feat: harden OAuth state secret validation, DCR file permissions, and policy defaults
docker / test (pull_request) Successful in 24s
lint / lint (pull_request) Successful in 37s
lint / lint (push) Successful in 1m26s
test / test (push) Successful in 1m40s
test / test (pull_request) Successful in 34s
docker / lint (pull_request) Successful in 1m59s
docker / docker-test (pull_request) Successful in 14s
docker / docker-publish (pull_request) Has been skipped
docker / test (pull_request) Successful in 24s
lint / lint (pull_request) Successful in 37s
lint / lint (push) Successful in 1m26s
test / test (push) Successful in 1m40s
test / test (pull_request) Successful in 34s
docker / lint (pull_request) Successful in 1m59s
docker / docker-test (pull_request) Successful in 14s
docker / docker-publish (pull_request) Has been skipped
- Enforce 32-char minimum on OAUTH_STATE_SECRET at startup (config.py) - Write DCR client registry with owner-only (0o600) permissions before atomic replace - Flip policy.yaml default write action from allow → deny - Add CLAUDE.md with architecture, commands, and AGENTS.md contract summary - Add .pre-commit-config.yaml mirroring `make lint` checks - Update .gitignore: add .venv, .claude, .mypy_cache, .ruff_cache, .coverage.* - Extend docs: audit log rotation guidance, OAUTH_STATE_SECRET and DCR_STORAGE_PATH notes - Tests: short-secret rejection, 32-char acceptance, POSIX permission check for DCR store Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,42 @@
|
||||
# Pre-commit hooks mirror `make lint` so local commits enforce the same checks as CI.
|
||||
# Installed via `make install-dev` (runs `pre-commit install`).
|
||||
#
|
||||
# Hooks use `language: system`, i.e. they invoke ruff/black/mypy from PATH rather than
|
||||
# letting pre-commit manage isolated tool environments. This keeps versions identical to
|
||||
# `make lint`/`make format` and lets mypy resolve the project's real dependencies.
|
||||
# Requirement: commit with the dev virtualenv active (so requirements-dev.txt tools are on
|
||||
# PATH). Outside an active venv the hooks will report the tools as "not found".
|
||||
repos:
|
||||
- repo: local
|
||||
hooks:
|
||||
- id: ruff-check
|
||||
name: ruff check
|
||||
entry: ruff check
|
||||
language: system
|
||||
types: [python]
|
||||
args: [src/, tests/]
|
||||
pass_filenames: false
|
||||
|
||||
- id: ruff-format
|
||||
name: ruff format --check
|
||||
entry: ruff format --check
|
||||
language: system
|
||||
types: [python]
|
||||
args: [src/, tests/]
|
||||
pass_filenames: false
|
||||
|
||||
- id: black
|
||||
name: black --check
|
||||
entry: black --check
|
||||
language: system
|
||||
types: [python]
|
||||
args: [src/, tests/]
|
||||
pass_filenames: false
|
||||
|
||||
- id: mypy
|
||||
name: mypy
|
||||
entry: mypy
|
||||
language: system
|
||||
types: [python]
|
||||
args: [src/]
|
||||
pass_filenames: false
|
||||
Reference in New Issue
Block a user