erplibre/script/todo
Mathieu Benoit eb28952d6c [FIX] execute : caviarder les clés d'API et les jetons Bearer
Le filtre ne connaissait que trois noms de variable — mot de passe, secret,
jeton — donc `OPENAI_API_KEY=` partait en clair dans le terminal, dans les
journaux et dans toute sortie CI qui les capture. Un jeton d'en-tête échappait
aux deux règles par construction : il ne porte ni nom d'option ni nom de
variable, il suit le mot « Bearer ».

Le filtre couvre maintenant `API_KEY` côté variables et `Authorization:
Bearer|Basic` côté en-têtes, sans casse, la valeur allant jusqu'au premier
blanc. Il protège au même titre la restauration de base, qui l'appelle sur
six sorties. Reste le dernier rempart et non le premier : argv est lisible par
tout compte de la machine, où aucun caviardage n'atteint.

--- EN ---

The filter knew only three variable names — password, secret, token — so
`OPENAI_API_KEY=` went out in the clear to the terminal, to the logs and to
any CI output capturing them. A header token escaped both rules by
construction: it carries neither an option name nor a variable name, it
follows the word "Bearer".

The filter now covers `API_KEY` on the variable side and `Authorization:
Bearer|Basic` on the header side, case-insensitively, the value running to the
first blank. It protects database restore just as much, which calls it on six
outputs. It stays the last line of defence, not the first: argv is readable by
every account on the machine, where no redaction reaches.

Assisted-by: Claude Opus 5
2026-09-09 07:35:15 -04:00
..
assistant [FIX] execute : caviarder les clés d'API et les jetons Bearer 2026-09-09 07:35:15 -04:00
mail [ADD] mail: read and send email from the TODO CLI 2026-08-16 03:56:34 -04:00
assistant_menu.py [FIX] execute : caviarder les clés d'API et les jetons Bearer 2026-09-09 07:35:15 -04:00
auto_ask.py [UPD] invites : 15 secondes pour décider, et le fichier nomme la base 2026-08-29 02:11:04 -04:00
database_manager.py [ADD] database: dupliquer une base, et la neutraliser pour de bon 2026-08-29 02:11:04 -04:00
deploy_form_extras.py [IMP] qemu deploy : pré-configurer la VM, et dire ce qui s'y installe 2026-09-04 02:03:52 -04:00
deploy_form_lib.py [IMP] qemu deploy : pré-configurer la VM, et dire ce qui s'y installe 2026-09-04 02:03:52 -04:00
deploy_form_plan.py [IMP] qemu deploy : pré-configurer la VM, et dire ce qui s'y installe 2026-09-04 02:03:52 -04:00
dev_tools.py [FIX] script todo : starship, URL corrigée, curl qui refuse le HTML 2026-09-04 00:38:29 -04:00
kdbx_manager.py [ADD] vpn openconnect : groupe d'URL, SSO délégué, mot de passe borné 2026-09-04 06:26:34 -04:00
logo_ascii.txt [IMP] bot assistant TODO 2025-04-27 02:40:20 -04:00
longtest_menu.py [ADD] long_test : partir d'un hôte existant, et le menu des deux piles 2026-08-29 01:53:03 -04:00
migration_form.py [ADD] migration: offer « go back to a step » on the resume screen 2026-08-22 07:23:59 -04:00
migration_stats.py [ADD] migration: see and repair the website COW views 2026-08-10 03:10:50 -04:00
migration_status.py [FIX] verdicts de migration : distinguer trouvaille et échec d'outil 2026-08-29 02:11:04 -04:00
migration_status_tui.py [FIX] migration state: open the quality screen in its own process 2026-08-22 07:23:59 -04:00
proxmox_deploy_form.py [IMP] qemu deploy : pré-configurer la VM, et dire ce qui s'y installe 2026-09-04 02:03:52 -04:00
proxmox_menu.py [ADD] LongTest : jusqu'à quel étage un Proxmox imbriqué tient-il 2026-08-29 01:53:03 -04:00
qemu_access.py [FIX] qemu menu : passer par le groupe libvirt plutôt que par sudo 2026-09-03 05:00:55 -04:00
qemu_deploy.py [IMP] qemu deploy : constater le motif du sudo, le dire avant l'invite 2026-09-04 02:27:51 -04:00
qemu_deploy_form.py [IMP] qemu deploy : pré-configurer la VM, et dire ce qui s'y installe 2026-09-04 02:03:52 -04:00
qemu_hardware.py [FIX] qemu 3D : voir l'ABI figée qui annule l'accélération demandée 2026-09-03 05:00:55 -04:00
qemu_install.py [IMP] qemu deploy : pré-configurer la VM, et dire ce qui s'y installe 2026-09-04 02:03:52 -04:00
qemu_install_monitor.py [FIX] qemu menu : nommer l'URI libvirt, sinon la liste des VM est vide 2026-09-03 05:00:55 -04:00
qemu_manage.py [ADD] qemu diagnostic : l'état 3D de chaque VM, ABI figée comprise 2026-09-03 05:00:55 -04:00
qemu_menu.py [ADD] qemu réseau : voir et recréer le sous-réseau des VM 2026-09-04 03:31:22 -04:00
qemu_network.py [ADD] qemu réseau : voir et recréer le sous-réseau des VM 2026-09-04 03:31:22 -04:00
qemu_privilege.py [ADD] qemu diagnostic : un relevé à transmettre, Gérer scindé en trois 2026-09-03 05:00:55 -04:00
qemu_recover.py [ADD] qemu diagnostic : un relevé à transmettre, Gérer scindé en trois 2026-09-03 05:00:55 -04:00
README.base.md [ADD] proxmox : un écran pour déployer sur un hôte distant 2026-08-25 03:17:13 -04:00
README.fr.md [ADD] proxmox : un écran pour déployer sur un hôte distant 2026-08-25 03:17:13 -04:00
README.md [ADD] proxmox : un écran pour déployer sur un hôte distant 2026-08-25 03:17:13 -04:00
source_todo.sh [ADD] install: mise as Python provider, pyenv as fallback 2026-08-16 23:33:49 -04:00
textual_setup.py [ADD] todo: install Textual on demand 2026-08-07 03:22:26 -04:00
todo.json [ADD] menu vpn : créer un profil, déposer les secrets, monter le tunnel 2026-09-04 03:43:02 +00:00
todo.py [ADD] assistant : serveur LLM reconnu, catalogue gpt, sessions locales 2026-09-09 07:35:15 -04:00
todo_example.json [ADD] menu vpn : créer un profil, déposer les secrets, monter le tunnel 2026-09-04 03:43:02 +00:00
todo_file_browser.py [FIX] todo: test menu, file browser and KeePass refusals 2026-08-16 03:56:34 -04:00
todo_i18n.py [ADD] assistant : serveur LLM reconnu, catalogue gpt, sessions locales 2026-09-09 07:35:15 -04:00
todo_install.py [ADD] script todo : installer les outils manquants, les quatre familles 2026-08-31 07:18:13 -04:00
todo_prefs.py [ADD] assistant : serveur LLM reconnu, catalogue gpt, sessions locales 2026-09-09 07:35:15 -04:00
todo_telemetry.py [ADD] script todo : installer les outils manquants, les quatre familles 2026-08-31 07:18:13 -04:00
todo_upgrade.py [ADD] commentaires : un relevé non bloquant, sa règle, le code nettoyé 2026-08-30 06:08:30 -04:00
version_manager.py [IMP] script: update copyright year to 2026 2026-03-11 23:16:05 -04:00
vpn_menu.py [FIX] vpn : ne plus demander la route par défaut à qui ne la pose pas 2026-09-08 09:41:17 -04:00

TODO is an assistant robot to use ERPLibre Execute it with ./script/todo/todo.py or make todo.

For a new project, copy todo_example.json to private/todo/todo_override.json | private/todo/todo_override_private.json and edit it.

The mail/ package is the mail client reachable from Assistant > Mail: several IMAP/SMTP accounts, a local cache, and a Textual TUI. See ../../doc/EMAIL.md.

Where the code lives

todo.py carries the menus and the general helpers. Everything around a single subject sits in its own file, and the whole thing is assembled by mixins on the TODO class — one file, one subject, its header states its boundary.

File What it owns
todo.py the menus, the configuration, the general helpers
qemu_menu.py the QEMU/KVM menu, the image catalogue, the statistics
qemu_deploy.py deciding then running a deployment
qemu_install.py the recipes run inside a VM
qemu_manage.py lifecycle, disks, hardware, cleanup, addresses
qemu_access.py SSH, tunnels, consoles, Android emulator
proxmox_menu.py the same, on a REMOTE Proxmox VE host

The two deployment forms — libvirt here, Proxmox over there — ask the same questions, so they share a foundation rather than each holding a copy:

File What it owns
deploy_form_lib.py pure logic (sizes, plan, totals, spec), the shared CSS, the resource-row factory, the progress view
deploy_form_plan.py the plan's gestures: overrides, locks, copies, renaming, free values
qemu_deploy_form.py what QEMU/KVM adds: desktops, tools, branches, install profiles
proxmox_deploy_form.py what Proxmox adds: host, storage, bridge, VMID, address

A form inherits PlanMixin and provides three hooks: which presets each resource offers, the name a VM would fall back to, and what a lock freezes. test_todo_deploy_form_lib.py fails if a form redefines a gesture the foundation already carries — that is what keeps the architecture from drifting back into two copies.