Check every destination, including hosts without a dot, and fix CI, pins and imports past the plugin surface #1

Closed
opened 2026-09-15 21:23:40 +00:00 by tiagoagueda · 0 comments
Owner

Found in the 2026-09-15 audit of the plugin repositories.

1. Hostnames without a dot skip the destination check

  • src/postulo_apprise/notifier.py:34: the _HOSTNAME regex requires at least one dot.
  • :74-80: destination_of returns None for any host that doesn't match, and :136-140 then skips http.check_destination.
  • So json://redis:6379/, form://paperless:8000/ and gotify://internal/ (Docker service names and single-label LAN hosts) are never checked.
  • Apprise also resolves DNS itself later, so even a checked name can be rebound between the check and the send.

Fix:

  • Treat every Apprise host that is not a known token slot as a destination: keep an allowlist of the hosted-service schemes whose "host" field is really a token, and check everything else.
  • Longer term, send the custom-webhook schemes (json, xml, form) through api.client, so the check and the connection are one act.
  • Tests: json://redis:6379/ refused with private destinations off.

2. CI cannot pass

.forgejo/workflows/ci.yml:39,41 runs scripts/compile_messages.py, and the repository has no scripts/ directory.

Fix: use the postulo-messages compile command, and add a tag-triggered job running uv run pytest -m release.

3. The version pin is a label

  • __version__ is 0.1.0 while pyproject.toml says 0.3.0.
  • The core dev dependency has no ref, and the lock tracks a main commit that is not on 0.3.0.
  • Catalogue tests skip silently against the release branch.

Fix: version from importlib.metadata, pin the core to v0.3.0, and fail instead of skipping under -m release.

4. Imports past postulo.plugins.api

notifier.py:26-27 imports postulo.plugins.http and postulo.plugins.base. Move FieldSpec/TestResult and client to api now. Move DestinationRefused/check_destination once the core exposes them (core plugin-surface issue (postulo/postulo#229)). Add the surface AST check to CI.

Found in the 2026-09-15 audit of the plugin repositories. ## 1. Hostnames without a dot skip the destination check - `src/postulo_apprise/notifier.py:34`: the `_HOSTNAME` regex requires at least one dot. - `:74-80`: `destination_of` returns `None` for any host that doesn't match, and `:136-140` then skips `http.check_destination`. - So `json://redis:6379/`, `form://paperless:8000/` and `gotify://internal/` (Docker service names and single-label LAN hosts) are never checked. - Apprise also resolves DNS itself later, so even a checked name can be rebound between the check and the send. **Fix:** - Treat every Apprise host that is not a known token slot as a destination: keep an allowlist of the hosted-service schemes whose "host" field is really a token, and check everything else. - Longer term, send the custom-webhook schemes (`json`, `xml`, `form`) through `api.client`, so the check and the connection are one act. - Tests: `json://redis:6379/` refused with private destinations off. ## 2. CI cannot pass `.forgejo/workflows/ci.yml:39,41` runs `scripts/compile_messages.py`, and the repository has no `scripts/` directory. **Fix:** use the `postulo-messages` compile command, and add a tag-triggered job running `uv run pytest -m release`. ## 3. The version pin is a label - `__version__` is `0.1.0` while `pyproject.toml` says `0.3.0`. - The core dev dependency has no ref, and the lock tracks a `main` commit that is not on `0.3.0`. - Catalogue tests skip silently against the release branch. **Fix:** version from `importlib.metadata`, pin the core to `v0.3.0`, and fail instead of skipping under `-m release`. ## 4. Imports past `postulo.plugins.api` `notifier.py:26-27` imports `postulo.plugins.http` and `postulo.plugins.base`. Move `FieldSpec`/`TestResult` and `client` to `api` now. Move `DestinationRefused`/`check_destination` once the core exposes them (core plugin-surface issue (postulo/postulo#229)). Add the surface AST check to CI.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Postulo/postulo-apprise#1
No description provided.