- Create shared/filename_utils.py for date/time/dimension filename building
- Create shared/path_utils.py for output directory handling
- Create shared/discord/message_builder.py for Discord message construction
- Create shared/discord/cdn_extractor.py for CDN URL extraction
- Refactor image_node.py to use shared utilities (-161 lines, 16.3%)
- Refactor video_node.py to use shared utilities (-361 lines, 23.1%)
- Fix setup_logging missing from logging_config.py
- Fix test imports to use new module paths (nodes.* instead of discord_*_node)
- Total reduction: 522 lines (20.5%), exceeding PRD target of ~200 lines
Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
- Updated `tests/test_image_node_sanitization.py` to include `github_token` in test inputs.
- Verified test now correctly covers github token sanitization.
- Updated `tests/test_image_node_sanitization.py` to avoid bare `try...except` that swallowed `AssertionError`.
- Verified the test fails correctly when sanitization is broken.
- Removed redundant calls to `sanitize_json_for_export` in `discord_image_node.py` loop.
- Verified ~33ms performance gain per batch via benchmark.
- Added regression test `tests/test_image_node_sanitization.py`.
- Fix potential BufferError in video frame writing path by enforcing C-contiguity with np.ascontiguousarray
- Add regression tests for non-contiguous array writing to Popen.stdin
- Rename variables for clarity (images_bytes -> image_chunks)
- Ensure cross-platform compatibility in tests
- Fix BufferError when passing non-contiguous transposed audio array to memoryview/subprocess by using np.ascontiguousarray
- Rename 'images_bytes' to 'image_chunks' to better reflect that it contains numpy arrays, not bytes objects
- Improve test portability by using sys.executable instead of 'cat'
Avoids unnecessary memory copying by passing numpy arrays/memoryviews directly to subprocess stdin instead of creating intermediate bytes objects. This reduces memory pressure and allocation overhead when processing high-resolution video frames.
Prevent arbitrary file write and repo traversal by strictly validating
`github_repo` and `file_path` inputs in `update_github_cdn_urls`.
Added `validate_github_repo` and `validate_file_path` functions to
enforce strict whitelisting of characters and reject path traversal sequences.
Added comprehensive unit tests in `tests/test_github_validation.py`.
- Sanitize `DiscordWebhookClient` exception messages to redact webhook tokens.
- Sanitize GitHub API response text in error messages to prevent token leakage.
- Update `tests/test_utils.py` with mocks and new security test cases.
- Record security learning in `.jules/sentinel.md`.
This addresses potential credential exposure in logs and error messages.
This change updates the `validate_webhook_url` function to strictly enforce the use of `https://` for Discord webhook URLs. This prevents the accidental transmission of sensitive webhook tokens over unencrypted HTTP connections.
Security Impact:
- Prevents potential Man-in-the-Middle (MitM) attacks from capturing webhook tokens if a user inadvertently copies an `http://` URL (e.g. from a proxy or non-standard source).
- Aligns with Discord's API security best practices.
Changes:
- Updated `WEBHOOK_URL_PATTERNS` regex to require `https`.
- Updated `validate_webhook_url` logic to check for `https://` prefix.
- Added unit test `test_http_url_rejected` to verify the fix.
- Add `utils/logging_config.py` for logger setup.
- Replace print statements with logging in `utils/discord_api.py`.
- Add `tests/test_utils.py` unit tests.