Add hash_extension functionality

Add hash_extension functionality so _signature can be verified regardless of the extension.
This commit is contained in:
macneiln
2020-09-07 19:55:59 +12:00
committed by GitHub
parent d13c5349b6
commit c23e95a9e2
+15 -4
View File
@@ -190,7 +190,8 @@ def URL(a=None,
port=None, port=None,
encode_embedded_slash=False, encode_embedded_slash=False,
url_encode=True, url_encode=True,
language=None language=None,
hash_extension=True
): ):
""" """
generates a url '/a/c/f' corresponding to application a, controller c generates a url '/a/c/f' corresponding to application a, controller c
@@ -339,7 +340,8 @@ def URL(a=None,
if '.' in function: if '.' in function:
function, extension = function.rsplit('.', 1) function, extension = function.rsplit('.', 1)
function2 = '%s.%s' % (function, extension or 'html') # only include the extension as part of the variables for the hash if requested
function2 = '%s.%s' % (function, extension or 'html') if hash_extension else function
if not (application and controller and function): if not (application and controller and function):
raise SyntaxError('not enough information to build the url (%s %s %s)' % (application, controller, function)) raise SyntaxError('not enough information to build the url (%s %s %s)' % (application, controller, function))
@@ -416,7 +418,7 @@ def URL(a=None,
return url return url
def verifyURL(request, hmac_key=None, hash_vars=True, salt=None, user_signature=None): def verifyURL(request, hmac_key=None, hash_vars=True, salt=None, user_signature=None, hash_extension=True):
""" """
Verifies that a request's args & vars have not been tampered with by the user Verifies that a request's args & vars have not been tampered with by the user
@@ -477,10 +479,19 @@ def verifyURL(request, hmac_key=None, hash_vars=True, salt=None, user_signature=
# always include all of the args # always include all of the args
other = args and urllib_quote('/' + '/'.join([str(x) for x in args])) or '' other = args and urllib_quote('/' + '/'.join([str(x) for x in args])) or ''
# decide whether the extension should be part of the hash verification
h_extension = request.extension if hash_extension else ''
# only add a period to the extension when it exists otherwise empty
# extensions will fail to validate
if h_extension:
h_extension = '.%s' % (h_extension)
h_args = '/%s/%s/%s.%s%s' % (request.application, h_args = '/%s/%s/%s.%s%s' % (request.application,
request.controller, request.controller,
request.function, request.function,
request.extension, h_extension,
other) other)
# but only include those vars specified (allows more flexibility for use with # but only include those vars specified (allows more flexibility for use with