Security/review remediation - #98
Merged
VanDelinea merged 4 commits intoAug 12, 2026
Merged
Conversation
…, attach response to errors, 🧪 add offline security tests security review remediation, phase 1 (DevPlan.md) == - every http call now passes an explicit timeout via DEFAULT_REQUEST_TIMEOUT; the folder and lookup calls had none and could hang a consumer forever - oauth2 grant now refreshes up to 300s before expiry; the drift sign was inverted so expired tokens were reused for up to 300s past expiry - SecretServerError keeps the server response (error.response works now); a 4xx json body without message/error keys no longer masks the failure with UnboundLocalError - example masks the password value instead of printing it - new offline test suite covers timeout coverage on every request path, refresh boundary behavior, and error plumbing; no live credentials needed
…n, sanitize error bodies, validate vault redirect, 🧪 add offline security tests security review remediation, phase 2 (DevPlan.md) == - warn (UserWarning) when base_url is not https; credentials and bearer tokens would otherwise travel in plaintext with no signal to the caller. strict rejection is deferred to v3.0 to avoid breaking localhost/lab setups - health-check probing now requires a 2xx status and an exact "healthy" match instead of a substring check; the old check matched "Unhealthy" and ignored the http status entirely - exception messages no longer echo raw response bodies; the secrets endpoint omits the body outright, other endpoints get a capped, clearly truncated excerpt - the platform vault-broker redirect url is now required to be a valid https url before any token is sent to it - SecretServerError now passes its message through to Exception.__init__, so str(error) is populated instead of always empty - new offline test suite covers all four fixes; existing FakeResponse fixtures updated with .ok/.status_code/.text to match the tightened health-check contract
…lease to pypi trusted publishing, align tox deps with pinned requirements security review remediation, phase 3 (DevPlan.md) == - every workflow now declares least-privilege permissions at the top level; the lint job (needs to push auto-fix commits and publish check results) and the release job (needs the oidc token) grant themselves only what they actually use - pypa/gh-action-pypi-publish was pinned to the mutable release/v1 branch, the only unpinned action in the repo; now pinned to the v1.14.2 commit sha - release.yml drops the long-lived PYPI_API_TOKEN in favor of PyPI Trusted Publishing (OIDC) -- requires a trusted publisher to be configured for this repo/workflow on pypi.org before the next tag push; keep the repo secret until that is confirmed working - tox.ini and lint.yml now install the versions pinned in requirements.txt (black==26.5.1, flit==3.12.0, and the full pinned set via -r requirements.txt) instead of floating latest, so CI exercises what consumers actually get
…SECURITY.md, 🚀 split runtime/dev deps and pin pip - token refresh now locked and utc-aware; mutable default args removed - fixed get_folder_json crash on bare call, itemValue returning a Response object instead of text, and an unvalidated non-numeric secrets count - requirements.txt split into runtime-only pins with a new requirements-dev.txt for build/test tooling; pip>=26.2 pinned there and in release.yml (transitive via flit; CVE-2026-8643 and others)
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
No description provided.