Fix CI and the version pin, stop importing past the plugin surface, and refuse tokens over plain http #2

Closed
opened 2026-09-15 21:23:43 +00:00 by tiagoagueda · 0 comments
Owner

Found in the 2026-09-15 audit of the plugin repositories. The plugin itself is in good shape: it uses the guarded client, retries without duplicating, and takes its StorePlugin types from api.

1. CI cannot pass

.forgejo/workflows/ci.yml:39,41 runs scripts/compile_messages.py, and the repository has no scripts/ directory.

Fix: use the postulo-messages compile command the tests already name, and add a tag-triggered job running uv run pytest -m release.

2. The version pin is a label

  • __version__ is 0.1.0 while pyproject.toml says 0.3.0, and Postulo displays the former.
  • The core dev dependency has no ref, and the lock tracks a main commit that is not on the 0.3.0 branch.
  • The catalogue tests importorskip silently against that branch.

Fix: version from importlib.metadata, pin the core to v0.3.0, and fail instead of skipping under -m release.

3. Imports past postulo.plugins.api

store.py:31,33 imports postulo.plugins.http and postulo.plugins.base. Use api.client, FieldSpec and TestResult from the surface now. Move DestinationRefused once the core exposes it (core plugin-surface issue (postulo/postulo#229)). Add the surface AST check to CI.

4. The API token can be sent over plain http

The URL field is a plain type="url" (store.py:200-205), and Authorization: Token … goes to whatever scheme is typed (store.py:61).

Fix: in validate(), refuse http:// unless the host is private and the operator allows private destinations, or at least warn.

Found in the 2026-09-15 audit of the plugin repositories. The plugin itself is in good shape: it uses the guarded client, retries without duplicating, and takes its `StorePlugin` types from `api`. ## 1. CI cannot pass `.forgejo/workflows/ci.yml:39,41` runs `scripts/compile_messages.py`, and the repository has no `scripts/` directory. **Fix:** use the `postulo-messages` compile command the tests already name, and add a tag-triggered job running `uv run pytest -m release`. ## 2. The version pin is a label - `__version__` is `0.1.0` while `pyproject.toml` says `0.3.0`, and Postulo displays the former. - The core dev dependency has no ref, and the lock tracks a `main` commit that is not on the `0.3.0` branch. - The catalogue tests `importorskip` silently against that branch. **Fix:** version from `importlib.metadata`, pin the core to `v0.3.0`, and fail instead of skipping under `-m release`. ## 3. Imports past `postulo.plugins.api` `store.py:31,33` imports `postulo.plugins.http` and `postulo.plugins.base`. Use `api.client`, `FieldSpec` and `TestResult` from the surface now. Move `DestinationRefused` once the core exposes it (core plugin-surface issue (postulo/postulo#229)). Add the surface AST check to CI. ## 4. The API token can be sent over plain http The URL field is a plain `type="url"` (`store.py:200-205`), and `Authorization: Token …` goes to whatever scheme is typed (`store.py:61`). **Fix:** in `validate()`, refuse `http://` unless the host is private and the operator allows private destinations, or at least warn.
Sign in to join this conversation.
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
Postulo/postulo-paperless#2
No description provided.