feat(i18n): serve every page in 30 languages
The interface ships translated; page content stays English until a
LibreTranslate instance fills app/i18n/content/ through make i18n. A string
without a catalogue entry falls back to its English source, so a half-filled
catalogue degrades instead of breaking.
Translation runs after ConfigurationResolver.resolve_links(), on a copy.
resolve_links matches by the `name` field, so translating it beforehand
would break every `link:` reference in the configuration.
negotiate() normalises to the primary subtag itself. Werkzeug's best_match
returns an exact match before it considers a primary-tag fallback, so the
Chrome default `de-DE,en;q=0.8` resolves to English there. "/" carries
Vary: Accept-Language, without which a shared cache pins the first
visitor's language for everyone.
The route rule lists the known codes as a converter argument. A bare
"/<lang>/" answers /robots.txt and /favicon.ico with a permanently
cacheable 308 to their trailing-slash form.
Templates gain lang, dir, the RTL stylesheet, a canonical URL and 30
hreflang alternates. Those are the first external URLs in this app:
ProxyFix takes the scheme from X-Forwarded-Proto so they do not claim
http:// behind a TLS-terminating proxy, X-Forwarded-Host stays untrusted
because nginx passes a client-supplied one through, and TRUSTED_HOSTS lets
Flask reject a forged Host outright.
Flask only autoescapes .html/.htm/.xml/.xhtml/.svg, so every *.html.j2
template interpolated configuration raw. Enabling it changes two lines of
the shipped page, both an apostrophe.
read_catalog degrades an unreadable catalogue to English rather than
serving a 500, and drops non-string entries that would otherwise render as
"42". i18n_sync writes atomically, never overwrites an existing entry,
refuses to touch a catalogue it could not parse, and leaves the file alone
when a run translated nothing.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-22 00:02:35 +02:00
|
|
|
"""Guards for configuration that no other test observes.
|
|
|
|
|
|
|
|
|
|
Each assertion here stands for a defect that was found by deleting the line it
|
|
|
|
|
checks: the deletion is invisible to every suite, and its effect only shows up
|
|
|
|
|
in production or in a fresh checkout.
|
|
|
|
|
"""
|
|
|
|
|
|
fix(app): stop trusting X-Forwarded-For, and pin what the audit found
ProxyFix defaults x_for to 1, so ProxyFix(app.wsgi_app, x_proto=1) never
disabled it: request.remote_addr and the access log were forgeable by any
client that reached the app directly. It is x_for=0 now, asserted rather
than assumed.
A mutation audit over the change set reverted 196 deliberate behaviours
and found 47 that no test noticed. This closes the ones that carry damage:
- apod_background lost its key check, its transport guard, its status
guard and its media-type check without a single test failing. Each one
turns a slow or unhappy NASA into a 500 on every page.
- Untrusted values reached innerHTML through window.I18N, which the
translation backend writes, and the modal's click handlers stacked so a
later click opened an earlier popup's URL.
- The sync tool could ask for HTML instead of text, translate from "auto"
instead of English, run without a timeout, store an empty translation
that marks the string done for good, abandon 28 languages because one
could not be written, and report success after reaching nothing.
- Neither the lint target, the CI jobs, the vendored RTL stylesheet, the
documented environment keys, nor any of the four hardenings in
scripts/run-e2e.sh was observed by anything.
Three of the new tests passed for the wrong reason on their first cut —
a mock that answered None whether or not the guard existed, a
raise_for_status that was never called, a string that stayed in the file
after the mutation. The audit found those too; all 24 reverts now fail.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-22 10:02:54 +02:00
|
|
|
import json
|
feat(i18n): serve every page in 30 languages
The interface ships translated; page content stays English until a
LibreTranslate instance fills app/i18n/content/ through make i18n. A string
without a catalogue entry falls back to its English source, so a half-filled
catalogue degrades instead of breaking.
Translation runs after ConfigurationResolver.resolve_links(), on a copy.
resolve_links matches by the `name` field, so translating it beforehand
would break every `link:` reference in the configuration.
negotiate() normalises to the primary subtag itself. Werkzeug's best_match
returns an exact match before it considers a primary-tag fallback, so the
Chrome default `de-DE,en;q=0.8` resolves to English there. "/" carries
Vary: Accept-Language, without which a shared cache pins the first
visitor's language for everyone.
The route rule lists the known codes as a converter argument. A bare
"/<lang>/" answers /robots.txt and /favicon.ico with a permanently
cacheable 308 to their trailing-slash form.
Templates gain lang, dir, the RTL stylesheet, a canonical URL and 30
hreflang alternates. Those are the first external URLs in this app:
ProxyFix takes the scheme from X-Forwarded-Proto so they do not claim
http:// behind a TLS-terminating proxy, X-Forwarded-Host stays untrusted
because nginx passes a client-supplied one through, and TRUSTED_HOSTS lets
Flask reject a forged Host outright.
Flask only autoescapes .html/.htm/.xml/.xhtml/.svg, so every *.html.j2
template interpolated configuration raw. Enabling it changes two lines of
the shipped page, both an apostrophe.
read_catalog degrades an unreadable catalogue to English rather than
serving a 500, and drops non-string entries that would otherwise render as
"42". i18n_sync writes atomically, never overwrites an existing entry,
refuses to touch a catalogue it could not parse, and leaves the file alone
when a run translated nothing.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-22 00:02:35 +02:00
|
|
|
import re
|
|
|
|
|
import tomllib
|
|
|
|
|
import unittest
|
|
|
|
|
from pathlib import Path
|
|
|
|
|
|
|
|
|
|
import yaml
|
|
|
|
|
|
|
|
|
|
REPO_ROOT = Path(__file__).resolve().parents[2]
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
class TestYamllintConfiguration(unittest.TestCase):
|
|
|
|
|
def setUp(self):
|
|
|
|
|
self.config = yaml.safe_load(
|
|
|
|
|
(REPO_ROOT / ".yamllint").read_text(encoding="utf-8")
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
def test_duplicate_keys_are_an_error(self):
|
|
|
|
|
self.assertEqual(self.config["rules"]["key-duplicates"], "enable")
|
|
|
|
|
|
|
|
|
|
def test_the_directories_that_collect_foreign_yaml_are_ignored(self):
|
|
|
|
|
ignored = self.config["ignore"].split()
|
|
|
|
|
|
|
|
|
|
self.assertGreaterEqual(
|
|
|
|
|
set(ignored),
|
|
|
|
|
{".git/", ".venv/", "node_modules/", "app/node_modules/"},
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
class TestRunTargets(unittest.TestCase):
|
|
|
|
|
def setUp(self):
|
|
|
|
|
self.makefile = (REPO_ROOT / "Makefile").read_text(encoding="utf-8")
|
|
|
|
|
self.recipes = {
|
|
|
|
|
name: body
|
|
|
|
|
for name, body in re.findall(
|
|
|
|
|
r"^(run-dev|run-prod):[^\n]*\n((?:\t[^\n]*\n)+)",
|
|
|
|
|
self.makefile,
|
|
|
|
|
re.MULTILINE,
|
|
|
|
|
)
|
|
|
|
|
}
|
|
|
|
|
|
|
|
|
|
def test_both_run_targets_exist(self):
|
|
|
|
|
self.assertEqual(set(self.recipes), {"run-dev", "run-prod"})
|
|
|
|
|
|
|
|
|
|
def test_the_container_is_told_which_hosts_are_trusted(self):
|
|
|
|
|
for name, body in self.recipes.items():
|
|
|
|
|
with self.subTest(target=name):
|
|
|
|
|
self.assertIn("TRUSTED_HOSTS", body)
|
|
|
|
|
|
|
|
|
|
def test_the_container_is_told_which_port_to_bind(self):
|
|
|
|
|
for name, body in self.recipes.items():
|
|
|
|
|
with self.subTest(target=name):
|
|
|
|
|
self.assertIn('-e PORT="$$PORT"', body)
|
|
|
|
|
|
|
|
|
|
def test_the_whole_env_file_is_not_handed_to_the_web_container(self):
|
|
|
|
|
for name, body in self.recipes.items():
|
|
|
|
|
with self.subTest(target=name):
|
|
|
|
|
self.assertNotIn("--env-file", body)
|
|
|
|
|
|
|
|
|
|
|
fix(app): stop trusting X-Forwarded-For, and pin what the audit found
ProxyFix defaults x_for to 1, so ProxyFix(app.wsgi_app, x_proto=1) never
disabled it: request.remote_addr and the access log were forgeable by any
client that reached the app directly. It is x_for=0 now, asserted rather
than assumed.
A mutation audit over the change set reverted 196 deliberate behaviours
and found 47 that no test noticed. This closes the ones that carry damage:
- apod_background lost its key check, its transport guard, its status
guard and its media-type check without a single test failing. Each one
turns a slow or unhappy NASA into a 500 on every page.
- Untrusted values reached innerHTML through window.I18N, which the
translation backend writes, and the modal's click handlers stacked so a
later click opened an earlier popup's URL.
- The sync tool could ask for HTML instead of text, translate from "auto"
instead of English, run without a timeout, store an empty translation
that marks the string done for good, abandon 28 languages because one
could not be written, and report success after reaching nothing.
- Neither the lint target, the CI jobs, the vendored RTL stylesheet, the
documented environment keys, nor any of the four hardenings in
scripts/run-e2e.sh was observed by anything.
Three of the new tests passed for the wrong reason on their first cut —
a mock that answered None whether or not the guard existed, a
raise_for_status that was never called, a string that stayed in the file
after the mutation. The audit found those too; all 24 reverts now fail.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-22 10:02:54 +02:00
|
|
|
class TestLintCoverage(unittest.TestCase):
|
|
|
|
|
def setUp(self):
|
|
|
|
|
self.makefile = (REPO_ROOT / "Makefile").read_text(encoding="utf-8")
|
|
|
|
|
|
|
|
|
|
def test_the_lint_target_runs_every_linter(self):
|
|
|
|
|
prerequisites = re.search(r"^lint: (.+)$", self.makefile, re.MULTILINE).group(1)
|
|
|
|
|
|
|
|
|
|
self.assertGreaterEqual(
|
|
|
|
|
set(prerequisites.split()),
|
|
|
|
|
{"lint-actions", "lint-python", "lint-yaml", "lint-js", "lint-shell"},
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
def test_every_linter_has_a_ci_job(self):
|
|
|
|
|
workflow = yaml.safe_load(
|
|
|
|
|
(REPO_ROOT / ".github" / "workflows" / "lint.yml").read_text(
|
|
|
|
|
encoding="utf-8"
|
|
|
|
|
)
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
self.assertGreaterEqual(
|
|
|
|
|
set(workflow["jobs"]),
|
|
|
|
|
{"lint-actions", "lint-python", "lint-yaml", "lint-js", "lint-shell"},
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
def test_the_javascript_linter_is_declared(self):
|
|
|
|
|
package = json.loads(
|
|
|
|
|
(REPO_ROOT / "app" / "package.json").read_text(encoding="utf-8")
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
self.assertGreaterEqual(
|
|
|
|
|
set(package["devDependencies"]), {"eslint", "@eslint/js", "globals"}
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
def test_the_documented_environment_keys_exist(self):
|
|
|
|
|
example = (REPO_ROOT / "env.example").read_text(encoding="utf-8")
|
|
|
|
|
|
|
|
|
|
for key in ("PORT", "IMAGE_NAME", "TRUSTED_HOSTS", "LIBRETRANSLATE_URL"):
|
|
|
|
|
with self.subTest(key=key):
|
|
|
|
|
self.assertRegex(example, rf"(?m)^{key}=")
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
class TestEndToEndRunner(unittest.TestCase):
|
|
|
|
|
def setUp(self):
|
|
|
|
|
self.script = (REPO_ROOT / "scripts" / "run-e2e.sh").read_text(encoding="utf-8")
|
|
|
|
|
|
|
|
|
|
def test_a_foreign_listener_stops_the_run(self):
|
|
|
|
|
self.assertIn("already serves port", self.script)
|
|
|
|
|
|
|
|
|
|
def test_cypress_is_pinned_to_the_origin_flask_binds(self):
|
|
|
|
|
self.assertIn("CYPRESS_baseUrl", self.script)
|
|
|
|
|
self.assertIn("127.0.0.1", self.script)
|
|
|
|
|
|
|
|
|
|
def test_the_electron_node_flag_is_dropped(self):
|
|
|
|
|
self.assertIn("env -u ELECTRON_RUN_AS_NODE", self.script)
|
|
|
|
|
|
|
|
|
|
def test_every_probe_bypasses_a_proxy_and_is_bounded(self):
|
|
|
|
|
probes = [line for line in self.script.splitlines() if "curl " in line]
|
|
|
|
|
|
|
|
|
|
self.assertTrue(probes)
|
|
|
|
|
for probe in probes:
|
|
|
|
|
with self.subTest(probe=probe.strip()):
|
|
|
|
|
self.assertIn("--noproxy", probe)
|
|
|
|
|
self.assertIn("--max-time", probe)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
class TestVendoredAssets(unittest.TestCase):
|
|
|
|
|
def test_the_right_to_left_stylesheet_is_vendored(self):
|
|
|
|
|
script = (REPO_ROOT / "app" / "scripts" / "copy-vendor.js").read_text(
|
|
|
|
|
encoding="utf-8"
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
self.assertEqual(
|
|
|
|
|
script.count("bootstrap.rtl.min.css"),
|
|
|
|
|
2,
|
|
|
|
|
"the RTL stylesheet needs both a source and a destination path",
|
|
|
|
|
)
|
|
|
|
|
|
|
|
|
|
|
feat(i18n): serve every page in 30 languages
The interface ships translated; page content stays English until a
LibreTranslate instance fills app/i18n/content/ through make i18n. A string
without a catalogue entry falls back to its English source, so a half-filled
catalogue degrades instead of breaking.
Translation runs after ConfigurationResolver.resolve_links(), on a copy.
resolve_links matches by the `name` field, so translating it beforehand
would break every `link:` reference in the configuration.
negotiate() normalises to the primary subtag itself. Werkzeug's best_match
returns an exact match before it considers a primary-tag fallback, so the
Chrome default `de-DE,en;q=0.8` resolves to English there. "/" carries
Vary: Accept-Language, without which a shared cache pins the first
visitor's language for everyone.
The route rule lists the known codes as a converter argument. A bare
"/<lang>/" answers /robots.txt and /favicon.ico with a permanently
cacheable 308 to their trailing-slash form.
Templates gain lang, dir, the RTL stylesheet, a canonical URL and 30
hreflang alternates. Those are the first external URLs in this app:
ProxyFix takes the scheme from X-Forwarded-Proto so they do not claim
http:// behind a TLS-terminating proxy, X-Forwarded-Host stays untrusted
because nginx passes a client-supplied one through, and TRUSTED_HOSTS lets
Flask reject a forged Host outright.
Flask only autoescapes .html/.htm/.xml/.xhtml/.svg, so every *.html.j2
template interpolated configuration raw. Enabling it changes two lines of
the shipped page, both an apostrophe.
read_catalog degrades an unreadable catalogue to English rather than
serving a 500, and drops non-string entries that would otherwise render as
"42". i18n_sync writes atomically, never overwrites an existing entry,
refuses to touch a catalogue it could not parse, and leaves the file alone
when a run translated nothing.
Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
2026-08-22 00:02:35 +02:00
|
|
|
class TestPackagedCatalogs(unittest.TestCase):
|
|
|
|
|
def test_the_interface_catalogs_are_declared_as_package_data(self):
|
|
|
|
|
with (REPO_ROOT / "pyproject.toml").open("rb") as handle:
|
|
|
|
|
pyproject = tomllib.load(handle)
|
|
|
|
|
|
|
|
|
|
package_data = pyproject["tool"]["setuptools"]["package-data"]["app"]
|
|
|
|
|
|
|
|
|
|
self.assertIn("i18n/ui/*.yaml", package_data)
|
|
|
|
|
|
|
|
|
|
|
|
|
|
|
if __name__ == "__main__":
|
|
|
|
|
unittest.main()
|