#28104: Django conditional view processing decorator adds stale ETag
-----------------------------------------+------------------------
Reporter: safialishah | Owner: nobody
Type: Bug | Status: new
Component: Uncategorized | Version: 1.11
Severity: Normal | Keywords:
Triage Stage: Unreviewed | Has patch: 0
Needs documentation: 0 | Needs tests: 0
Patch needs improvement: 0 | Easy pickings: 1
UI/UX: 0 |
-----------------------------------------+------------------------
For conditional view processing, Django provides the @condition decorator,
which is defined here
https://github.com/django/django/blob/master/django/views/decorators/http.py
While it works nicely for GET requests, it has a bug when handling unsafe
methods such as PUT or PATCH that modify a resource.
If the PUT or PATCH request contains a valid ETag in the If-Match header,
the request is allowed to go through to the view for processing. Once
processed, the resource would have been modified, which would most likely
cause the ETag to be updated.
However, the @condition decorator would simply add the ETag that it had
computed *before* the request was processed, into the PUT or PATCH
response. By now this ETag is not valid anymore. Same would apply to the
Last-Modified header.
Below is the snippet of the buggy code:-
{{{
#!div style="font-size: 80%"
{{{#!python
# Set relevant headers on the response if they don't already
exist.
if res_last_modified and not response.has_header('Last-
Modified'):
response['Last-Modified'] = http_date(res_last_modified)
# possibly stale value
if res_etag and not response.has_header('ETag'):
response['ETag'] = res_etag # possible stale value
}}}
}}}
There are two solutions:
1) If the request was for an unsafe method, re-compute the ETag before
sending the response back.
or
2) As pointed out by Kevin [http://stackoverflow.com/questions/43495112
/django-conditional-view-processing-decorator-adds-stale-etag here], to
comform to the RFC better, we should avoid sending ETag and Last-Modified
headers in response to unsafe methods.
--
Ticket URL: <https://code.djangoproject.com/ticket/28104>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
--
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/django-updates/054.e7c12a187c4a3cf222fc60a0305136f5%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.