Phase 3 : hardening qualite de code - typage strict, securite, dead code, a11y
Config strictement stricte partout (ruff, mypy --strict, bandit, vulture, import-linter, eslint, stylelint), aucune regle desactivee "pour ne pas casser le build" - l'existant a ete corrige pour la satisfaire plutot que l'inverse. Hooks pre-commit locaux (language: system) bloquants. - Typage mypy --strict propage a tout le moteur (db, screens, auth, core, ai, routes, puis publish/scripts/tests/app.py/build_css.py). - Securite : fuite de handle fichier Windows corrigee dans l'export SCORM (routes/publish/export_scorm.py), CSRF/RNG non-crypto/xAPI documentes (# nosec, # NOSONAR justifies), nouveau db.json_for_script() (echappe "</script>" dans le JSON embarque en <script>, 25 sites). - Architecture : imports circulaires/F811 nettoyes, contrats import-linter respectes, code mort retire (vulture). - Accessibilite : 69 champs de formulaire sans label correctement associe corriges (for/id ou aria-label) sur 11 templates. - ESLint/Stylelint : lot mecanique JS/CSS, regles ajustees puis appliquees (aucune desactivee sans verification individuelle). - Tests : isolation du compte admin partage (nettoyage ponctuel + fixture de teardown automatique en filet de securite), suite complete verte (591 tests Python, 241 tests JS). - SonarQube Community Build self-heberge (Docker + PostgreSQL) : rapport complet analyse point par point, faux positifs documentes. - .gitattributes ajoute (LF force) : core.autocrlf=true sur cette machine faisait echouer ESLint (linebreak-style) via un bug connu de git (checkout "en place" qui ignore l'eol force sur un fichier deja present sur disque - contourne en supprimant puis recreant chaque fichier suivi). djLint (H021, styles inline) volontairement saute pour ce commit - backlog assume, deja documente, traite dans un lot separe. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
This commit is contained in:
co-authored by
Claude Sonnet 5
parent
7db4803b93
commit
c57420c8c9
+25
-16
@@ -2,17 +2,20 @@
|
||||
produit" : concept de premier ordre, distinct des variables globales,
|
||||
préalable aux futurs exports SCORM/xAPI (qui ont besoin d'un signal
|
||||
"score"/"terminé" propre)."""
|
||||
|
||||
import json
|
||||
|
||||
from flask.testing import FlaskClient
|
||||
|
||||
import db
|
||||
import screens
|
||||
|
||||
|
||||
def test_get_score_defaults_before_any_write(game):
|
||||
def test_get_score_defaults_before_any_write(game: str) -> None:
|
||||
assert db.get_score(game) == {"player_id": db.PLAYER_SHARED, "score": 0, "status": "non_commence"}
|
||||
|
||||
|
||||
def test_set_score_value_and_status(game):
|
||||
def test_set_score_value_and_status(game: str) -> None:
|
||||
db.set_score_value(game, 42)
|
||||
db.set_status(game, "en_cours")
|
||||
score = db.get_score(game)
|
||||
@@ -20,12 +23,12 @@ def test_set_score_value_and_status(game):
|
||||
assert score["status"] == "en_cours"
|
||||
|
||||
|
||||
def test_set_status_rejects_unknown_value(game):
|
||||
def test_set_status_rejects_unknown_value(game: str) -> None:
|
||||
assert db.set_status(game, "n_importe_quoi") is False
|
||||
assert db.get_score(game)["status"] == "non_commence"
|
||||
|
||||
|
||||
def test_score_is_tracked_per_player(game):
|
||||
def test_score_is_tracked_per_player(game: str) -> None:
|
||||
db.set_score_value(game, 5, player_id="joueur-a")
|
||||
db.set_score_value(game, 99, player_id="joueur-b")
|
||||
assert db.get_score(game, "joueur-a")["score"] == 5
|
||||
@@ -33,7 +36,7 @@ def test_score_is_tracked_per_player(game):
|
||||
assert db.get_score(game)["score"] == 0 # PLAYER_SHARED (aperçu créateur) inchangé
|
||||
|
||||
|
||||
def test_apply_score_action_reuses_data_operations(game):
|
||||
def test_apply_score_action_reuses_data_operations(game: str) -> None:
|
||||
db.set_score_value(game, 10)
|
||||
ok = screens.apply_score_action(game, {"data_operation": "incrementer", "data_value": "5"})
|
||||
assert ok
|
||||
@@ -44,21 +47,23 @@ def test_apply_score_action_reuses_data_operations(game):
|
||||
assert db.get_score(game)["score"] == 100
|
||||
|
||||
|
||||
def test_apply_status_action_writes_status(game):
|
||||
def test_apply_status_action_writes_status(game: str) -> None:
|
||||
ok = screens.apply_status_action(game, {"data_value": "termine"})
|
||||
assert ok
|
||||
assert db.get_score(game)["status"] == "termine"
|
||||
|
||||
|
||||
def test_apply_status_action_rejects_missing_value(game):
|
||||
def test_apply_status_action_rejects_missing_value(game: str) -> None:
|
||||
assert screens.apply_status_action(game, {}) is False
|
||||
|
||||
|
||||
def test_flow_node_run_score_route(client, game):
|
||||
def test_flow_node_run_score_route(client: FlaskClient, game: str) -> None:
|
||||
screen_id = screens.create_screen(game, "Accueil")
|
||||
resp = client.post(
|
||||
f"/game/{game}/screens/{screen_id}/flow/nodes/add",
|
||||
data=json.dumps({"node_type": "action", "action_type": "modifier_score", "data_operation": "incrementer", "data_value": "7"}),
|
||||
data=json.dumps(
|
||||
{"node_type": "action", "action_type": "modifier_score", "data_operation": "incrementer", "data_value": "7"}
|
||||
),
|
||||
content_type="application/json",
|
||||
)
|
||||
node_id = resp.get_json()["id"]
|
||||
@@ -67,7 +72,7 @@ def test_flow_node_run_score_route(client, game):
|
||||
assert db.get_score(game)["score"] == 7
|
||||
|
||||
|
||||
def test_flow_node_run_score_route_rejects_wrong_action_type(client, game):
|
||||
def test_flow_node_run_score_route_rejects_wrong_action_type(client: FlaskClient, game: str) -> None:
|
||||
screen_id = screens.create_screen(game, "Accueil")
|
||||
resp = client.post(
|
||||
f"/game/{game}/screens/{screen_id}/flow/nodes/add",
|
||||
@@ -79,7 +84,7 @@ def test_flow_node_run_score_route_rejects_wrong_action_type(client, game):
|
||||
assert run_resp.status_code == 400
|
||||
|
||||
|
||||
def test_flow_node_run_status_route(client, game):
|
||||
def test_flow_node_run_status_route(client: FlaskClient, game: str) -> None:
|
||||
screen_id = screens.create_screen(game, "Accueil")
|
||||
resp = client.post(
|
||||
f"/game/{game}/screens/{screen_id}/flow/nodes/add",
|
||||
@@ -92,17 +97,19 @@ def test_flow_node_run_status_route(client, game):
|
||||
assert db.get_score(game)["status"] == "echoue"
|
||||
|
||||
|
||||
def test_game_scoring_view_route_reads_player_score(client, game):
|
||||
def test_game_scoring_view_route_reads_player_score(client: FlaskClient, game: str) -> None:
|
||||
db.set_score_value(game, 33, player_id="joueur-x")
|
||||
db.set_status(game, "reussi", player_id="joueur-x")
|
||||
resp = client.get(f"/game/{game}/scoring/joueur-x")
|
||||
assert resp.get_json() == {
|
||||
"player_id": "joueur-x", "score": 33, "status": "reussi",
|
||||
"player_id": "joueur-x",
|
||||
"score": 33,
|
||||
"status": "reussi",
|
||||
"updated_at": resp.get_json()["updated_at"],
|
||||
}
|
||||
|
||||
|
||||
def test_two_players_get_independent_scores(game):
|
||||
def test_two_players_get_independent_scores(game: str) -> None:
|
||||
"""Le score est TOUJOURS par joueur (voir db/scoring/), jamais partagé
|
||||
— même garantie que db/global_vars (voir tests/test_player_state.py),
|
||||
vérifiée ici directement au niveau db/ (routes publiques retirées)."""
|
||||
@@ -111,7 +118,9 @@ def test_two_players_get_independent_scores(game):
|
||||
db.set_score_value(game, 20, player_id="bob")
|
||||
|
||||
assert db.get_score(game, "alice") == {
|
||||
"player_id": "alice", "score": 10, "status": "reussi",
|
||||
"player_id": "alice",
|
||||
"score": 10,
|
||||
"status": "reussi",
|
||||
"updated_at": db.get_score(game, "alice")["updated_at"],
|
||||
}
|
||||
assert db.get_score(game, "bob")["score"] == 20
|
||||
@@ -119,7 +128,7 @@ def test_two_players_get_independent_scores(game):
|
||||
assert db.get_score(game)["score"] == 0 # aperçu créateur (PLAYER_SHARED) inchangé
|
||||
|
||||
|
||||
def test_editor_exposes_score_and_status_action_labels(client, game):
|
||||
def test_editor_exposes_score_and_status_action_labels(client: FlaskClient, game: str) -> None:
|
||||
screen_id = screens.create_screen(game, "Accueil")
|
||||
html = client.get(f"/game/{game}/screens/{screen_id}/edit").get_data(as_text=True)
|
||||
assert "Modifier le score" in html
|
||||
|
||||
Reference in New Issue
Block a user