Phase 3 : hardening qualite de code - typage strict, securite, dead code, a11y

Config strictement stricte partout (ruff, mypy --strict, bandit, vulture,
import-linter, eslint, stylelint), aucune regle desactivee "pour ne pas
casser le build" - l'existant a ete corrige pour la satisfaire plutot que
l'inverse. Hooks pre-commit locaux (language: system) bloquants.

- Typage mypy --strict propage a tout le moteur (db, screens, auth, core,
  ai, routes, puis publish/scripts/tests/app.py/build_css.py).
- Securite : fuite de handle fichier Windows corrigee dans l'export SCORM
  (routes/publish/export_scorm.py), CSRF/RNG non-crypto/xAPI documentes
  (# nosec, # NOSONAR justifies), nouveau db.json_for_script() (echappe
  "</script>" dans le JSON embarque en <script>, 25 sites).
- Architecture : imports circulaires/F811 nettoyes, contrats
  import-linter respectes, code mort retire (vulture).
- Accessibilite : 69 champs de formulaire sans label correctement
  associe corriges (for/id ou aria-label) sur 11 templates.
- ESLint/Stylelint : lot mecanique JS/CSS, regles ajustees puis
  appliquees (aucune desactivee sans verification individuelle).
- Tests : isolation du compte admin partage (nettoyage ponctuel +
  fixture de teardown automatique en filet de securite), suite complete
  verte (591 tests Python, 241 tests JS).
- SonarQube Community Build self-heberge (Docker + PostgreSQL) : rapport
  complet analyse point par point, faux positifs documentes.
- .gitattributes ajoute (LF force) : core.autocrlf=true sur cette machine
  faisait echouer ESLint (linebreak-style) via un bug connu de git
  (checkout "en place" qui ignore l'eol force sur un fichier deja
  present sur disque - contourne en supprimant puis recreant chaque
  fichier suivi).

djLint (H021, styles inline) volontairement saute pour ce commit -
backlog assume, deja documente, traite dans un lot separe.

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
william
2026-09-15 16:06:15 +02:00
co-authored by Claude Sonnet 5
parent 7db4803b93
commit c57420c8c9
454 changed files with 16448 additions and 6967 deletions
+62 -37
View File
@@ -5,20 +5,25 @@ réutilise TELLE QUELLE la structure _personnage_data et les fonctions
resolve_personnage_* déjà écrites pour le widget "personnage" de
l'éditeur document (Phase 8) — même bibliothèque Forge, même moteur
d'animation côté client, juste une autre table de stockage."""
from collections.abc import Callable
from typing import Any
import db
import screens
from tests.conftest import not_none
def _create_jeu2d_game(tmp_game_slug_cleanup, name="pytest_scene_test"):
def _create_jeu2d_game(tmp_game_slug_cleanup: Callable[[str], str], name: str = "pytest_scene_test") -> Any:
slug = tmp_game_slug_cleanup(db.create_game(name))
screen_id = screens.create_screen(slug, "Scène 1", kind="jeu_2d")
return slug, screen_id
def test_scene_object_defaults_to_forge_personnage(tmp_game_slug_cleanup):
def test_scene_object_defaults_to_forge_personnage(tmp_game_slug_cleanup: Callable[[str], str]) -> None:
slug, screen_id = _create_jeu2d_game(tmp_game_slug_cleanup)
obj_id = screens.add_scene_object(slug, screen_id)
obj = screens.get_scene_object(slug, obj_id)
obj = not_none(screens.get_scene_object(slug, obj_id))
assert obj["kind"] == "personnage"
assert obj["attributes"]["_personnage_data"]
data = screens.resolve_personnage_data(obj)
@@ -26,21 +31,23 @@ def test_scene_object_defaults_to_forge_personnage(tmp_game_slug_cleanup):
assert data["forge_character"] in screens.SPRITE_LIBRARY
def test_add_scene_object_with_specific_forge_character(tmp_game_slug_cleanup):
def test_add_scene_object_with_specific_forge_character(tmp_game_slug_cleanup: Callable[[str], str]) -> None:
slug, screen_id = _create_jeu2d_game(tmp_game_slug_cleanup)
obj_id = screens.add_scene_object(slug, screen_id, kind="personnage", forge_character="zombie")
obj = screens.get_scene_object(slug, obj_id)
obj = not_none(screens.get_scene_object(slug, obj_id))
assert screens.resolve_personnage_data(obj)["forge_character"] == "zombie"
def test_add_decor_scene_object(tmp_game_slug_cleanup):
def test_add_decor_scene_object(tmp_game_slug_cleanup: Callable[[str], str]) -> None:
slug, screen_id = _create_jeu2d_game(tmp_game_slug_cleanup)
obj_id = screens.add_scene_object(slug, screen_id, kind="decor")
obj = screens.get_scene_object(slug, obj_id)
obj = not_none(screens.get_scene_object(slug, obj_id))
assert obj["kind"] == "decor"
def test_add_decor_scene_object_with_an_image_defaults_to_200x200_with_a_150x150_collision_box(tmp_game_slug_cleanup):
def test_add_decor_scene_object_with_an_image_defaults_to_200x200_with_a_150x150_collision_box(
tmp_game_slug_cleanup: Callable[[str], str],
) -> None:
"""Demande explicite : un objet/décor posé depuis "Mes assets" doit
toujours démarrer à 200×200 (jamais la taille réelle, souvent bien
plus grande, ni le défaut 128×128 du schéma), avec une boîte de
@@ -48,34 +55,40 @@ def test_add_decor_scene_object_with_an_image_defaults_to_200x200_with_a_150x150
silhouette réelle."""
slug, screen_id = _create_jeu2d_game(tmp_game_slug_cleanup)
obj_id = screens.add_scene_object(slug, screen_id, kind="decor", image_url="/assets/1/photo.png")
obj = screens.get_scene_object(slug, obj_id)
obj = not_none(screens.get_scene_object(slug, obj_id))
assert (obj["width"], obj["height"]) == (200, 200)
collision = screens.resolve_collision_settings(obj)
assert (collision["width"], collision["height"]) == (150, 150)
def test_add_decor_scene_object_with_an_image_ignores_real_image_dimensions(tmp_game_slug_cleanup):
def test_add_decor_scene_object_with_an_image_ignores_real_image_dimensions(
tmp_game_slug_cleanup: Callable[[str], str],
) -> None:
"""Contrairement à "fond" (voir add_scene_object.py), un "decor" ne
doit JAMAIS être posé à la taille réelle de l'image importée — même
quand elle est connue (image_width/image_height fournis)."""
slug, screen_id = _create_jeu2d_game(tmp_game_slug_cleanup)
obj_id = screens.add_scene_object(
slug, screen_id, kind="decor", image_url="/assets/1/photo.png",
image_width=5504, image_height=3072,
slug,
screen_id,
kind="decor",
image_url="/assets/1/photo.png",
image_width=5504,
image_height=3072,
)
obj = screens.get_scene_object(slug, obj_id)
obj = not_none(screens.get_scene_object(slug, obj_id))
assert (obj["width"], obj["height"]) == (200, 200)
def test_scene_object_geometry_is_pixels_not_percent(tmp_game_slug_cleanup):
def test_scene_object_geometry_is_pixels_not_percent(tmp_game_slug_cleanup: Callable[[str], str]) -> None:
slug, screen_id = _create_jeu2d_game(tmp_game_slug_cleanup)
obj_id = screens.add_scene_object(slug, screen_id)
screens.update_scene_object_geometry(slug, obj_id, x=320, y=200, width=128, height=128)
obj = screens.get_scene_object(slug, obj_id)
obj = not_none(screens.get_scene_object(slug, obj_id))
assert (obj["x"], obj["y"], obj["width"], obj["height"]) == (320, 200, 128, 128)
def test_list_scene_objects_ordered_by_z_index(tmp_game_slug_cleanup):
def test_list_scene_objects_ordered_by_z_index(tmp_game_slug_cleanup: Callable[[str], str]) -> None:
slug, screen_id = _create_jeu2d_game(tmp_game_slug_cleanup)
first = screens.add_scene_object(slug, screen_id)
second = screens.add_scene_object(slug, screen_id)
@@ -83,19 +96,19 @@ def test_list_scene_objects_ordered_by_z_index(tmp_game_slug_cleanup):
assert [o["id"] for o in objs] == [first, second]
def test_swap_scene_object_forge_character(tmp_game_slug_cleanup):
def test_swap_scene_object_forge_character(tmp_game_slug_cleanup: Callable[[str], str]) -> None:
slug, screen_id = _create_jeu2d_game(tmp_game_slug_cleanup)
obj_id = screens.add_scene_object(slug, screen_id, forge_character="male-adventurer")
screens.set_scene_object_personnage_data(slug, obj_id, {"source": "forge", "forge_character": "robot"})
obj = screens.get_scene_object(slug, obj_id)
obj = not_none(screens.get_scene_object(slug, obj_id))
assert screens.resolve_personnage_data(obj)["forge_character"] == "robot"
def test_render_scene_object_shows_idle_frame_pixel_positioned(tmp_game_slug_cleanup):
def test_render_scene_object_shows_idle_frame_pixel_positioned(tmp_game_slug_cleanup: Callable[[str], str]) -> None:
slug, screen_id = _create_jeu2d_game(tmp_game_slug_cleanup)
obj_id = screens.add_scene_object(slug, screen_id, forge_character="zombie")
screens.update_scene_object_geometry(slug, obj_id, x=50, y=60, width=64, height=64)
obj = screens.get_scene_object(slug, obj_id)
obj = not_none(screens.get_scene_object(slug, obj_id))
html = screens.render_scene_object(obj)
assert "/static/characters/zombie/idle.png" in html
assert "left:50" in html and "top:60" in html
@@ -103,82 +116,94 @@ def test_render_scene_object_shows_idle_frame_pixel_positioned(tmp_game_slug_cle
assert 'data-personnage="1"' in html
def test_render_scene_object_alt_uses_the_authored_name_rgaa(tmp_game_slug_cleanup):
def test_render_scene_object_alt_uses_the_authored_name_rgaa(tmp_game_slug_cleanup: Callable[[str], str]) -> None:
"""RGAA/WCAG 1.1.1 : le nom donné par l'auteur (panneau "ℹ️
Informations") sert d'alternative textuelle — jamais aucun attribut
alt du tout n'était généré avant."""
slug, screen_id = _create_jeu2d_game(tmp_game_slug_cleanup)
obj_id = screens.add_scene_object(slug, screen_id, forge_character="zombie")
screens.set_scene_object_name(slug, obj_id, "Zombie du hangar")
obj = screens.get_scene_object(slug, obj_id)
obj = not_none(screens.get_scene_object(slug, obj_id))
html = screens.render_scene_object(obj)
assert 'alt="Zombie du hangar"' in html
def test_render_scene_object_alt_is_empty_when_unnamed_rgaa(tmp_game_slug_cleanup):
def test_render_scene_object_alt_is_empty_when_unnamed_rgaa(tmp_game_slug_cleanup: Callable[[str], str]) -> None:
"""alt="" (décoratif) plutôt qu'aucun attribut du tout quand l'auteur
n'a pas nommé l'objet."""
slug, screen_id = _create_jeu2d_game(tmp_game_slug_cleanup)
obj_id = screens.add_scene_object(slug, screen_id, forge_character="zombie")
obj = screens.get_scene_object(slug, obj_id)
obj = not_none(screens.get_scene_object(slug, obj_id))
html = screens.render_scene_object(obj)
assert 'alt=""' in html
def test_render_scene_object_fond_alt_is_always_empty_rgaa(tmp_game_slug_cleanup):
def test_render_scene_object_fond_alt_is_always_empty_rgaa(tmp_game_slug_cleanup: Callable[[str], str]) -> None:
"""Un "fond" est toujours décoratif — alt="" même s'il est nommé."""
slug, screen_id = _create_jeu2d_game(tmp_game_slug_cleanup)
obj_id = screens.add_scene_object(slug, screen_id, kind="fond", background_slug="foret")
screens.set_scene_object_name(slug, obj_id, "Grand décor de fond")
obj = screens.get_scene_object(slug, obj_id)
obj = not_none(screens.get_scene_object(slug, obj_id))
html = screens.render_scene_object(obj)
assert 'alt=""' in html
def test_add_scene_object_with_explicit_position_uses_it_instead_of_the_default(tmp_game_slug_cleanup):
def test_add_scene_object_with_explicit_position_uses_it_instead_of_the_default(
tmp_game_slug_cleanup: Callable[[str], str],
) -> None:
"""Vrai glisser-déposer depuis la galerie (demande explicite :
"n'importe où sur la scène") — x/y explicites remplacent le défaut
100/100 posé par le schéma (voir ensure_scene_schema.py)."""
slug, screen_id = _create_jeu2d_game(tmp_game_slug_cleanup)
obj_id = screens.add_scene_object(slug, screen_id, kind="decor", x=250, y=340)
obj = screens.get_scene_object(slug, obj_id)
obj = not_none(screens.get_scene_object(slug, obj_id))
assert obj["x"] == 250
assert obj["y"] == 340
def test_add_scene_object_without_position_still_defaults_to_100_100(tmp_game_slug_cleanup):
def test_add_scene_object_without_position_still_defaults_to_100_100(
tmp_game_slug_cleanup: Callable[[str], str],
) -> None:
slug, screen_id = _create_jeu2d_game(tmp_game_slug_cleanup)
obj_id = screens.add_scene_object(slug, screen_id, kind="decor")
obj = screens.get_scene_object(slug, obj_id)
obj = not_none(screens.get_scene_object(slug, obj_id))
assert obj["x"] == 100
assert obj["y"] == 100
def test_add_scene_object_fond_with_explicit_position_overrides_the_top_left_default(tmp_game_slug_cleanup):
def test_add_scene_object_fond_with_explicit_position_overrides_the_top_left_default(
tmp_game_slug_cleanup: Callable[[str], str],
) -> None:
"""Un "fond" reste au coin haut-gauche (0,0) SANS position explicite
(comportement inchangé), mais un glisser-déposer précis doit pouvoir
le positionner ailleurs si le créateur le demande explicitement."""
slug, screen_id = _create_jeu2d_game(tmp_game_slug_cleanup)
obj_id = screens.add_scene_object(slug, screen_id, kind="fond", background_slug="foret", x=50, y=60)
obj = screens.get_scene_object(slug, obj_id)
obj = not_none(screens.get_scene_object(slug, obj_id))
assert obj["x"] == 50
assert obj["y"] == 60
def test_add_scene_object_fond_without_position_still_defaults_to_top_left(tmp_game_slug_cleanup):
def test_add_scene_object_fond_without_position_still_defaults_to_top_left(
tmp_game_slug_cleanup: Callable[[str], str],
) -> None:
slug, screen_id = _create_jeu2d_game(tmp_game_slug_cleanup)
obj_id = screens.add_scene_object(slug, screen_id, kind="fond", background_slug="foret")
obj = screens.get_scene_object(slug, obj_id)
obj = not_none(screens.get_scene_object(slug, obj_id))
assert obj["x"] == 0
assert obj["y"] == 0
def test_delete_scene_object_cleans_up_referencing_flow_nodes(tmp_game_slug_cleanup):
def test_delete_scene_object_cleans_up_referencing_flow_nodes(tmp_game_slug_cleanup: Callable[[str], str]) -> None:
slug, screen_id = _create_jeu2d_game(tmp_game_slug_cleanup)
obj_id = screens.add_scene_object(slug, screen_id)
node_id = screens.add_flow_node(
slug, screen_id, node_type="action", action_type="jouer_animation_sprite",
target_object_id=obj_id, data_value='{"animation":"idle","fps":8,"loop":true}',
slug,
screen_id,
node_type="action",
action_type="jouer_animation_sprite",
target_object_id=obj_id,
data_value='{"animation":"idle","fps":8,"loop":true}',
)
screens.delete_scene_object(slug, obj_id)
assert screens.get_flow_node(slug, node_id) is None