[FIX] ETag value must be quote-delimited

According to RFC 7232 # 2.3, an etag must be wrapped in double quotes:

    entity-tag = [ weak ] opaque-tag
    opaque-tag = DQUOTE *etagc DQUOTE
    etagc      = %x21 / %x23-7E / obs-text
               ; VCHAR except double quotes, plus obs-text

Odoo didn't properly quote etags, which could lead to stripping or
failures when putting Odoo behind strict HTTP proxies.
This commit is contained in:
andreparames
2016-09-15 08:15:34 +02:00
committed by xmo-odoo
parent 9a5b040ff8
commit 07a207c07c
+1 -1
View File
@@ -302,7 +302,7 @@ class ir_http(osv.AbstractModel):
# cache
etag = hasattr(request, 'httprequest') and request.httprequest.headers.get('If-None-Match')
retag = hashlib.md5(last_update).hexdigest()
retag = '"%s"' % hashlib.md5(last_update).hexdigest()
status = status or (304 if etag == retag else 200)
headers.append(('ETag', retag))
headers.append(('Cache-Control', 'max-age=%s' % (STATIC_CACHE if unique else 0)))