Phase 3 : hardening qualite de code - typage strict, securite, dead code, a11y

Config strictement stricte partout (ruff, mypy --strict, bandit, vulture,
import-linter, eslint, stylelint), aucune regle desactivee "pour ne pas
casser le build" - l'existant a ete corrige pour la satisfaire plutot que
l'inverse. Hooks pre-commit locaux (language: system) bloquants.

- Typage mypy --strict propage a tout le moteur (db, screens, auth, core,
  ai, routes, puis publish/scripts/tests/app.py/build_css.py).
- Securite : fuite de handle fichier Windows corrigee dans l'export SCORM
  (routes/publish/export_scorm.py), CSRF/RNG non-crypto/xAPI documentes
  (# nosec, # NOSONAR justifies), nouveau db.json_for_script() (echappe
  "</script>" dans le JSON embarque en <script>, 25 sites).
- Architecture : imports circulaires/F811 nettoyes, contrats
  import-linter respectes, code mort retire (vulture).
- Accessibilite : 69 champs de formulaire sans label correctement
  associe corriges (for/id ou aria-label) sur 11 templates.
- ESLint/Stylelint : lot mecanique JS/CSS, regles ajustees puis
  appliquees (aucune desactivee sans verification individuelle).
- Tests : isolation du compte admin partage (nettoyage ponctuel +
  fixture de teardown automatique en filet de securite), suite complete
  verte (591 tests Python, 241 tests JS).
- SonarQube Community Build self-heberge (Docker + PostgreSQL) : rapport
  complet analyse point par point, faux positifs documentes.
- .gitattributes ajoute (LF force) : core.autocrlf=true sur cette machine
  faisait echouer ESLint (linebreak-style) via un bug connu de git
  (checkout "en place" qui ignore l'eol force sur un fichier deja
  present sur disque - contourne en supprimant puis recreant chaque
  fichier suivi).

djLint (H021, styles inline) volontairement saute pour ce commit -
backlog assume, deja documente, traite dans un lot separe.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
william
2026-09-15 16:06:15 +02:00
co-authored by Claude Sonnet 5
parent 7db4803b93
commit c57420c8c9
454 changed files with 16448 additions and 6967 deletions
+58 -40
View File
@@ -1,13 +1,13 @@
import json
from typing import Any
from flask import render_template, request, abort, g, url_for
from flask import abort, g, render_template, request, url_for
import auth
import db
import screens
def render_scene_edit(slug, screen_id, game):
def render_scene_edit(slug: str, screen_id: int, game: dict[str, Any]) -> str:
"""Vue de l'éditeur de scène 2D — appelée par routes/screens/
screen_edit.py (le dispatcher, selon screen["kind"]), PAS une route
Flask elle-même : même URL/endpoint "screen_edit" pour les deux types
@@ -73,10 +73,7 @@ def render_scene_edit(slug, screen_id, game):
quiz_box_config = screens.resolve_quiz_box_config(selected_obj)
_DEFAULT_OBJECT_LABELS = {"personnage": "Personnage", "fond": "Fond"}
object_labels = {
o["id"]: (o.get("name") or _DEFAULT_OBJECT_LABELS.get(o["kind"], "Décor"))
for o in objects
}
object_labels = {o["id"]: (o.get("name") or _DEFAULT_OBJECT_LABELS.get(o["kind"], "Décor")) for o in objects}
element_animations_map = {
o["id"]: screens.resolve_personnage_animations(o) for o in objects if o["kind"] == "personnage"
}
@@ -134,13 +131,19 @@ def render_scene_edit(slug, screen_id, game):
return render_template(
"scene_edit.html",
game=game, screen=screen, all_screens=all_screens,
world_width=world_width, world_height=world_height,
game=game,
screen=screen,
all_screens=all_screens,
world_width=world_width,
world_height=world_height,
any_quiz_box_fullscreen=any_quiz_box_fullscreen,
objects=objects, selected_id=selected_id, personnage_data=personnage_data,
objects=objects,
selected_id=selected_id,
personnage_data=personnage_data,
personnage_commands=personnage_commands or screens.DEFAULT_PERSONNAGE_COMMANDS,
personnage_role=personnage_role or screens.DEFAULT_PERSONNAGE_ROLE,
personnage_role_choices=screens.PERSONNAGE_ROLES, personnage_role_labels=screens.PERSONNAGE_ROLE_LABELS,
personnage_role_choices=screens.PERSONNAGE_ROLES,
personnage_role_labels=screens.PERSONNAGE_ROLE_LABELS,
collision_settings=collision_settings or screens.DEFAULT_COLLISION_SETTINGS,
dialogue_box_style=dialogue_box_style or screens.DEFAULT_DIALOGUE_BOX_STYLE,
dialogue_box_font_weight_choices=screens.FONT_WEIGHT_CHOICES,
@@ -150,49 +153,64 @@ def render_scene_edit(slug, screen_id, game):
quiz_box_dialog_template_labels=screens.QUIZ_BOX_DIALOG_TEMPLATE_LABELS,
quiz_box_page_templates=screens.QUIZ_BOX_PAGE_TEMPLATES,
quiz_box_page_template_labels=screens.QUIZ_BOX_PAGE_TEMPLATE_LABELS,
sprite_library=sprite_library, sprite_library_families=sprite_library_families,
sprite_library_json=json.dumps(sprite_library),
sprite_library=sprite_library,
sprite_library_families=sprite_library_families,
sprite_library_json=db.json_for_script(sprite_library),
background_library=background_library,
user_assets_fond=user_assets_fond, user_assets_decor=user_assets_decor,
user_assets_audio=user_assets_audio, user_assets_video=user_assets_video,
element_animations_map_json=json.dumps(element_animations_map),
user_assets_fond=user_assets_fond,
user_assets_decor=user_assets_decor,
user_assets_audio=user_assets_audio,
user_assets_video=user_assets_video,
element_animations_map_json=db.json_for_script(element_animations_map),
element_orientation_values=screens.ELEMENT_ORIENTATION_VALUES,
element_orientation_labels_json=json.dumps(screens.ELEMENT_ORIENTATION_LABELS),
element_orientation_labels_json=db.json_for_script(screens.ELEMENT_ORIENTATION_LABELS),
element_visibility_values=screens.ELEMENT_VISIBILITY_VALUES,
element_visibility_labels_json=json.dumps(screens.ELEMENT_VISIBILITY_LABELS),
trigger_events=screens.TRIGGER_EVENTS_2D, action_type_labels=screens.ACTION_TYPE_LABELS_2D,
element_visibility_labels_json=db.json_for_script(screens.ELEMENT_VISIBILITY_LABELS),
trigger_events=screens.TRIGGER_EVENTS_2D,
action_type_labels=screens.ACTION_TYPE_LABELS_2D,
object_action_properties=screens.OBJECT_ACTION_PROPERTIES,
element_action_property_labels_json=json.dumps(dict(screens.OBJECT_ACTION_PROPERTIES)),
element_action_property_labels_json=db.json_for_script(dict(screens.OBJECT_ACTION_PROPERTIES)),
condition_operators=screens.CONDITION_OPERATORS,
data_operations=screens.DATA_OPERATIONS, data_operation_labels=screens.DATA_OPERATION_LABELS,
data_operations=screens.DATA_OPERATIONS,
data_operation_labels=screens.DATA_OPERATION_LABELS,
score_status_choices=db.SCORE_STATUS_CHOICES,
score_status_labels_json=json.dumps(db.SCORE_STATUS_LABELS),
data_operation_labels_json=json.dumps(screens.DATA_OPERATION_LABELS),
condition_operator_labels_json=json.dumps(screens.CONDITION_OPERATOR_LABELS),
action_type_labels_json=json.dumps(screens.ACTION_TYPE_LABELS_2D),
elements_labels_json=json.dumps(object_labels), screens_map_json=json.dumps(screens_map),
flow_nodes=flow_nodes, flow_edges=flow_edges,
flow_nodes_json=json.dumps(flow_nodes), flow_edges_json=json.dumps(flow_edges),
flow_blocks_json=json.dumps(flow_blocks), blocks_view=blocks_view,
animation_clips=animation_clips, animation_clips_json=json.dumps(animation_clips),
animate_css_catalog=screens.ANIMATE_CSS_CATALOG, animate_css_labels_json=json.dumps(screens.ANIMATE_CSS_LABELS),
global_variables=global_variables, global_variable_types=db.GLOBAL_VARIABLE_TYPES,
custom_events=custom_events, custom_event_usages=custom_event_usages,
custom_events_map_json=json.dumps(custom_events_map),
score_status_labels_json=db.json_for_script(db.SCORE_STATUS_LABELS),
data_operation_labels_json=db.json_for_script(screens.DATA_OPERATION_LABELS),
condition_operator_labels_json=db.json_for_script(screens.CONDITION_OPERATOR_LABELS),
action_type_labels_json=db.json_for_script(screens.ACTION_TYPE_LABELS_2D),
elements_labels_json=db.json_for_script(object_labels),
screens_map_json=db.json_for_script(screens_map),
flow_nodes=flow_nodes,
flow_edges=flow_edges,
flow_nodes_json=db.json_for_script(flow_nodes),
flow_edges_json=db.json_for_script(flow_edges),
flow_blocks_json=db.json_for_script(flow_blocks),
blocks_view=blocks_view,
animation_clips=animation_clips,
animation_clips_json=db.json_for_script(animation_clips),
animate_css_catalog=screens.ANIMATE_CSS_CATALOG,
animate_css_labels_json=db.json_for_script(screens.ANIMATE_CSS_LABELS),
global_variables=global_variables,
global_variable_types=db.GLOBAL_VARIABLE_TYPES,
custom_events=custom_events,
custom_event_usages=custom_event_usages,
custom_events_map_json=db.json_for_script(custom_events_map),
definitions=db.list_definitions(slug),
definitions_json=json.dumps({str(d["id"]): screens.data_definition_options(slug, d["id"]) for d in db.list_definitions(slug)}),
definitions_names_json=json.dumps({d["id"]: d["name"] for d in db.list_definitions(slug)}),
definitions_json=db.json_for_script(
{str(d["id"]): screens.data_definition_options(slug, d["id"]) for d in db.list_definitions(slug)}
),
definitions_names_json=db.json_for_script({d["id"]: d["name"] for d in db.list_definitions(slug)}),
# "qui parle" dans un dialogue de déclencheur (voir "ℹ️
# Informations", static/js/triggers/trigger-editor.js) : les noms
# donnés à N'IMPORTE QUEL objet de scène (personnage, décor,
# fond), toutes scènes du jeu confondues.
scene_object_names_json=json.dumps(screens.list_named_scene_object_names(slug)),
scene_object_names_json=db.json_for_script(screens.list_named_scene_object_names(slug)),
# Nouveaux déclencheurs/actions (voir screens/rendering/
# collision_rules.py, screens/rendering/screen_triggers.py) :
# vocabulaire des nouvelles actions feuilles + assets disponibles
# pour "son"/"vidéo", posés en JS comme le reste ci-dessus.
surbrillance_labels_json=json.dumps(screens.SURBRILLANCE_LABELS),
video_mode_labels_json=json.dumps(screens.VIDEO_MODE_LABELS),
user_assets_options_json=json.dumps(user_assets_options),
surbrillance_labels_json=db.json_for_script(screens.SURBRILLANCE_LABELS),
video_mode_labels_json=db.json_for_script(screens.VIDEO_MODE_LABELS),
user_assets_options_json=db.json_for_script(user_assets_options),
screen_triggers=screens.resolve_screen_triggers(screen),
)