
|
|
assert r.status_code == 403, r.text
|
|
|
|
|
|
def test_contained_non_sloppak_is_404(dlc_client):
|
|
"""A contained-but-non-sloppak `filename` (plain dir) must not turn
|
|
the endpoint into read-any-file-under-DLC_DIR — the is_sloppak gate
|
|
rejects it with 404."""
|
|
tc, _server, dlc = dlc_client
|
|
plain = dlc / "Artist"
|
|
plain.mkdir()
|
|
(plain / "notes.txt").write_text("not a sloppak")
|
|
r = tc.get("/api/sloppak/Artist/file/notes.txt")
|
|
assert r.status_code == 404, r.text
|
|
|
|
|
|
def test_dot_filename_is_404(dlc_client):
|
|
"""`filename=.` resolves to DLC_DIR itself; the is_sloppak gate
|
|
blocks it rather than serving arbitrary DLC files."""
|
|
tc, _server, dlc = dlc_client
|
|
(dlc / "config.json").write_text("{}")
|
|
r = tc.get("/api/sloppak/./file/config.json")
|
|
assert r.status_code == 404, r.text
|
|
|
|
|
|
def test_missing_sloppak_is_404(dlc_client):
|
|
"""A safe-but-missing sloppak path produces 404, not 403 — guards
|
|
against over-rejecting legitimate filenames."""
|
|
tc, _server, _dlc = dlc_client
|
|
r = tc.get("/api/sloppak/missing.sloppak/file/stems/full.ogg")
|
|
assert r.status_code == 404, r.text
|
|
|
|
|
|
def test_legitimate_file_is_served(dlc_client):
|
|
"""A real file inside a real sloppak serves with 200 + bytes."""
|
|
tc, _server, dlc = dlc_client
|
|
_make_sloppak(dlc)
|
|
r = tc.get("/api/sloppak/song.sloppak/file/stems/full.ogg")
|
|
assert r.status_code == 200, r.text
|
|
assert r.content == b"OggS-fake"
|