Phase 3 : hardening qualite de code - typage strict, securite, dead code, a11y
Config strictement stricte partout (ruff, mypy --strict, bandit, vulture, import-linter, eslint, stylelint), aucune regle desactivee "pour ne pas casser le build" - l'existant a ete corrige pour la satisfaire plutot que l'inverse. Hooks pre-commit locaux (language: system) bloquants. - Typage mypy --strict propage a tout le moteur (db, screens, auth, core, ai, routes, puis publish/scripts/tests/app.py/build_css.py). - Securite : fuite de handle fichier Windows corrigee dans l'export SCORM (routes/publish/export_scorm.py), CSRF/RNG non-crypto/xAPI documentes (# nosec, # NOSONAR justifies), nouveau db.json_for_script() (echappe "</script>" dans le JSON embarque en <script>, 25 sites). - Architecture : imports circulaires/F811 nettoyes, contrats import-linter respectes, code mort retire (vulture). - Accessibilite : 69 champs de formulaire sans label correctement associe corriges (for/id ou aria-label) sur 11 templates. - ESLint/Stylelint : lot mecanique JS/CSS, regles ajustees puis appliquees (aucune desactivee sans verification individuelle). - Tests : isolation du compte admin partage (nettoyage ponctuel + fixture de teardown automatique en filet de securite), suite complete verte (591 tests Python, 241 tests JS). - SonarQube Community Build self-heberge (Docker + PostgreSQL) : rapport complet analyse point par point, faux positifs documentes. - .gitattributes ajoute (LF force) : core.autocrlf=true sur cette machine faisait echouer ESLint (linebreak-style) via un bug connu de git (checkout "en place" qui ignore l'eol force sur un fichier deja present sur disque - contourne en supprimant puis recreant chaque fichier suivi). djLint (H021, styles inline) volontairement saute pour ce commit - backlog assume, deja documente, traite dans un lot separe. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
7db4803b93
commit
c57420c8c9
@@ -24,7 +24,18 @@ _DECOR_DEFAULT_SIZE = (200, 200)
|
||||
_DECOR_COLLISION_SIZE = (150, 150)
|
||||
|
||||
|
||||
def add_scene_object(slug, scene_id, kind="personnage", forge_character=None, background_slug=None, image_url=None, image_width=None, image_height=None, x=None, y=None):
|
||||
def add_scene_object(
|
||||
slug: str,
|
||||
scene_id: int,
|
||||
kind: str = "personnage",
|
||||
forge_character: str | None = None,
|
||||
background_slug: str | None = None,
|
||||
image_url: str | None = None,
|
||||
image_width: int | None = None,
|
||||
image_height: int | None = None,
|
||||
x: float | None = None,
|
||||
y: float | None = None,
|
||||
) -> int:
|
||||
"""Pose un nouvel objet sur une scène (voir ensure_scene_schema.py).
|
||||
kind="personnage" : attributes._personnage_data, MÊME structure/mêmes
|
||||
fonctions resolve_personnage_* que le widget "personnage" de l'éditeur
|
||||
@@ -64,8 +75,9 @@ def add_scene_object(slug, scene_id, kind="personnage", forge_character=None, ba
|
||||
if kind == "personnage":
|
||||
data = dict(_DEFAULT_PERSONNAGE_DATA)
|
||||
if forge_character:
|
||||
from ..labels.sprite_library import PUBLIC_SPRITE_LIBRARY
|
||||
from ..labels.animal_sprite_library import ADMIN_SPRITE_LIBRARY
|
||||
from ..labels.sprite_library import PUBLIC_SPRITE_LIBRARY
|
||||
|
||||
if forge_character in PUBLIC_SPRITE_LIBRARY or forge_character in ADMIN_SPRITE_LIBRARY:
|
||||
data["forge_character"] = forge_character
|
||||
attributes["_personnage_data"] = json.dumps(data)
|
||||
@@ -86,11 +98,15 @@ def add_scene_object(slug, scene_id, kind="personnage", forge_character=None, ba
|
||||
elif kind == "decor" and image_url:
|
||||
attributes["src"] = image_url
|
||||
width, height = _DECOR_DEFAULT_SIZE
|
||||
attributes["_collision"] = json.dumps({
|
||||
"width": _DECOR_COLLISION_SIZE[0], "height": _DECOR_COLLISION_SIZE[1],
|
||||
})
|
||||
attributes["_collision"] = json.dumps(
|
||||
{
|
||||
"width": _DECOR_COLLISION_SIZE[0],
|
||||
"height": _DECOR_COLLISION_SIZE[1],
|
||||
}
|
||||
)
|
||||
elif kind == "fond" and background_slug:
|
||||
from ..labels.background_library import BACKGROUND_LIBRARY
|
||||
|
||||
background = BACKGROUND_LIBRARY.get(background_slug)
|
||||
if background:
|
||||
attributes["src"] = background["url"]
|
||||
@@ -104,9 +120,9 @@ def add_scene_object(slug, scene_id, kind="personnage", forge_character=None, ba
|
||||
if kind == "fond":
|
||||
z_index = -1000
|
||||
else:
|
||||
max_z = conn.execute(
|
||||
"SELECT MAX(z_index) AS m FROM _scene_objects WHERE scene_id = ?", (scene_id,)
|
||||
).fetchone()["m"]
|
||||
max_z = conn.execute("SELECT MAX(z_index) AS m FROM _scene_objects WHERE scene_id = ?", (scene_id,)).fetchone()[
|
||||
"m"
|
||||
]
|
||||
z_index = (max_z or 0) + 1
|
||||
cols = ["scene_id", "kind", "attributes", "z_index"]
|
||||
values = [scene_id, kind, json.dumps(attributes), z_index]
|
||||
@@ -123,8 +139,8 @@ def add_scene_object(slug, scene_id, kind="personnage", forge_character=None, ba
|
||||
cols += ["x", "y"]
|
||||
values += [x, y]
|
||||
placeholders = ", ".join(["?"] * len(values))
|
||||
conn.execute(f"INSERT INTO _scene_objects ({', '.join(cols)}) VALUES ({placeholders})", values)
|
||||
object_id = conn.execute("SELECT last_insert_rowid() AS id").fetchone()["id"]
|
||||
conn.execute(f"INSERT INTO _scene_objects ({', '.join(cols)}) VALUES ({placeholders})", values) # nosec B608 # noqa: S608 - cols construit uniquement a partir de litteraux Python, jamais d'une cle arbitraire ; valeurs parametrees (?)
|
||||
object_id = int(conn.execute("SELECT last_insert_rowid() AS id").fetchone()["id"])
|
||||
conn.commit()
|
||||
conn.close()
|
||||
return object_id
|
||||
|
||||
Reference in New Issue
Block a user