Refactor and clean up code across multiple modules
- Simplified token type assignment in OAuth service. - Removed unused session_lock module and re-exported Session from zesdex_entities. - Cleaned up session entity by removing unnecessary comments and code. - Consolidated session handling in HTTP handlers for better readability. - Improved formatting and readability in OAuth repository tests. - Enhanced session lock repository with clearer match statements. - Streamlined session repository error handling. - Refined RNG tests for better clarity. - Adjusted module visibility and organization in lib.rs. - Updated IPC client and connection code for better error handling and clarity. - Improved frame handling in IPC for better readability. - Organized module imports and added test utilities for IPC. - Enhanced database connection error handling. - Simplified JWT token creation error handling. - Improved password verification error handling. - Cleaned up state management code for better readability. - Refactored middleware for session authentication and rate limiting. - Simplified clipboard utility for better error handling. - Enhanced logging initialization for better error reporting. - Improved pagination utility with clearer method annotations. - Cleaned up sanitization functions for filenames and paths. - Enhanced slug generation functions for better clarity and usability.
This commit is contained in:
@@ -27,19 +27,14 @@ pub fn handle_create_session<S: SessionService>(
|
||||
}
|
||||
|
||||
/// Handle a list-sessions request.
|
||||
pub fn handle_list_sessions<S: SessionService>(
|
||||
service: &S,
|
||||
) -> anyhow::Result<SessionListResponse> {
|
||||
pub fn handle_list_sessions<S: SessionService>(service: &S) -> anyhow::Result<SessionListResponse> {
|
||||
let sessions = service.list_all()?;
|
||||
let total = sessions.len();
|
||||
Ok(SessionListResponse { sessions, total })
|
||||
}
|
||||
|
||||
/// Handle an archive-session request.
|
||||
pub fn handle_archive_session<S: SessionService>(
|
||||
service: &S,
|
||||
id: &str,
|
||||
) -> anyhow::Result<()> {
|
||||
pub fn handle_archive_session<S: SessionService>(service: &S, id: &str) -> anyhow::Result<()> {
|
||||
service.archive_session(id)?;
|
||||
Ok(())
|
||||
}
|
||||
@@ -63,9 +58,7 @@ pub fn handle_complete_oauth<O: OAuthService>(
|
||||
}
|
||||
|
||||
/// Handle a get-token request.
|
||||
pub fn handle_get_token<O: OAuthService>(
|
||||
service: &O,
|
||||
) -> anyhow::Result<OAuthTokenResponse> {
|
||||
pub fn handle_get_token<O: OAuthService>(service: &O) -> anyhow::Result<OAuthTokenResponse> {
|
||||
let token = service
|
||||
.get_token()?
|
||||
.ok_or_else(|| anyhow::anyhow!("no OAuth token stored"))?;
|
||||
|
||||
@@ -65,7 +65,8 @@ mod tests {
|
||||
#[cfg(unix)]
|
||||
fn save_token_sets_owner_only_permissions() {
|
||||
use std::os::unix::fs::PermissionsExt;
|
||||
let dir = std::env::temp_dir().join(format!("zesdex-iam-perm-test-{}", uuid::Uuid::new_v4()));
|
||||
let dir =
|
||||
std::env::temp_dir().join(format!("zesdex-iam-perm-test-{}", uuid::Uuid::new_v4()));
|
||||
let path = dir.join("oauth_test.json");
|
||||
let repo = FileSystemOAuthRepository::new();
|
||||
let token = OAuthToken {
|
||||
@@ -74,10 +75,14 @@ mod tests {
|
||||
expires_at: 0,
|
||||
token_type: "Bearer".to_string(),
|
||||
};
|
||||
repo.save_token(&path, &token).expect("save_token should succeed");
|
||||
repo.save_token(&path, &token)
|
||||
.expect("save_token should succeed");
|
||||
|
||||
let mode = std::fs::metadata(&path).unwrap().permissions().mode() & 0o777;
|
||||
assert_eq!(mode, 0o600, "token file must be readable/writable by owner only, got {mode:o}");
|
||||
assert_eq!(
|
||||
mode, 0o600,
|
||||
"token file must be readable/writable by owner only, got {mode:o}"
|
||||
);
|
||||
|
||||
let _ = std::fs::remove_dir_all(&dir);
|
||||
}
|
||||
|
||||
@@ -30,7 +30,11 @@ impl SessionLockRepository for FileSystemSessionLockRepository {
|
||||
let path = session_dir.join(".lock");
|
||||
let pid = std::process::id();
|
||||
|
||||
match fs::OpenOptions::new().create_new(true).write(true).open(&path) {
|
||||
match fs::OpenOptions::new()
|
||||
.create_new(true)
|
||||
.write(true)
|
||||
.open(&path)
|
||||
{
|
||||
Ok(mut file) => {
|
||||
write!(file, "{pid}")?;
|
||||
file.sync_all()?;
|
||||
@@ -49,7 +53,11 @@ impl SessionLockRepository for FileSystemSessionLockRepository {
|
||||
|
||||
let tmp = path.with_extension("lock.tmp");
|
||||
{
|
||||
let mut tmp_file = fs::OpenOptions::new().create(true).truncate(true).write(true).open(&tmp)?;
|
||||
let mut tmp_file = fs::OpenOptions::new()
|
||||
.create(true)
|
||||
.truncate(true)
|
||||
.write(true)
|
||||
.open(&tmp)?;
|
||||
write!(tmp_file, "{pid}")?;
|
||||
tmp_file.sync_all()?;
|
||||
}
|
||||
@@ -89,7 +97,8 @@ mod tests {
|
||||
use super::*;
|
||||
|
||||
fn tmp_dir() -> std::path::PathBuf {
|
||||
let dir = std::env::temp_dir().join(format!("zesdex-iam-lock-test-{}", uuid::Uuid::new_v4()));
|
||||
let dir =
|
||||
std::env::temp_dir().join(format!("zesdex-iam-lock-test-{}", uuid::Uuid::new_v4()));
|
||||
std::fs::create_dir_all(&dir).unwrap();
|
||||
dir
|
||||
}
|
||||
@@ -119,7 +128,10 @@ mod tests {
|
||||
let repo = FileSystemSessionLockRepository::new();
|
||||
// Write a lock file with a PID that cannot possibly be alive.
|
||||
std::fs::write(dir.join(".lock"), "999999999").unwrap();
|
||||
assert!(repo.try_lock(&dir).unwrap(), "a stale lock (dead PID) must be recoverable");
|
||||
assert!(
|
||||
repo.try_lock(&dir).unwrap(),
|
||||
"a stale lock (dead PID) must be recoverable"
|
||||
);
|
||||
let _ = std::fs::remove_dir_all(&dir);
|
||||
}
|
||||
|
||||
|
||||
@@ -46,9 +46,7 @@ impl SessionRepository for FileSystemSessionRepository {
|
||||
fn load_session(&self, base_dir: &Path, id: &str) -> anyhow::Result<Session> {
|
||||
// Directory-traversal prevention.
|
||||
if id.contains('/') || id.contains('\\') || id.contains("..") {
|
||||
anyhow::bail!(
|
||||
"invalid session id '{id}': must not contain path separators"
|
||||
);
|
||||
anyhow::bail!("invalid session id '{id}': must not contain path separators");
|
||||
}
|
||||
let path = base_dir.join("sessions").join(id).join("session.json");
|
||||
if !path.exists() {
|
||||
@@ -79,9 +77,7 @@ impl SessionRepository for FileSystemSessionRepository {
|
||||
|
||||
fn delete_session(&self, base_dir: &Path, id: &str) -> anyhow::Result<()> {
|
||||
if id.contains('/') || id.contains('\\') || id.contains("..") {
|
||||
anyhow::bail!(
|
||||
"invalid session id '{id}': must not contain path separators"
|
||||
);
|
||||
anyhow::bail!("invalid session id '{id}': must not contain path separators");
|
||||
}
|
||||
let dir = base_dir.join("sessions").join(id);
|
||||
if dir.exists() {
|
||||
|
||||
@@ -33,6 +33,9 @@ mod tests {
|
||||
fn secure_token_hex_is_not_constant() {
|
||||
let a = secure_token_hex(16);
|
||||
let b = secure_token_hex(16);
|
||||
assert_ne!(a, b, "two consecutive calls must not produce the same token");
|
||||
assert_ne!(
|
||||
a, b,
|
||||
"two consecutive calls must not produce the same token"
|
||||
);
|
||||
}
|
||||
}
|
||||
|
||||
Reference in New Issue
Block a user