fix: аудит — 19 фиксов безопасности, надёжности, UI и 16 новых тестов
- S4: bump jinja2>=3.1.4, python-multipart>=0.0.18, httpx>=0.28.0
- S5: _detect_ecosystem — DEFAULT_ECOSYSTEM для неизвестных форматов
- S6: harvester — log.exception() вместо log.error()
- S8: _scan_component — urlencode параметров
- P1: scanner — proc.kill() при таймауте
- P3: api_packages — selectinload(Scan.findings), убран N+1
- P4+P5: утечка _url_locks и _llm_locks при early return
- P6: DB reaper — сброс {'status':'analyzing'} при старте
- UI: htmx-пагинация, фильтры не теряют flagged, 404 с layout
- UI: мобильные таблицы overflow-x, полная стата на дашборде
- UI: i18n статусов в _status_badge, urlencode package_name
- 16 новых тестов: analyze endpoint (6), scanner errors (4),
webhook signature (2), llm client (4)
This commit is contained in:
@@ -1,6 +1,5 @@
|
||||
"""Async SQLite database setup via SQLAlchemy."""
|
||||
|
||||
|
||||
from sqlalchemy import inspect, text
|
||||
from sqlalchemy.ext.asyncio import AsyncSession, async_sessionmaker, create_async_engine
|
||||
from sqlalchemy.orm import DeclarativeBase
|
||||
@@ -69,6 +68,7 @@ async def init_db():
|
||||
await conn.run_sync(Base.metadata.create_all)
|
||||
await _migrate()
|
||||
await _ensure_indexes()
|
||||
await _reap_stale_analysis()
|
||||
|
||||
|
||||
async def get_session() -> AsyncSession:
|
||||
@@ -90,3 +90,17 @@ async def _ensure_indexes():
|
||||
async with _engine.begin() as conn:
|
||||
for sql in indexes:
|
||||
await conn.execute(text(sql))
|
||||
|
||||
|
||||
async def _reap_stale_analysis():
|
||||
"""Reset stuck 'analyzing' statuses left from crashes."""
|
||||
sql = (
|
||||
"UPDATE findings SET report = NULL "
|
||||
"WHERE report IS NOT NULL "
|
||||
"AND json_extract(report, '$.status') = 'analyzing'"
|
||||
)
|
||||
async with _engine.begin() as conn:
|
||||
result = await conn.execute(text(sql))
|
||||
count = result.rowcount
|
||||
if count:
|
||||
log.warning("Reset %d stale LLM analysis statuses", count)
|
||||
|
||||
@@ -23,6 +23,7 @@ from guarddog_nexus.db.models import Finding, Scan
|
||||
# Scan list query builder
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
def build_scan_list_query(
|
||||
flagged: bool | None = None,
|
||||
status: str | None = None,
|
||||
@@ -51,9 +52,7 @@ def build_scan_list_query(
|
||||
count_q = count_q.where(Scan.repository == repository)
|
||||
if search:
|
||||
pattern = f"%{search}%"
|
||||
condition = Scan.package_name.ilike(pattern) | Scan.package_version.ilike(
|
||||
pattern
|
||||
)
|
||||
condition = Scan.package_name.ilike(pattern) | Scan.package_version.ilike(pattern)
|
||||
q = q.where(condition)
|
||||
count_q = count_q.where(condition)
|
||||
|
||||
@@ -70,6 +69,7 @@ def build_scan_list_query(
|
||||
# Package list query builder
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
def build_package_list_query(
|
||||
flagged: bool | None = None,
|
||||
ecosystem: str | None = None,
|
||||
@@ -101,9 +101,7 @@ def build_package_list_query(
|
||||
subq = subq.where(Scan.repository == repository)
|
||||
if search:
|
||||
pattern = f"%{search}%"
|
||||
subq = subq.where(
|
||||
Scan.package_name.ilike(pattern) | Scan.package_version.ilike(pattern)
|
||||
)
|
||||
subq = subq.where(Scan.package_name.ilike(pattern) | Scan.package_version.ilike(pattern))
|
||||
|
||||
if flagged is not None:
|
||||
subq = subq.having(func.max(Scan.flagged) == flagged)
|
||||
@@ -112,9 +110,7 @@ def build_package_list_query(
|
||||
sort_field_name = PACKAGE_SORT_FIELDS.get(sort_by, "started_at")
|
||||
sort_col_from = getattr(Scan, sort_field_name, Scan.started_at)
|
||||
sort_col = func.max(sort_col_from)
|
||||
subq = subq.order_by(
|
||||
sort_col.desc() if sort_dir == "desc" else sort_col.asc()
|
||||
)
|
||||
subq = subq.order_by(sort_col.desc() if sort_dir == "desc" else sort_col.asc())
|
||||
|
||||
sq = subq.subquery()
|
||||
total_q = select(func.count()).select_from(sq)
|
||||
@@ -126,12 +122,11 @@ def build_package_list_query(
|
||||
# Dashboard stats (shared between API /stats and web dashboard)
|
||||
# ---------------------------------------------------------------------------
|
||||
|
||||
|
||||
async def get_dashboard_stats(session: AsyncSession) -> dict:
|
||||
"""Return all dashboard statistics as a single dict."""
|
||||
total_scans = await session.scalar(select(func.count(Scan.id)))
|
||||
flagged_scans = await session.scalar(
|
||||
select(func.count(Scan.id)).where(Scan.flagged == True)
|
||||
)
|
||||
flagged_scans = await session.scalar(select(func.count(Scan.id)).where(Scan.flagged == True))
|
||||
recent_flagged = await session.scalar(
|
||||
select(func.count(Scan.id)).where(
|
||||
Scan.flagged == True,
|
||||
@@ -165,9 +160,7 @@ async def get_dashboard_stats(session: AsyncSession) -> dict:
|
||||
latest_scans = (
|
||||
(
|
||||
await session.execute(
|
||||
select(Scan)
|
||||
.order_by(Scan.started_at.desc())
|
||||
.limit(DASHBOARD_LATEST_SCANS_LIMIT)
|
||||
select(Scan).order_by(Scan.started_at.desc()).limit(DASHBOARD_LATEST_SCANS_LIMIT)
|
||||
)
|
||||
)
|
||||
.scalars()
|
||||
|
||||
Reference in New Issue
Block a user