fix: bug scan - fix 10 bugs across backend (search field names, missing import, file handle leak, None guard, race condition, hardcoded secrets)

This commit is contained in:
chunyu
2026-08-28 13:49:55 +08:00
parent a1048de0fe
commit a2ba489b46
5 changed files with 36 additions and 33 deletions
+10 -16
View File
@@ -67,8 +67,8 @@ class GlobalSearchView(APIView):
for article in articles:
cover_url = ''
if article.cover and hasattr(article.cover, 'url'):
cover_url = request.build_absolute_uri(article.cover.url)
if article.cover_image and hasattr(article.cover_image, 'url'):
cover_url = request.build_absolute_uri(article.cover_image.url)
excerpt = article.excerpt or ''
if not excerpt and article.content:
@@ -91,21 +91,16 @@ class GlobalSearchView(APIView):
).order_by('-created_at')[:100]
for tool in tools:
cover_url = ''
if tool.icon and hasattr(tool.icon, 'url'):
cover_url = request.build_absolute_uri(tool.icon.url)
results.append({
'id': tool.id,
'type': '工具',
'title': tool.name,
'desc': tool.description or '',
'cover': cover_url,
'views': tool.views or 0,
'likes': tool.likes or 0,
'cover': '',
'views': tool.usage_count or 0,
'likes': 0,
'url': f'/use?tool={tool.id}',
})
if content_type == 'all' or content_type == 'course':
courses = Course.objects.filter(
Q(title__icontains=q) | Q(description__icontains=q)
@@ -113,8 +108,8 @@ class GlobalSearchView(APIView):
for course in courses:
cover_url = ''
if course.cover and hasattr(course.cover, 'url'):
cover_url = request.build_absolute_uri(course.cover.url)
if course.cover_image and hasattr(course.cover_image, 'url'):
cover_url = request.build_absolute_uri(course.cover_image.url)
results.append({
'id': course.id,
@@ -122,9 +117,8 @@ class GlobalSearchView(APIView):
'title': course.title,
'desc': course.description or '',
'cover': cover_url,
'views': course.views or 0,
'likes': course.likes or 0,
'url': f'/courses/{course.id}',
'views': 0,
'likes': 0,
})
if content_type == 'all' or content_type == 'api':
@@ -236,4 +230,4 @@ class HotKeywordsView(APIView):
'Vue3',
'Python',
]
return create_standardized_response(data=hot_keywords, code=ResponseCode.SUCCESS)
return create_standardized_response(data=hot_keywords, code=ResponseCode.SUCCESS)