Fix CI and the version pin, stop importing past the plugin surface, and refuse tokens over plain http #2
Labels
No labels
bug
documentation
enhancement
security
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo-paperless#2
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Found in the 2026-09-15 audit of the plugin repositories. The plugin itself is in good shape: it uses the guarded client, retries without duplicating, and takes its
StorePlugintypes fromapi.1. CI cannot pass
.forgejo/workflows/ci.yml:39,41runsscripts/compile_messages.py, and the repository has noscripts/directory.Fix: use the
postulo-messagescompile command the tests already name, and add a tag-triggered job runninguv run pytest -m release.2. The version pin is a label
__version__is0.1.0whilepyproject.tomlsays0.3.0, and Postulo displays the former.maincommit that is not on the0.3.0branch.importorskipsilently against that branch.Fix: version from
importlib.metadata, pin the core tov0.3.0, and fail instead of skipping under-m release.3. Imports past
postulo.plugins.apistore.py:31,33importspostulo.plugins.httpandpostulo.plugins.base. Useapi.client,FieldSpecandTestResultfrom the surface now. MoveDestinationRefusedonce the core exposes it (core plugin-surface issue (postulo/postulo#229)). Add the surface AST check to CI.4. The API token can be sent over plain http
The URL field is a plain
type="url"(store.py:200-205), andAuthorization: Token …goes to whatever scheme is typed (store.py:61).Fix: in
validate(), refusehttp://unless the host is private and the operator allows private destinations, or at least warn.