Skip to content

fix: Validate DB/IMDb IDs and add tests#6933

Merged
ReenigneArcher merged 1 commit into
masterfrom
refactor/sonar-fixes
Jun 5, 2026
Merged

fix: Validate DB/IMDb IDs and add tests#6933
ReenigneArcher merged 1 commit into
masterfrom
refactor/sonar-fixes

Conversation

@ReenigneArcher

Copy link
Copy Markdown
Member

Description

Prevent path-traversal/invalid identifier usage when writing item JSON files by adding regex constants (DATABASE_ITEM_ID_PATTERN, IMDB_ID_PATTERN) and a helper _build_database_json_path that validates an ID before building an absolute path. _write_item_files now uses the helper for the primary database id and the IMDb copy, raising ValueError for invalid IDs. New unit tests assert that unsafe database ids and unsafe IMDb ids are rejected and that no files are created when validation fails.

Screenshot

Issues Fixed or Closed

Roadmap Issues

Type of Change

  • feat: New feature (non-breaking change which adds functionality)
  • fix: Bug fix (non-breaking change which fixes an issue)
  • docs: Documentation only changes
  • style: Changes that do not affect the meaning of the code (white-space, formatting, missing semicolons, etc.)
  • refactor: Code change that neither fixes a bug nor adds a feature
  • perf: Code change that improves performance
  • test: Adding missing tests or correcting existing tests
  • build: Changes that affect the build system or external dependencies
  • ci: Changes to CI configuration files and scripts
  • chore: Other changes that don't modify src or test files
  • revert: Reverts a previous commit
  • BREAKING CHANGE: Introduces a breaking change (can be combined with any type above)

Checklist

  • Code follows the style guidelines of this project
  • Code has been self-reviewed
  • Code has been commented, particularly in hard-to-understand areas
  • Code docstring/documentation-blocks for new or existing methods/components have been added or updated
  • Unit tests have been added or updated for any new or modified functionality

AI Usage

  • None: No AI tools were used in creating this PR
  • Light: AI provided minor assistance (formatting, simple suggestions)
  • Moderate: AI helped with code generation or debugging specific parts
  • Heavy: AI generated most or all of the code changes

Prevent path-traversal/invalid identifier usage when writing item JSON files by adding regex constants (DATABASE_ITEM_ID_PATTERN, IMDB_ID_PATTERN) and a helper _build_database_json_path that validates an ID before building an absolute path. _write_item_files now uses the helper for the primary database id and the IMDb copy, raising ValueError for invalid IDs. New unit tests assert that unsafe database ids and unsafe IMDb ids are rejected and that no files are created when validation fails.
@sonarqubecloud

sonarqubecloud Bot commented Jun 5, 2026

Copy link
Copy Markdown

@codecov

codecov Bot commented Jun 5, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 100.00%. Comparing base (8bcc1fb) to head (d3b069b).
✅ All tests successful. No failed tests found.

Additional details and impacted files

Impacted file tree graph

@@            Coverage Diff            @@
##            master     #6933   +/-   ##
=========================================
  Coverage   100.00%   100.00%           
=========================================
  Files           13        13           
  Lines         1426      1433    +7     
  Branches        85        85           
=========================================
+ Hits          1426      1433    +7     
Files with missing lines Coverage Δ
src/updater.py 100.00% <100.00%> (ø)

Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update 8bcc1fb...d3b069b. Read the comment docs.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@ReenigneArcher
ReenigneArcher merged commit eb6c4e6 into master Jun 5, 2026
17 checks passed
@ReenigneArcher
ReenigneArcher deleted the refactor/sonar-fixes branch June 5, 2026 00:30
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant