Feature/server detection - #95
Open
VanDelinea wants to merge 14 commits into
Open
Conversation
Authorizer now memoizes the /api/v1/healthcheck + /health probe result in a process-scoped, thread-safe class cache keyed by normalized base_url, so detection fires once per base_url per process instead of on every authorizer construction. Closes the unauthenticated-probe burst that the Delinea Platform WAF rate-limits to 403 under Ansible token-auth lookups. - successes only are cached; detection failures re-probe - per-instance _server_type still set on cache hit (SecretServer + _refresh read it) - adds first offline unit tests (tests/test_server_detection_cache.py) Addresses 728859
✅ Snyk checks have passed. No issues have been found so far.
💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse. |
Clears CVE-2026-25645 (requests) and CVE-2026-44431/44432 (urllib3) per work item 741117. The fixed releases require Python >= 3.10. - requirements.txt: requests==2.34.2, urllib3==2.7.0 - pyproject.toml: requires-python >=3.10, requests floor >= 2.34.2 - tox.ini / run_tests.yml: matrix trimmed to 3.10-3.12 - README: minimum Python 3.10 BREAKING: drops Python 3.8/3.9 support (both EOL) and raises the published requests floor for downstream consumers.
…XPM/python-tss-sdk into dependencies/741117-requests-urllib3-bump
…rllib3-bump 🛡️ bump requests 2.34.2 & urllib3 2.7.0; drop Python 3.8/3.9
…XPM/python-tss-sdk into feature/server-detection
…, attach response to errors, 🧪 add offline security tests security review remediation, phase 1 (DevPlan.md) == - every http call now passes an explicit timeout via DEFAULT_REQUEST_TIMEOUT; the folder and lookup calls had none and could hang a consumer forever - oauth2 grant now refreshes up to 300s before expiry; the drift sign was inverted so expired tokens were reused for up to 300s past expiry - SecretServerError keeps the server response (error.response works now); a 4xx json body without message/error keys no longer masks the failure with UnboundLocalError - example masks the password value instead of printing it - new offline test suite covers timeout coverage on every request path, refresh boundary behavior, and error plumbing; no live credentials needed
…n, sanitize error bodies, validate vault redirect, 🧪 add offline security tests security review remediation, phase 2 (DevPlan.md) == - warn (UserWarning) when base_url is not https; credentials and bearer tokens would otherwise travel in plaintext with no signal to the caller. strict rejection is deferred to v3.0 to avoid breaking localhost/lab setups - health-check probing now requires a 2xx status and an exact "healthy" match instead of a substring check; the old check matched "Unhealthy" and ignored the http status entirely - exception messages no longer echo raw response bodies; the secrets endpoint omits the body outright, other endpoints get a capped, clearly truncated excerpt - the platform vault-broker redirect url is now required to be a valid https url before any token is sent to it - SecretServerError now passes its message through to Exception.__init__, so str(error) is populated instead of always empty - new offline test suite covers all four fixes; existing FakeResponse fixtures updated with .ok/.status_code/.text to match the tightened health-check contract
…lease to pypi trusted publishing, align tox deps with pinned requirements security review remediation, phase 3 (DevPlan.md) == - every workflow now declares least-privilege permissions at the top level; the lint job (needs to push auto-fix commits and publish check results) and the release job (needs the oidc token) grant themselves only what they actually use - pypa/gh-action-pypi-publish was pinned to the mutable release/v1 branch, the only unpinned action in the repo; now pinned to the v1.14.2 commit sha - release.yml drops the long-lived PYPI_API_TOKEN in favor of PyPI Trusted Publishing (OIDC) -- requires a trusted publisher to be configured for this repo/workflow on pypi.org before the next tag push; keep the repo secret until that is confirmed working - tox.ini and lint.yml now install the versions pinned in requirements.txt (black==26.5.1, flit==3.12.0, and the full pinned set via -r requirements.txt) instead of floating latest, so CI exercises what consumers actually get
…SECURITY.md, 🚀 split runtime/dev deps and pin pip - token refresh now locked and utc-aware; mutable default args removed - fixed get_folder_json crash on bare call, itemValue returning a Response object instead of text, and an unvalidated non-numeric secrets count - requirements.txt split into runtime-only pins with a new requirements-dev.txt for build/test tooling; pip>=26.2 pinned there and in release.yml (transitive via flit; CVE-2026-8643 and others)
Security/review remediation
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
base_url— detection fires at most once perbase_urlper process instead of on everyAuthorizer/SecretServerconstruction.server_typeoverride available for callers that don't need auto-detection."healthy"match (JSONHealthy: trueor literal text) instead of a loose substring check, so an unhealthy or non-2xx response can no longer be mistaken for a pass.