Close the leaked httpx.AsyncClient in MyWhoosh sync runs, ensure hard
failures finish sync_runs as FAILED instead of leaving them stuck at
RUNNING, log (non-benign) exceptions surfaced by sync_all_enabled during
scheduled ticks, classify GarminImportRejected as a non-retryable
per-activity failure, fix a bug where a live Garmin-class action_required
state could be silently cleared by a run that did no Garmin work, use the
activity's DB primary key instead of the unsanitized remote id for
filesystem paths, add regression/coverage tests for the health-state fix
and MFA code threading through the real SyncManager, add idempotency
coverage to the two-user acceptance test, and note the Dockerfile's
single-process assumption.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
- C1: drop module-level app singleton in app/main.py so importing the
package no longer validates Settings or creates DATA_DIR; run uvicorn
with --factory in the Dockerfile. pytest now collects and passes with
no ambient env vars.
- I2: add missing app/auth, app/security, app/web __init__.py so
setuptools discovers all five packages.
- I3: resolve the Jinja2 template directory relative to __file__ instead
of the process CWD.
- I4: add .gitignore covering .env, data/, .venv/, caches and build
artifacts so example deployment secrets cannot be committed.
- I5: assert UserRepository.list_enabled() excludes disabled users.
- M6: encode both operands before hmac.compare_digest in validate_csrf so
a non-ASCII token yields 403 instead of an unhandled 500.
- M9: remove unused relationship / HealthState imports.
- M11: make session cookie https_only configurable via SESSION_HTTPS_ONLY
(default unchanged: false).
- M13: dispose SQLAlchemy engines in the db_session and client fixtures.
Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>