Skip to content

Long overdue maintenance - #146

Merged
mgerni merged 3 commits into
masterfrom
audit_taskapp
Sep 28, 2026
Merged

mgerni merged 3 commits into
masterfrom
audit_taskapp

Conversation

@mgerni

@mgerni mgerni commented Sep 27, 2026

Copy link
Copy Markdown
Collaborator

Starting to put some more work in on TaskApp. Bringing some packages up to date and adding some long overdue automations.

Changes Overview

  • Dependency cleanup: 47 pinned packages down to the 9 we actually import. requirements.txt is now generated with hashes (that's most of the 12k additions), pip-audit comes back clean.
  • Code updates the new versions needed:
    • itsdangerous dropped the old token serializer, so password reset / email verify tokens now use URLSafeTimedSerializer.
    • flask_recaptcha is unmaintained and breaks on current Jinja, so it's swapped for a small recaptcha_helper.py. recaptcha.verify() works the same as before.
    • bcrypt 5 throws an error on passwords over 72 bytes instead of quietly cutting them off, so we cut them off ourselves first. Existing passwords still work.
  • Small fixes: password reset rejects a bad token on submit, removed an unused template variable and dead markup in base.html.
  • pytest: 65 tests covering login, reset, profile, Discord, the API and page loads. No database or network needed. Feel free to add any tests.
  • CI on PR creation: runs the tests, checks requirements.txt still matches requirements.in, and runs pip-audit. Also re-audits master every Monday for new CVEs.
  • Python 3.14: Heroku's runtime.txt is deprecated, so it's migrated to .python-version. Set to 3.14 so Heroku picks up patch releases on its own.
  • Additional .gitignore entries so I can maintain my organized chaos.

Adding a package

Add it to requirements.in (or requirements-dev.in if it's only for tests), then regenerate the matching .txt and commit both files.

pip-tools

pip install pip-tools
pip-compile --generate-hashes requirements.in
pip-compile --generate-hashes requirements-dev.in

uv

uv pip compile requirements.in --generate-hashes -o requirements.txt
uv pip compile requirements-dev.in --generate-hashes -o requirements-dev.txt

To bump a single package without touching the rest, add --upgrade-package <name> to either command.

@rmobis @cringland I'll hold off on merging until later this weekend to give y'all a chance to review in case I borked anything. Mostly updates and some tests AI whipped up; I'm far too lazy to write my own tests.

Updated requirements.txt
Removed runtime.txt -> migrated to .python-version
Updated token serializers with specific salts for reset/tokens
Replaced flask_recaptcha with recaptcha_helper
Capped bcrypt 5 password at 72 bytes before hashing/checking
Removed taskapp_email variable and old base.html
Add pytest

@rmobis rmobis left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@mgerni
mgerni merged commit 4078c49 into master Sep 28, 2026
2 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants