Implements the parallel.md workstreams (Agents A-E) toward REFACTOR_GOAL.md. Phase 1 — app factory + blueprints + /api/v1: - app.py -> create_app() factory (no module-level app); entrypoints updated - routes/ (auth, pages, settings, admin, assets) + blueprints/api.py at /api/v1 - config.py / extensions.py / security.py extracted; services/ layer added - endpoint names preserved so template url_for() calls keep resolving (static check: all 27 template url_for endpoints are defined routes) Phase 2 — one pluggable filter system: - filter_pipeline/registry.py: @register_stage / @register_plugin + discover_modules - engine._init_stages() instantiates registered stages (no hardcoded dict); process_batch is AI-aware: only short-circuits to the AI-disabled path when a filterset's stages declare requires_ai, so offline filtersets run with AI off - BaseFilterPlugin gets a consumer (stages/plugins.py); Keyword/Quality re-enabled via filter_config.json plugins config - comment tree modes ported to stages/comment_filter.py + shared rules.py; wired into /api/v1/posts/<uuid> and /api/v1/comments/<uuid> via FilterEngine.filter_comments() (fails open) - offline quality_filter filterset exercises plugins+ranker without AI - legacy filter_lib / comment_lib / html_generation_lib / generate_html / active_html path deleted Phase 3 prep — pluggable fetchers + Postgres models: - Post / Comment SQLAlchemy models added to models.py - migrate_content_to_db.py backfill (idempotent by uuid, batched, --dry-run) - platforms/ fetcher registry (extension point) - live reads/writes still go through PostService (disk JSON); cutover deferred Phase 6 — test harness: - pytest.ini + tests/ (conftest with in-memory SQLite fixture, no Postgres; stubbed polling/filter singletons) - test_app_factory.py (route registration, no module-level app), test_api_contracts.py (posts/post_detail/comments/filters shape with monkeypatched post_service + get_filter_engine), test_filter_pipeline.py + test_plugin_contract.py (Flask-free; validated locally 12/12 incl. drop-in stage/plugin discovered with zero core edits) Other: .gitignore added (__pycache__, data/, secrets); pytest in requirements. Verification: py_compile clean across the project; the Flask-free filter-pipeline and plugin-contract tests pass locally. App-factory / API-contract tests need deps+docker to run; runtime flask routes / Auth0-repeated-create_app also gated on docker. Co-Authored-By: Claude <noreply@anthropic.com>
41 lines
1.3 KiB
Python
41 lines
1.3 KiB
Python
"""Asset and static-file route registration."""
|
|
|
|
import logging
|
|
import os
|
|
|
|
from flask import abort, current_app, send_from_directory
|
|
|
|
from security import is_safe_path
|
|
|
|
logger = logging.getLogger(__name__)
|
|
|
|
|
|
def register_asset_routes(app):
|
|
"""Register asset routes while preserving legacy endpoint names."""
|
|
|
|
@app.route("/themes/<path:filename>")
|
|
def serve_theme(filename):
|
|
"""Serve theme files (CSS, JS)."""
|
|
if not is_safe_path(filename) or ".." in filename:
|
|
logger.warning(f"Unsafe theme file requested: {filename}")
|
|
abort(404)
|
|
return send_from_directory("themes", filename)
|
|
|
|
@app.route("/logo.png")
|
|
def serve_logo():
|
|
"""Serve configurable logo."""
|
|
logo_path = current_app.config["LOGO_PATH"]
|
|
if "/" not in logo_path:
|
|
return send_from_directory(".", logo_path)
|
|
|
|
directory = os.path.dirname(logo_path)
|
|
filename = os.path.basename(logo_path)
|
|
return send_from_directory(directory, filename)
|
|
|
|
@app.route("/static/<path:filename>")
|
|
def serve_static(filename):
|
|
"""Serve static files (avatars, etc.)."""
|
|
if not is_safe_path(filename) or ".." in filename:
|
|
logger.warning(f"Unsafe static file requested: {filename}")
|
|
abort(404)
|
|
return send_from_directory("static", filename) |