#28680: Document that Func's.__init__()'s **extra and as_sql()'s **extra_context
aren't escaped
------------------------------------------------+------------------------
               Reporter:  Hynek Cernoch         |          Owner:  nobody
                   Type:  Cleanup/optimization  |         Status:  new
              Component:  Documentation         |        Version:  1.11
               Severity:  Normal                |       Keywords:
           Triage Stage:  Accepted              |      Has patch:  0
    Needs documentation:  0                     |    Needs tests:  0
Patch needs improvement:  0                     |  Easy pickings:  0
                  UI/UX:  0                     |
------------------------------------------------+------------------------
 I found an SQL injection possibility due to unclear documentation about
 query expression:

 `class Func(*expressions, **extra)`

 if unsafe user input is passed by keyword parameters `extra` it is
 unprotected, while positional parameters are protected by compile and
 passing through sql execute parameters, never merged to SQL by % format.
 {{{
 class Position(Func):
     function = 'POSITION'
     template = "%(function)s('%(substring)s' in %(expressions)s)"

     def __init__(self, expression, substring):
         super(Position, self).__init__(expression, substring=substring)
 }}}

-- 
Ticket URL: <https://code.djangoproject.com/ticket/28680>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.

-- 
You received this message because you are subscribed to the Google Groups 
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email 
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit 
https://groups.google.com/d/msgid/django-updates/051.bca24e5d24f5442f0a843840375065a1%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.

Reply via email to