From patchwork Sun Sep 6 12:55:48 2020 Content-Type: text/plain; charset="utf-8" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit X-Patchwork-Submitter: Thomas Bracht Laumann Jespersen X-Patchwork-Id: 1358304 Return-Path: X-Original-To: incoming@patchwork.ozlabs.org Delivered-To: patchwork-incoming@bilbo.ozlabs.org Received: from lists.ozlabs.org (lists.ozlabs.org [IPv6:2401:3900:2:1::3]) (using TLSv1.3 with cipher TLS_AES_256_GCM_SHA384 (256/256 bits) key-exchange X25519 server-signature RSA-PSS (4096 bits) server-digest SHA256) (No client certificate requested) by ozlabs.org (Postfix) with ESMTPS id 4Bks9m137zz9sSP for ; Sun, 6 Sep 2020 23:06:20 +1000 (AEST) Authentication-Results: ozlabs.org; dmarc=none (p=none dis=none) header.from=laumann.xyz Authentication-Results: ozlabs.org; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=laumann.xyz header.i=@laumann.xyz header.a=rsa-sha256 header.s=fm1 header.b=lENZ31Gz; dkim=fail reason="signature verification failed" (2048-bit key; unprotected) header.d=messagingengine.com header.i=@messagingengine.com header.a=rsa-sha256 header.s=fm3 header.b=UAgiM1jS; dkim-atps=neutral Received: from bilbo.ozlabs.org (lists.ozlabs.org [IPv6:2401:3900:2:1::3]) by lists.ozlabs.org (Postfix) with ESMTP id 4Bks9l4R9XzDqTs for ; Sun, 6 Sep 2020 23:06:19 +1000 (AEST) X-Original-To: patchwork@lists.ozlabs.org Delivered-To: patchwork@lists.ozlabs.org Authentication-Results: lists.ozlabs.org; spf=pass (sender SPF authorized) smtp.mailfrom=laumann.xyz (client-ip=66.111.4.29; helo=out5-smtp.messagingengine.com; envelope-from=t@laumann.xyz; receiver=) Authentication-Results: lists.ozlabs.org; dmarc=none (p=none dis=none) header.from=laumann.xyz Authentication-Results: lists.ozlabs.org; dkim=pass (2048-bit key; unprotected) header.d=laumann.xyz header.i=@laumann.xyz header.a=rsa-sha256 header.s=fm1 header.b=lENZ31Gz; dkim=pass (2048-bit key; unprotected) header.d=messagingengine.com header.i=@messagingengine.com header.a=rsa-sha256 header.s=fm3 header.b=UAgiM1jS; dkim-atps=neutral X-Greylist: delayed 426 seconds by postgrey-1.36 at bilbo; Sun, 06 Sep 2020 23:06:10 AEST Received: from out5-smtp.messagingengine.com (out5-smtp.messagingengine.com [66.111.4.29]) (using TLSv1.2 with cipher ECDHE-RSA-AES256-GCM-SHA384 (256/256 bits)) (No client certificate requested) by lists.ozlabs.org (Postfix) with ESMTPS id 4Bks9Z3LYfzDqTG for ; Sun, 6 Sep 2020 23:06:10 +1000 (AEST) Received: from compute4.internal (compute4.nyi.internal [10.202.2.44]) by mailout.nyi.internal (Postfix) with ESMTP id 53C985C00F2; Sun, 6 Sep 2020 08:59:01 -0400 (EDT) Received: from mailfrontend2 ([10.202.2.163]) by compute4.internal (MEProxy); Sun, 06 Sep 2020 08:59:01 -0400 DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=laumann.xyz; h= from:to:cc:subject:date:message-id:mime-version :content-transfer-encoding; s=fm1; bh=dl2ayGnl1FORUo8hU3HINC4upX OB7YpBxxR1kIcND0I=; b=lENZ31GzA33NgxyS9fJGy5PD39CUeqVWJG9O7/zith Ckl1CYpiWwQiVMl3mJMq8KZpMnXxR3enpx8v3CUFqwmJ16iAjkt+of1RDGEj02cR tlxOUfT7SGBcHl0zG0utdtDwKMH48Fd9femBibLR4X7vfQpId3ShP0f2QbhVovqj 8ZconhaEXzmIuGp7BQitlhDBWNEe1bOofSLohfUlu1hV1aBbxDNtoWTX1dCwDTjJ VrQSU5qlV/OdqFW3y4yZptGkCyvwkGQRx00FOgN5u0ISU2TrcyNFdoxURF3I5XWU ytGgsRLqYCv4N6DEaUJaD+zMKcgc9J6cml8slWHxmcTQ== DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d= messagingengine.com; h=cc:content-transfer-encoding:date:from :message-id:mime-version:subject:to:x-me-proxy:x-me-proxy :x-me-sender:x-me-sender:x-sasl-enc; s=fm3; bh=dl2ayGnl1FORUo8hU 3HINC4upXOB7YpBxxR1kIcND0I=; b=UAgiM1jSEYYsF5zcNFzGVbJfOoeiC45N1 Jk+e0vaLkZm/4fPGasY6858YyVSYRriFY1VB85Ig+yWK43JZHhDLBUb+qMWS8bZc T9+Uubdulu7CjQ7gCWbB8/qvPl3bH6Xe0K67LOPJByAsVDPCJ9e4SWMuRNoDgHbb IU1wxZYPRF5ekppg1CAy5rHZj8LWTwonE2YCLuDAAJMTYi1Z560Npm6KwEMZ53jp Uh6tboi1H9/T1FzFesFvAXHhuRRG+ZOOC6P42wA13GDJOTjArnNuMa/mn7wTKfpC FYcuAFFohAIA8o/gRgiq7AkVbVPbkJiTNyYxq8Q/ZScQzFOY2xzTg== X-ME-Sender: X-ME-Proxy-Cause: gggruggvucftvghtrhhoucdtuddrgeduiedrudegjedgheelucetufdoteggodetrfdotf fvucfrrhhofhhilhgvmecuhfgrshhtofgrihhlpdfqfgfvpdfurfetoffkrfgpnffqhgen uceurghilhhouhhtmecufedttdenucgfrhhlucfvnfffucdlfeehmdenucfjughrpefhvf fufffkofgggfestdekredtredttdenucfhrhhomhepvfhhohhmrghsuceurhgrtghhthcu nfgruhhmrghnnhculfgvshhpvghrshgvnhcuoehtsehlrghumhgrnhhnrdighiiiqeenuc ggtffrrghtthgvrhhnpeeifeeftdffieevveevhefhgfehueelhfelleeiffegtdejledv jeejvefffeekhfenucffohhmrghinhepshhrrdhhthenucfkphepkedtrdejuddrudegvd druddvieenucevlhhushhtvghrufhiiigvpedtnecurfgrrhgrmhepmhgrihhlfhhrohhm pehtsehlrghumhgrnhhnrdighiii X-ME-Proxy: Received: from localhost.localdomain (unknown [80.71.142.126]) by mail.messagingengine.com (Postfix) with ESMTPA id 42B1D3064610; Sun, 6 Sep 2020 08:58:59 -0400 (EDT) From: Thomas Bracht Laumann Jespersen To: patchwork@lists.ozlabs.org Subject: [PATCH] models: Validate Project.linkname does not contain forward slash Date: Sun, 6 Sep 2020 14:55:48 +0200 Message-Id: <20200906125547.9659-1-t@laumann.xyz> X-Mailer: git-send-email 2.26.2 MIME-Version: 1.0 X-BeenThere: patchwork@lists.ozlabs.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: Patchwork development List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , Errors-To: patchwork-bounces+incoming=patchwork.ozlabs.org@lists.ozlabs.org Sender: "Patchwork" I started by creating a project that contained a forward slash (importing patches from https://lists.sr.ht/~sircmpwn/sr.ht-dev/) and it fails to render the "projects" main page. The specific error reads: NoReverseMatch at / Reverse for 'patch-list' with keyword arguments '{'project_id': 'foo/bar'}' not found. 1 pattern(s) tried: ['project/(?P[^/]+)/list/$'] which appears to explicitly disallow forward slashes. So I think it makes sense to validate that project linkname doesn't contain forward slahes. Signed-off-by: Thomas Bracht Laumann Jespersen --- I hard a hard time satisfying flake8, so I ended up disabling the pre-commit hook. I also looked over the documentation for contributors and figure that if a release note is required, just let me know then I'll add it. .../0044_add_project_linkname_validation.py | 19 +++++++++++++++++++ patchwork/models.py | 10 +++++++++- 2 files changed, 28 insertions(+), 1 deletion(-) create mode 100644 patchwork/migrations/0044_add_project_linkname_validation.py diff --git a/patchwork/migrations/0044_add_project_linkname_validation.py b/patchwork/migrations/0044_add_project_linkname_validation.py new file mode 100644 index 0000000..2fff7df --- /dev/null +++ b/patchwork/migrations/0044_add_project_linkname_validation.py @@ -0,0 +1,19 @@ +# Generated by Django 3.0.10 on 2020-09-06 22:47 + +from django.db import migrations, models +import patchwork.models + + +class Migration(migrations.Migration): + + dependencies = [ + ('patchwork', '0043_merge_patch_submission'), + ] + + operations = [ + migrations.AlterField( + model_name='project', + name='linkname', + field=models.CharField(max_length=255, unique=True, validators=[patchwork.models.validate_project_linkname]), + ), + ] diff --git a/patchwork/models.py b/patchwork/models.py index 77ab924..9027219 100644 --- a/patchwork/models.py +++ b/patchwork/models.py @@ -31,6 +31,13 @@ def validate_regex_compiles(regex_string): raise ValidationError('Invalid regular expression entered!') +def validate_project_linkname(linkname): + if re.fullmatch(r'[^/]+', linkname) is None: + raise ValidationError( + 'Invalid project linkname: Value cannot contain forward slash (/)' + ) + + class Person(models.Model): # properties @@ -56,7 +63,8 @@ class Person(models.Model): class Project(models.Model): # properties - linkname = models.CharField(max_length=255, unique=True) + linkname = models.CharField(max_length=255, unique=True, + validators=[validate_project_linkname]) name = models.CharField(max_length=255, unique=True) listid = models.CharField(max_length=255) listemail = models.CharField(max_length=200)