#31077: Add a safeguard to debug decorators
(sensitive_variables/sensitive_post_parameters) to prevent incorrect usage
------------------------------------------------+--------------------------
Reporter: Baptiste Mispelon | Owner: (none)
Type: Cleanup/optimization | Status: assigned
Component: Error reporting | Version: master
Severity: Normal | Keywords:
Triage Stage: Unreviewed | Has patch: 1
Needs documentation: 0 | Needs tests: 0
Patch needs improvement: 0 | Easy pickings: 0
UI/UX: 0 |
------------------------------------------------+--------------------------
While trying to reproduce ticket:26480#comment:5, I noticed that Django
happily lets you write this kind of code:
{{{
#!python
@sensitive_variables # incorrect usage, should be @sensitive_variables()
def is_password_ok(password):
return len(password) > 8
}}}
It's very easy to miss that you forgot the `()`. Most of the time it's not
really dangerous because the decorated function will be unusable but in
this case, the consequences are pretty nasty:
{{{
#!python
>>> bool(is_password_ok('asdf'))
True # you would expect False because len('asdf') < 8
}}}
I propose adding some code to both `sensitive_variables()` and
`sensitive_post_parameters()` that catches this misuse to prevent users
from decorating their functions incorrectly.
Because both decorators take either no arguments or only string arguments,
it's not too hard to detect the error with something like this:
{{{
#!python
def sensitive_variables(*variables):
if len(variables) == 1 and callable(variables[0]):
raise TypeError(...)
# ...
}}}
This should be fully backwards compatible and in most cases it will raise
the error at import time which should make things easier to fix for those
who've incorrectly used the decorator.
(I've confirmed with the security team that this does not need to be
treated as a security issue)
--
Ticket URL: <https://code.djangoproject.com/ticket/31077>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
--
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/django-updates/052.707add9da96ff1293eb1de8006da9e9c%40djangoproject.com.