From d81fad842f9c4bd7190238eca8700ba24ed79e15 Mon Sep 17 00:00:00 2001 From: =?UTF-8?q?Ph=E1=BA=A1m=20V=C4=83n=20Nguy=C3=AAn?= Date: Sat, 26 Sep 2026 12:10:12 +0700 Subject: [PATCH] Address SonarCloud findings - Use `uv run --locked --no-build` in CI - Use trust auth for the throwaway CI Postgres service - Extract duplicated invalid-token message into a constant Co-Authored-By: Claude Opus 5.5 --- .github/workflows/ci.yml | 20 ++++++++------------ apps/core/views.py | 8 +++++--- 2 files changed, 13 insertions(+), 15 deletions(-) diff --git a/.github/workflows/ci.yml b/.github/workflows/ci.yml index 4db4f18..2786828 100644 --- a/.github/workflows/ci.yml +++ b/.github/workflows/ci.yml @@ -27,12 +27,10 @@ jobs: run: uv lock --locked - name: Ruff lint - run: | - uv sync --locked --no-build --only-dev - uv run --no-sync ruff check --output-format=github . + run: uv run --locked --no-build ruff check --output-format=github . - name: Ruff format - run: uv run --no-sync ruff format --check . + run: uv run --locked --no-build ruff format --check . test: runs-on: ubuntu-latest @@ -47,7 +45,7 @@ jobs: env: POSTGRES_DB: app POSTGRES_USER: postgres - POSTGRES_PASSWORD: postgres + POSTGRES_HOST_AUTH_METHOD: trust ports: - 5432:5432 options: >- @@ -56,7 +54,7 @@ jobs: --health-timeout 5s --health-retries 10 env: - DATABASE_URL: ${{ matrix.database == 'postgres' && 'postgres://postgres:postgres@localhost:5432/app' || 'sqlite:///db.sqlite3' }} + DATABASE_URL: ${{ matrix.database == 'postgres' && 'postgres://postgres@localhost:5432/app' || 'sqlite:///db.sqlite3' }} steps: - uses: actions/checkout@3d3c42e5aac5ba805825da76410c181273ba90b1 # v7.0.1 @@ -69,13 +67,13 @@ jobs: run: uv sync --locked --no-build - name: Django system checks - run: uv run --no-sync manage.py check + run: uv run --locked --no-build manage.py check - name: Check for missing migrations - run: uv run --no-sync manage.py makemigrations --check --dry-run + run: uv run --locked --no-build manage.py makemigrations --check --dry-run - name: Test - run: uv run --no-sync pytest + run: uv run --locked --no-build pytest deploy-check: runs-on: ubuntu-latest @@ -92,6 +90,4 @@ jobs: enable-cache: true - name: Django deployment checks - run: | - uv sync --locked --no-build --no-dev - uv run --no-sync manage.py check --deploy --fail-level ERROR + run: uv run --locked --no-build --no-dev manage.py check --deploy --fail-level ERROR diff --git a/apps/core/views.py b/apps/core/views.py index 134c022..c7148aa 100644 --- a/apps/core/views.py +++ b/apps/core/views.py @@ -27,6 +27,8 @@ ) from .utils import Util +INVALID_TOKEN_MESSAGE = "Token is not valid, please request a new one" + class CustomRedirect(HttpResponsePermanentRedirect): allowed_schemes = [os.environ.get("APP_SCHEME"), "http", "https"] @@ -107,7 +109,7 @@ def post(self, request, *args, **kwargs): if not PasswordResetTokenGenerator().check_token(user, token): return Response( - {"error": "Token is not valid, please request a new one"}, + {"error": INVALID_TOKEN_MESSAGE}, status=status.HTTP_400_BAD_REQUEST, ) return Response({"success": "Token is valid"}, status=status.HTTP_200_OK) @@ -116,13 +118,13 @@ def post(self, request, *args, **kwargs): try: if not PasswordResetTokenGenerator().check_token(user): return Response( - {"error": "Token is not valid, please request a new one"}, + {"error": INVALID_TOKEN_MESSAGE}, status=status.HTTP_400_BAD_REQUEST, ) except UnboundLocalError: return Response( - {"error": "Token is not valid, please request a new one"}, + {"error": INVALID_TOKEN_MESSAGE}, status=status.HTTP_400_BAD_REQUEST, )