#28104: Django conditional view processing decorator adds stale ETag
-----------------------------------------+------------------------
               Reporter:  safialishah    |          Owner:  nobody
                   Type:  Bug            |         Status:  new
              Component:  Uncategorized  |        Version:  1.11
               Severity:  Normal         |       Keywords:
           Triage Stage:  Unreviewed     |      Has patch:  0
    Needs documentation:  0              |    Needs tests:  0
Patch needs improvement:  0              |  Easy pickings:  1
                  UI/UX:  0              |
-----------------------------------------+------------------------
 For conditional view processing, Django provides the @condition decorator,
 which is defined here
 https://github.com/django/django/blob/master/django/views/decorators/http.py

 While it works nicely for GET requests, it has a bug when handling unsafe
 methods such as PUT or PATCH that modify a resource.
 If the PUT or PATCH request contains a valid ETag in the If-Match header,
 the request is allowed to go through to the view for processing. Once
 processed, the resource would have been modified, which would most likely
 cause the ETag to be updated.

 However, the @condition decorator would simply add the ETag that it had
 computed *before* the request was processed, into the PUT or PATCH
 response. By now this ETag is not valid anymore. Same would apply to the
 Last-Modified header.

 Below is the snippet of the buggy code:-
 {{{
 #!div style="font-size: 80%"
   {{{#!python
             # Set relevant headers on the response if they don't already
 exist.
             if res_last_modified and not response.has_header('Last-
 Modified'):
                 response['Last-Modified'] = http_date(res_last_modified)
 # possibly stale value
             if res_etag and not response.has_header('ETag'):
                 response['ETag'] = res_etag  # possible stale value
   }}}
 }}}

 There are two solutions:
 1) If the request was for an unsafe method, re-compute the ETag before
 sending the response back.
 or
 2) As pointed out by Kevin [http://stackoverflow.com/questions/43495112
 /django-conditional-view-processing-decorator-adds-stale-etag here], to
 comform to the RFC better, we should avoid sending ETag and Last-Modified
 headers in response to unsafe methods.

--
Ticket URL: <https://code.djangoproject.com/ticket/28104>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

-- 
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/django-updates/054.e7c12a187c4a3cf222fc60a0305136f5%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to