#28217: nested calls to functions decorated with sensitive_post_parameters
produces
unexpected results which parameters are considered sensitive
-------------------------------------------+------------------------
Reporter: Peter Zsoldos | Owner: (none)
Type: Bug | Status: new
Component: Error reporting | Version: 1.8
Severity: Normal | Keywords:
Triage Stage: Unreviewed | Has patch: 0
Needs documentation: 0 | Needs tests: 0
Patch needs improvement: 0 | Easy pickings: 0
UI/UX: 0 |
-------------------------------------------+------------------------
can reproduce with Django 1.8, 1.9, and 1.11
Rather than to explain in words, below is the testcase which reproduces
the issue. `test_all_outside_should_override_limited_inside` fails, and
for `test_what_should_happen_when_both_have_limited_variable_list` I'm not
even sure what would be the correct expected result - combine the
specified variable list?
{{{#!python
from django.http import HttpRequest
from django.test import SimpleTestCase
from django.views.decorators.debug import sensitive_post_parameters
class NestingSensitivePostParameterDecoratorsTestCase(SimpleTestCase):
def test_all_inside_should_override_limited_ones_outside(self):
self.assertEqual(
'__ALL__', self.get_request_sensitive_parameters(
inner_args=[],
outer_args=['foo', 'bar']
)
)
def test_all_outside_should_override_limited_inside(self):
self.assertEqual(
'__ALL__', self.get_request_sensitive_parameters(
inner_args=['foo', 'bar'],
outer_args=[]
)
)
def
test_what_should_happen_when_both_have_limited_variable_list(self):
self.assertEqual(
('bar', 'foo'), self.get_request_sensitive_parameters(
inner_args=['foo'],
outer_args=['bar']
)
)
def get_request_sensitive_parameters(self, inner_args, outer_args):
@sensitive_post_parameters(*outer_args)
def outer(request):
return inner(request)
@sensitive_post_parameters(*inner_args)
def inner(request):
return 'response'
request = HttpRequest()
outer(request)
return request.sensitive_post_parameters
}}}
--
Ticket URL: <https://code.djangoproject.com/ticket/28217>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
--
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/django-updates/051.8eea761ce9961cd7d0e1b88f3e3e8891%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.