Skip to content

test: Cover StaticFileHandler subclass patterns from downstream packages - #3785

Open
bdarnell wants to merge 1 commit into
tornadoweb:masterfrom
bdarnell:claude/static-subclass-tests
Open

bdarnell wants to merge 1 commit into
tornadoweb:masterfrom
bdarnell:claude/static-subclass-tests

Conversation

@bdarnell

Copy link
Copy Markdown
Member

Add tests modeled on how popular downstream packages subclass StaticFileHandler, so that changes to the base class that would break them are caught here:

  • A multi-root handler (as in jupyter_server) installed as the static_handler_class with a list static_path, used through static_url; and make_static_url called directly with static_path=None by a handler that finds its own files (voila).
  • A handler that routes by path prefix to one of several roots and calls super().get_absolute_path with that root (Bokeh). A ../ from one of its roots into another is rejected by the base get_absolute_path, even though the subclass's own validation would accept it.
  • A handler that sets allowed_symlink_directory itself during validate_absolute_path, following symlinked directories (Jupyter's actual FileFindHandler).
  • A get_absolute_path instance method that reassigns self.root, which get() must then pass to validate_absolute_path (voila).
  • A handler whose path is a single file, possibly a symlink (JupyterHub's LogoHandler).

Claude-Session: https://claude.ai/code/session_019nvEV873ZwBncgxPP13Xfd

Add tests modeled on how popular downstream packages subclass
StaticFileHandler, so that changes to the base class that would break
them are caught here:

- A multi-root handler (as in jupyter_server) installed as the
  static_handler_class with a list static_path, used through
  static_url; and make_static_url called directly with
  static_path=None by a handler that finds its own files (voila).
- A handler that routes by path prefix to one of several roots and
  calls super().get_absolute_path with that root (Bokeh). A ../ from
  one of its roots into another is rejected by the base
  get_absolute_path, even though the subclass's own validation would
  accept it.
- A handler that sets allowed_symlink_directory itself during
  validate_absolute_path, following symlinked directories (Jupyter's
  actual FileFindHandler).
- A get_absolute_path instance method that reassigns self.root, which
  get() must then pass to validate_absolute_path (voila).
- A handler whose path is a single file, possibly a symlink (JupyterHub's
  LogoHandler).

Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_019nvEV873ZwBncgxPP13Xfd

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants