Second-pass review fixes: kill last hardcoded creds, wire get_services, dedup
Verification audit (re-run of the 6 skill lenses) confirmed the prior fixes hold and surfaced a few misses: Security (HIGH): - search.py _check_smart_redirect still opened a raw pymysql connection with root/rootpassword (reachable on any 9-digit SSO query). Now uses the shared env-backed employee_connection helper. - Deleted dead shopdb/core/services/employee_service.py (zero importers; carried another root/rootpassword literal). No hardcoded credentials remain in app logic; config.py dev defaults stay gated by ProductionConfig.validate. Dead hook: - get_services was implemented by the printers plugin but had no consumer (docs claimed otherwise). Added PluginManager.get_service(name) that resolves a service from enabled plugins; updated PLUGIN-HOOKS.md. Tests: - search disabled-plugin exclusion (the high-value gap): enabled plugin's hostname appears, disabled plugin's hostname drops out (searched by a hostname distinct from assetnumber so only the gated domain can match). - get_service consumer test (unknown name -> None). Simplify: - Extract the triplicated GE_LOGO_SVG + loadLogo + drawLogoOverlay into shared frontend/src/views/print/qrLogo.js (renderQrDataUrl); both QR views use it. - applications.py: lift the misplaced pagination import to the top; drop unused Computer unpacking in the 3 endpoints that only touch ComputerInstalledApp. 154 tests pass, naming/style green, app boots, QR render verified. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
@@ -317,6 +317,25 @@ class PluginManager:
|
||||
"""Get all loaded plugins."""
|
||||
return self.loader.get_all_loaded()
|
||||
|
||||
def get_service(self, name: str):
|
||||
"""Resolve a service exposed by an enabled plugin via get_services().
|
||||
|
||||
Consumer for the BasePlugin.get_services hook: searches enabled plugins
|
||||
for one that registers `name` and returns the registered value (a service
|
||||
class or factory). Returns None if no enabled plugin provides it. This is
|
||||
how one plugin obtains another's service (e.g. the Zabbix service).
|
||||
"""
|
||||
for plugin_name, plugin in self.get_all_plugins().items():
|
||||
if not self.registry.is_enabled(plugin_name):
|
||||
continue
|
||||
try:
|
||||
services = plugin.get_services() or {}
|
||||
except Exception:
|
||||
continue
|
||||
if name in services:
|
||||
return services[name]
|
||||
return None
|
||||
|
||||
|
||||
# Global plugin manager instance
|
||||
plugin_manager = PluginManager()
|
||||
|
||||
Reference in New Issue
Block a user