Skip to content

fix(config): stricter validation for log_level + webhook_api_key (#46)#116

Merged
strausmann merged 2 commits into
mainfrom
fix/config-strict-validation
Jun 14, 2026
Merged

fix(config): stricter validation for log_level + webhook_api_key (#46)#116
strausmann merged 2 commits into
mainfrom
fix/config-strict-validation

Conversation

@strausmann

Copy link
Copy Markdown
Owner

Summary

  • log_level: Literal["DEBUG","INFO","WARNING","ERROR","CRITICAL"] statt str — Tippfehler werfen jetzt ValidationError beim Startup statt lautlos defaulten
  • webhook_api_key: whitespace-only Keys (≥32 Zeichen Spaces/Tabs/Newlines) werden abgelehnt — sonst trügerische Sicherheit, da der Webhook-Check nur die Länge prüft
  • Empty-Key bleibt erlaubt (Bootstrap ohne Webhook-Auth)

Hinweis zu Issue #46 Scope

Issue #46 fordert auch Field(ge=1, le=65535) für ql820_port + pt750w_port. Diese Felder wurden in Phase 1i CA-1 (PR #95) entfernt und durch printers.yaml ersetzt. Das Port-Range-Constraint wandert dorthin und wird mit Phase 1k.1b/c separat addressiert.

Tests

Neu in backend/tests/unit/test_config.py:

Test Was er prueft
test_settings_log_level_accepts_valid 5 valide Werte (DEBUGCRITICAL) — parametrisiert
test_settings_log_level_rejects_invalid 6 invalide Werte (debug, TRACE, "", INFOO) — parametrisiert
test_settings_log_level_default_is_info Regression-Guard: Default bleibt INFO
test_settings_webhook_api_key_rejects_whitespace_only 3 Whitespace-Patterns (Spaces, Tabs, Mixed)
test_settings_webhook_api_key_accepts_real_key 32x "a" wird akzeptiert
test_settings_webhook_api_key_empty_still_accepted Bootstrap ohne Auth bleibt moeglich
$ pytest tests/unit/test_config.py
36 passed in 0.21s

mypy ✓ ruff check ✓ ruff format ✓

Closes #46

- log_level: Literal["DEBUG","INFO","WARNING","ERROR","CRITICAL"] statt str
  → Tippfehler ("debug", "TRACE") werfen jetzt ValidationError beim Startup
- webhook_api_key: whitespace-only Keys (>=32 Zeichen Spaces/Tabs) werden
  abgelehnt — sonst trügerische Sicherheit, da der Webhook-Check nur die
  Länge prüft.

Issue #46 Teil "ql820_port/pt750w_port range validation" ist obsolet:
Phase 1i CA-1 hat diese Felder durch printers.yaml ersetzt.

Tests:
- test_settings_log_level_accepts_valid (5 Werte parametrisiert)
- test_settings_log_level_rejects_invalid (6 Werte parametrisiert)
- test_settings_log_level_default_is_info (Regression)
- test_settings_webhook_api_key_rejects_whitespace_only (3 Patterns)
- test_settings_webhook_api_key_accepts_real_key
- test_settings_webhook_api_key_empty_still_accepted (Bootstrap-Pfad)

Closes #46

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
Copilot AI review requested due to automatic review settings June 14, 2026 11:21

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

@gemini-code-assist

Copy link
Copy Markdown

Summary of Changes

Hello, I'm Gemini Code Assist1! I'm currently reviewing this pull request and will post my feedback shortly. In the meantime, here's a summary to help you and other reviewers quickly get up to speed!

Dieser Pull Request verbessert die Konfigurationsvalidierung der Anwendung, um die Robustheit beim Startup zu erhöhen. Durch die Einschränkung des log_level-Feldes auf definierte Literale und die zusätzliche Prüfung des webhook_api_key auf Whitespace-Inhalte werden potenzielle Fehlkonfigurationen frühzeitig erkannt und verhindert.

Highlights

  • Stricter log_level validation: Updated the log_level configuration to use a Literal type, ensuring only valid Python logging levels are accepted and preventing silent defaults on typos.
  • Improved webhook_api_key security: Added validation to reject whitespace-only API keys, preventing insecure configurations while maintaining support for empty keys during initial bootstrap.
  • Comprehensive unit testing: Added a suite of parameterized tests in test_config.py to verify the new validation logic for both log levels and API keys.
Using Gemini Code Assist

The full guide for Gemini Code Assist can be found on our documentation page, here are some quick tips.

Invoking Gemini

You can request assistance from Gemini at any point by creating a comment using either /gemini <command> or @gemini-code-assist <command>. Below is a summary of the supported commands on the current page.

Feature Command Description
Code Review /gemini review Performs a code review for the current pull request in its current state.
Pull Request Summary /gemini summary Provides a summary of the current pull request in its current state.
Comment @gemini-code-assist Responds in comments when explicitly tagged, both in pull request comments and review comments.
Help /gemini help Displays a list of available commands.

Customization

To customize the Gemini Code Assist for GitHub experience, repository maintainers can create a configuration file and/or provide a custom code review style guide (such as PEP-8 for Python) by creating and adding files to a .gemini/ folder in the base of the repository. Detailed instructions can be found here.

Limitations & Feedback

Gemini Code Assist may make mistakes. Please leave feedback on any instances where its feedback is incorrect or counterproductive. You can react with 👍 and 👎 on @gemini-code-assist comments. If you're interested in giving your feedback about your experience with Gemini Code Assist for GitHub and other Google products, sign up here.

Footnotes

  1. Review the Privacy Notices, Generative AI Prohibited Use Policy, Terms of Service, and learn how to configure Gemini Code Assist in GitHub here. Gemini can make mistakes, so double check it and use code with caution.

@gemini-code-assist gemini-code-assist Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request introduces stricter validation for configuration settings in backend/app/config.py by restricting log_level to a literal of standard Python log levels and rejecting whitespace-only values for webhook_api_key, accompanied by comprehensive unit tests. The review feedback highlights a security risk where leading or trailing whitespace can bypass the minimum length requirement of 32 characters (e.g., 31 spaces followed by a single character). It is recommended to validate the length of the stripped key and return the cleaned SecretStr to prevent this vulnerability.

Important

The consumer version of Gemini Code Assist on GitHub is being sunset. Starting June 18, 2026, new organization installations will be blocked, and all code review activity will officially cease on July 17, 2026.
For more details on the timeline and next steps, please review the Help Documentation.

Comment thread backend/app/config.py Outdated
Comment on lines 150 to 157
secret = v.get_secret_value()
if secret and len(secret) < 32:
if not secret:
return v
if len(secret) < 32:
raise ValueError("PRINTER_HUB_WEBHOOK_API_KEY must be at least 32 characters")
if secret.strip() == "":
raise ValueError("PRINTER_HUB_WEBHOOK_API_KEY must not be whitespace-only")
return v

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

security-high high

Security Risk / Validation Bypass:
If an API key contains leading or trailing whitespace (e.g., " " * 31 + "a"), the total length is 32 characters. This causes the len(secret) < 32 check to incorrectly pass. Since the key is not completely empty, the secret.strip() == "" check also does not trigger. However, the actual key after stripping has only a single significant character ("a"), which completely bypasses the required minimum length of 32 characters for entropy.

Recommendation:
Validate the length of the cleaned (stripped) key. Additionally, it is advisable to return the cleaned value directly as a SecretStr. This automatically cleans up accidentally copied whitespace or line breaks (e.g., from .env files), increasing robustness.

Suggested change
secret = v.get_secret_value()
if secret and len(secret) < 32:
if not secret:
return v
if len(secret) < 32:
raise ValueError("PRINTER_HUB_WEBHOOK_API_KEY must be at least 32 characters")
if secret.strip() == "":
raise ValueError("PRINTER_HUB_WEBHOOK_API_KEY must not be whitespace-only")
return v
secret = v.get_secret_value()
if not secret:
return v
stripped = secret.strip()
if not stripped:
raise ValueError("PRINTER_HUB_WEBHOOK_API_KEY must not be whitespace-only")
if len(stripped) < 32:
raise ValueError("PRINTER_HUB_WEBHOOK_API_KEY must be at least 32 characters (excluding leading/trailing whitespace)")
return SecretStr(stripped)

@codecov

codecov Bot commented Jun 14, 2026

Copy link
Copy Markdown

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 89.26%. Comparing base (d27bbcc) to head (6dcc598).
✅ All tests successful. No failed tests found.

Additional details and impacted files
@@            Coverage Diff             @@
##             main     #116      +/-   ##
==========================================
+ Coverage   89.22%   89.26%   +0.03%     
==========================================
  Files          91       91              
  Lines        4251     4257       +6     
  Branches      368      369       +1     
==========================================
+ Hits         3793     3800       +7     
+ Misses        360      359       -1     
  Partials       98       98              
Components Coverage Δ
Printer Backends (transport) 86.87% <ø> (ø)
Printer Models (drivers) 88.20% <ø> (ø)
Services 91.27% <ø> (+0.06%) ⬆️
REST API 84.97% <ø> (ø)
Pydantic Schemas 100.00% <ø> (ø)
Integration Plugins 100.00% <ø> (ø)
Files with missing lines Coverage Δ
backend/app/config.py 100.00% <100.00%> (ø)

... and 2 files with indirect coverage changes

Flag Coverage Δ
backend 89.26% <100.00%> (+0.03%) ⬆️

Flags with carried forward coverage won't be shown. Click here to find out more.


Continue to review full report in Codecov by Harness.

Legend - Click here to learn more
Δ = absolute <relative> (impact), ø = not affected, ? = missing data
Powered by Codecov. Last update d27bbcc...6dcc598. Read the comment docs.

🚀 New features to boost your workflow:
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

Gemini-Review-Feedback auf PR #116: die Length-Check verglich gegen die
Rohlänge des Secrets — das ließ ``" " * 31 + "a"`` durchgehen (32 Zeichen
formal, aber nur 1 Zeichen echtes Auth-Material).

- `len(stripped) < 32` statt `len(secret) < 32`
- Validator gibt jetzt `SecretStr(stripped)` zurück, damit später konsistent
  gegen den effektiven Key verglichen wird (kein Trailing-Whitespace-Drift)

Tests:
- `test_settings_webhook_api_key_rejects_short_effective_length` mit 3
  Patterns (Gemini-Pattern, Whitespace-Padding, Tab+Newline)
- `test_settings_webhook_api_key_strips_leading_trailing_whitespace`

40 Tests grün, mypy + ruff sauber.

Refs PR #116 Review-Comment

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
@strausmann

Copy link
Copy Markdown
Owner Author

Round-1 addressed (Gemini): webhook_api_key length now measured on stripped value; validator returns trimmed SecretStr. Prevents ' '*31+'a' from bypassing the 32-char gate. +2 tests (Gemini-Pattern + Trim-Roundtrip). 40 passed.

@strausmann
strausmann merged commit 6b8ac30 into main Jun 14, 2026
19 checks passed
@strausmann
strausmann deleted the fix/config-strict-validation branch June 14, 2026 11:29
github-actions Bot pushed a commit that referenced this pull request Jun 15, 2026
## <small>0.10.2 (2026-06-15)</small>

* refactor(main): _resolve_model_id_from_config nimmt PrinterYAMLConfig statt Any (#67) (#123) ([2ff51d2](2ff51d2)), closes [#67](#67) [#123](#123) [#67](#67) [#59](#59) [#67](#67) [#59](#59)
* refactor(snipeit): typisiere response payload als TypedDict statt dict[str, Any] (#67) (#122) ([e88601b](e88601b)), closes [#67](#67) [#122](#122) [#67](#67) [#67](#67) [#51](#51)
* perf(lifespan): plugin-discovery in Thread auslagern (Audit #67) (#121) ([48215b4](48215b4)), closes [#67](#67) [#121](#121) [#67](#67) [#59](#59)
* fix(config): stricter validation for log_level + webhook_api_key (#46) (#116) ([6b8ac30](6b8ac30)), closes [#46](#46) [#116](#116) [#46](#46) [#46](#46) [#46](#46) [#46](#46) [#116](#116)
* fix(print): copies-replication erzeugt UNIQUE job_ids (Round 2 #hangar-109) (#120) ([bd781ae](bd781ae)), closes [#hangar-109](https://github.com/strausmann/label-printer-hub/issues/hangar-109) [#120](#120) [#115](#115)
* fix(print): PrintOptions.copies replicates images for hardware print (#hangar-109) (#115) ([d27bbcc](d27bbcc)), closes [#hangar-109](https://github.com/strausmann/label-printer-hub/issues/hangar-109) [#115](#115) [strausmann/hangar#109](https://github.com/strausmann/hangar/issues/109)
* docs(metrics): präzisiere sse_events_published_total Beschreibung (Audit #67) (#119) ([ab8c4c4](ab8c4c4)), closes [#67](#67) [#119](#119) [#67](#67) [#67](#67) [#65](#65)
* docs(ptouch): korrigiere Tape-Klassen-Namen in ptouch-integration.md (Audit #67) (#118) ([0faab99](0faab99)), closes [#67](#67) [#118](#118) [#67](#67) [#59](#59)
* chore(readme): codecov badge ohne embedded Token (Audit #67) (#117) ([4bb5423](4bb5423)), closes [#67](#67) [#117](#117) [#67](#67) [#59](#59)

[skip ci]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

feat(config): stricter validation for log_level and printer ports

2 participants