ce9a926246
Backend (Python):
- Split app/routes.py (1,389 lines) into 6 Flask blueprints (upload, analysis,
results, doppelganger, management, api) under app/blueprints/, plus
service modules (rendering, summary, tool_check, error_handling) under
app/services/, and the shared RouteHelpers class in app/helpers.py.
app/__init__.py wires shared deps via app.extensions['litterbox'].
- Split app/utils.py (1,400 lines) into the app/utils/ package with
single-concern modules: file_io, validators, path_manager, risk_analyzer,
forensics, json_helpers, reporting. No facade — every caller migrated.
- Extracted BaseSubprocessAnalyzer in app/analyzers/base.py; refactored 9
subprocess analyzers (yara/checkplz/stringnalyzer static; yara/pe_sieve/
moneta/patriot/hsb/hollows_hunter dynamic) as thin subclasses that only
declare config + implement _parse_output.
Frontend (JS):
- Split results.js (2,060), holygrail.js (1,025), byovd_info.js (1,069),
and upload.js (974) into per-concern ES6 modules under
app/static/js/{results,holygrail,byovd,upload}/.
- Added app/static/js/utils/ with shared helpers: escape, formatters,
severity, fetch, modals, dom (single source of truth for escapeHtml,
formatBytes, severity-color mapping, etc.).
- Converted base.js, summary.js, blender.js, fuzzy.js to ES6 modules;
every <script> tag now uses type="module". window.X assignments preserved
so inline onclick handlers in templates keep resolving.
- Targeted XSS hardening at user-data interpolation sites in results
renderers (str.data, hex_dump, scan_info.target, list items).
Templates:
- New app/templates/partials/_macros.html with reusable scanner-table
macros + 3-card status grid; static_info.html and dynamic_info.html
migrated to use them, eliminating identical-HTML duplication.
CSS:
- Fixed broken @apply in .drag-over (no Tailwind build pipeline → @apply
was silently ignored, leaving drag-and-drop visual feedback broken).
Replaced with raw CSS equivalent.
- Dedented stray 8-space-indented block (lines 127-end) for consistency.
- Added header comment documenting the no-build-pipeline constraint.
Gitignore:
- Anchored Results/, Uploads/, DoppelgangerDB/Blender/, and Scanners/*
patterns to repo root with leading slash so they don't shadow same-
named directories elsewhere (notably the new app/static/js/results/
module directory and app/blueprints/results.py).
- Added /Scanners/PE-Sieve/process_*/ for runtime scan artifacts.
48 lines
1.4 KiB
Python
48 lines
1.4 KiB
Python
# app/utils/__init__.py
|
|
"""Re-exports from the utils package for ergonomic imports.
|
|
|
|
Prefer importing directly from submodules in new code:
|
|
from app.utils.risk_analyzer import calculate_risk
|
|
from app.utils.path_manager import find_file_by_hash
|
|
"""
|
|
from .file_io import (
|
|
FileTypeDetector,
|
|
detect_file_type,
|
|
get_lnk_info,
|
|
get_office_info,
|
|
get_pe_info,
|
|
save_uploaded_file,
|
|
)
|
|
from .forensics import (
|
|
RUNTIME_IMPORTS,
|
|
SecurityAnalyzer,
|
|
calculate_entropy,
|
|
get_security_analyzer,
|
|
)
|
|
from .json_helpers import (
|
|
extract_detection_counts,
|
|
format_hex,
|
|
format_size,
|
|
load_json_file,
|
|
)
|
|
from .path_manager import find_file_by_hash
|
|
from .reporting import generate_html_report
|
|
from .risk_analyzer import (
|
|
RiskCalculator,
|
|
calculate_risk,
|
|
calculate_yara_risk,
|
|
get_entropy_risk_level,
|
|
get_risk_level,
|
|
)
|
|
from .validators import allowed_file, check_tool, validate_pid
|
|
|
|
__all__ = [
|
|
'FileTypeDetector', 'RUNTIME_IMPORTS', 'RiskCalculator', 'SecurityAnalyzer',
|
|
'allowed_file', 'calculate_entropy', 'calculate_risk', 'calculate_yara_risk',
|
|
'check_tool', 'detect_file_type', 'extract_detection_counts',
|
|
'find_file_by_hash', 'format_hex', 'format_size', 'generate_html_report',
|
|
'get_entropy_risk_level', 'get_lnk_info', 'get_office_info', 'get_pe_info',
|
|
'get_risk_level', 'get_security_analyzer', 'load_json_file',
|
|
'save_uploaded_file', 'validate_pid',
|
|
]
|