Skip to content
GitLab
Explore
Sign in
Register
Primary navigation
Search or go to…
Project
funkwhale
Manage
Activity
Members
Labels
Plan
Issues
0
Issue boards
Milestones
Wiki
Code
Merge requests
0
Repository
Branches
Commits
Tags
Repository graph
Compare revisions
Snippets
Build
Pipelines
Jobs
Pipeline schedules
Artifacts
Deploy
Releases
Container Registry
Model registry
Operate
Environments
Monitor
Incidents
Service Desk
Analyze
Value stream analytics
Contributor analytics
CI/CD analytics
Repository analytics
Model experiments
Help
Help
Support
GitLab documentation
Compare GitLab plans
Community forum
Contribute to GitLab
Provide feedback
Keyboard shortcuts
?
Snippets
Groups
Projects
Show more breadcrumbs
Zwordi
funkwhale
Commits
7b84a988
Verified
Commit
7b84a988
authored
6 years ago
by
Eliot Berriot
Browse files
Options
Downloads
Patches
Plain Diff
See #223: dangerous actions can now prevent executing an action on all objects
parent
7df9112d
No related branches found
Branches containing commit
No related tags found
Tags containing commit
No related merge requests found
Changes
2
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
api/funkwhale_api/common/serializers.py
+7
-0
7 additions, 0 deletions
api/funkwhale_api/common/serializers.py
api/tests/common/test_serializers.py
+36
-0
36 additions, 0 deletions
api/tests/common/test_serializers.py
with
43 additions
and
0 deletions
api/funkwhale_api/common/serializers.py
+
7
−
0
View file @
7b84a988
...
...
@@ -12,6 +12,9 @@ class ActionSerializer(serializers.Serializer):
filters
=
serializers
.
DictField
(
required
=
False
)
actions
=
None
filterset_class
=
None
# those are actions identifier where we don't want to allow the "all"
# selector because it's to dangerous. Like object deletion.
dangerous_actions
=
[]
def
__init__
(
self
,
*
args
,
**
kwargs
):
self
.
queryset
=
kwargs
.
pop
(
'
queryset
'
)
...
...
@@ -49,6 +52,10 @@ class ActionSerializer(serializers.Serializer):
'
list of identifiers or the string
"
all
"
.
'
.
format
(
value
))
def
validate
(
self
,
data
):
dangerous
=
data
[
'
action
'
]
in
self
.
dangerous_actions
if
dangerous
and
self
.
initial_data
[
'
objects
'
]
==
'
all
'
:
raise
serializers
.
ValidationError
(
'
This action is to dangerous to be applied to all objects
'
)
if
self
.
filterset_class
and
'
filters
'
in
data
:
qs_filterset
=
self
.
filterset_class
(
data
[
'
filters
'
],
queryset
=
data
[
'
objects
'
])
...
...
This diff is collapsed.
Click to expand it.
api/tests/common/test_serializers.py
+
36
−
0
View file @
7b84a988
...
...
@@ -18,6 +18,17 @@ class TestSerializer(serializers.ActionSerializer):
return
{
'
hello
'
:
'
world
'
}
class
TestDangerousSerializer
(
serializers
.
ActionSerializer
):
actions
=
[
'
test
'
,
'
test_dangerous
'
]
dangerous_actions
=
[
'
test_dangerous
'
]
def
handle_test
(
self
,
objects
):
pass
def
handle_test_dangerous
(
self
,
objects
):
pass
def
test_action_serializer_validates_action
():
data
=
{
'
objects
'
:
'
all
'
,
'
action
'
:
'
nope
'
}
serializer
=
TestSerializer
(
data
,
queryset
=
models
.
User
.
objects
.
none
())
...
...
@@ -98,3 +109,28 @@ def test_action_serializers_validates_at_least_one_object():
assert
serializer
.
is_valid
()
is
False
assert
'
non_field_errors
'
in
serializer
.
errors
def
test_dangerous_actions_refuses_all
(
factories
):
factories
[
'
users.User
'
]()
data
=
{
'
objects
'
:
'
all
'
,
'
action
'
:
'
test_dangerous
'
,
}
serializer
=
TestDangerousSerializer
(
data
,
queryset
=
models
.
User
.
objects
.
all
())
assert
serializer
.
is_valid
()
is
False
assert
'
non_field_errors
'
in
serializer
.
errors
def
test_dangerous_actions_refuses_not_listed
(
factories
):
factories
[
'
users.User
'
]()
data
=
{
'
objects
'
:
'
all
'
,
'
action
'
:
'
test
'
,
}
serializer
=
TestDangerousSerializer
(
data
,
queryset
=
models
.
User
.
objects
.
all
())
assert
serializer
.
is_valid
()
is
True
This diff is collapsed.
Click to expand it.
Preview
0%
Loading
Try again
or
attach a new file
.
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Save comment
Cancel
Please
register
or
sign in
to comment