mirror of
https://github.com/alexta69/metube.git
synced 2026-09-21 13:35:01 +00:00
fix: create fallback state file with owner-only 0600 permissions
This commit is contained in:
+5
-1
@@ -148,7 +148,11 @@ class AtomicJsonStore:
|
|||||||
raise
|
raise
|
||||||
|
|
||||||
def _direct_write(self, payload: dict[str, Any]) -> None:
|
def _direct_write(self, payload: dict[str, Any]) -> None:
|
||||||
with open(self.path, "w", encoding="utf-8") as f:
|
# Create with 0o600 so the fallback keeps the owner-only permissions the
|
||||||
|
# atomic path gets from mkstemp; state files can contain URLs and
|
||||||
|
# per-download option overrides that must not leak on shared mounts.
|
||||||
|
fd = os.open(self.path, os.O_WRONLY | os.O_CREAT | os.O_TRUNC, 0o600)
|
||||||
|
with os.fdopen(fd, "w", encoding="utf-8") as f:
|
||||||
self._write_payload(payload, f)
|
self._write_payload(payload, f)
|
||||||
f.flush()
|
f.flush()
|
||||||
self._best_effort_fsync(f.fileno())
|
self._best_effort_fsync(f.fileno())
|
||||||
|
|||||||
@@ -36,6 +36,8 @@ class StateStoreTests(unittest.TestCase):
|
|||||||
|
|
||||||
self.assertTrue(os.path.exists(path))
|
self.assertTrue(os.path.exists(path))
|
||||||
self.assertTrue(any(path in message for message in logs.output))
|
self.assertTrue(any(path in message for message in logs.output))
|
||||||
|
# Fallback keeps owner-only permissions, matching the atomic path.
|
||||||
|
self.assertEqual(os.stat(path).st_mode & 0o777, 0o600)
|
||||||
payload = store.load()
|
payload = store.load()
|
||||||
self.assertEqual(payload["items"], [{"key": "a"}])
|
self.assertEqual(payload["items"], [{"key": "a"}])
|
||||||
|
|
||||||
@@ -64,7 +66,10 @@ class StateStoreTests(unittest.TestCase):
|
|||||||
"state_store.tempfile.mkstemp",
|
"state_store.tempfile.mkstemp",
|
||||||
side_effect=PermissionError(1, "Operation not permitted"),
|
side_effect=PermissionError(1, "Operation not permitted"),
|
||||||
):
|
):
|
||||||
with patch("builtins.open", side_effect=PermissionError(13, "Permission denied")):
|
with patch(
|
||||||
|
"state_store.os.open",
|
||||||
|
side_effect=PermissionError(13, "Permission denied"),
|
||||||
|
):
|
||||||
with self.assertRaises(PermissionError) as ctx:
|
with self.assertRaises(PermissionError) as ctx:
|
||||||
store.save({"items": [{"key": "a"}]})
|
store.save({"items": [{"key": "a"}]})
|
||||||
|
|
||||||
|
|||||||
Reference in New Issue
Block a user