fix: code review fixes — auth gap, path traversal, dead code, health-check timeout
- backend/app.py: add Depends(_require_auth) to /api/copilotkit endpoint (critical security fix — endpoint was fully unprotected; now requires valid session cookie) - backend/app.py: move 'from ag_ui.core import RunStartedEvent' from inline function body to top-level imports (style consistency) - backend/auth.py: remove dead AUTH_PASS_HASH module-level constant (verify_password already reads from os.environ at call time; the cached binding was unused dead code) - backend/artifacts.py: add path traversal guards to list_artifacts, get_artifact, and save_artifact — resolve paths and verify they stay within ARTIFACTS_DIR - entrypoint.sh: health-check loop now sets READY flag and exits 1 if amplifierd fails to start within 30s (previously fell through silently, causing 502s) - tests/test_app.py: add TestCopilotKitAuth — verifies unauthenticated requests to /api/copilotkit return 401; includes note explaining why streaming is not tested here - tests/test_structure.sh: update to reflect that Dockerfile and entrypoint.sh now exist (created in Tasks 7+8); convert absent-checks to presence-checks Co-authored-by: Amplifier <amplifier@anthropic.com>
This commit is contained in:
+17
-2
@@ -44,11 +44,26 @@ check_absent "sites.yaml"
|
||||
check_absent "app.py"
|
||||
check_absent "static"
|
||||
check_absent "results"
|
||||
check_absent "Dockerfile"
|
||||
check_absent "entrypoint.sh"
|
||||
check_absent "pyproject.toml"
|
||||
check_absent "uv.lock"
|
||||
|
||||
echo ""
|
||||
echo "=== Checking new root-level files exist ==="
|
||||
if [ -f "$REPO/Dockerfile" ]; then
|
||||
echo "PASS: 'Dockerfile' exists (Task 7)"
|
||||
((PASS++))
|
||||
else
|
||||
echo "FAIL: 'Dockerfile' should exist (Task 7) but is missing"
|
||||
((FAIL++))
|
||||
fi
|
||||
if [ -f "$REPO/entrypoint.sh" ]; then
|
||||
echo "PASS: 'entrypoint.sh' exists (Task 8)"
|
||||
((PASS++))
|
||||
else
|
||||
echo "FAIL: 'entrypoint.sh' should exist (Task 8) but is missing"
|
||||
((FAIL++))
|
||||
fi
|
||||
|
||||
echo ""
|
||||
echo "=== Checking new directories exist ==="
|
||||
check_dir "backend"
|
||||
|
||||
Reference in New Issue
Block a user