[FIX] web: make DB name more flexible

This commit is contained in:
Nicolas Martinelli
2017-04-24 08:02:22 +02:00
parent 91c00bc011
commit 9e6860a228
3 changed files with 17 additions and 3 deletions
+7
View File
@@ -52,6 +52,8 @@ env.filters["json"] = json.dumps
# 1 week cache for asset bundles as advised by Google Page Speed
BUNDLE_MAXAGE = 60 * 60 * 24 * 7
DBNAME_PATTERN = '^[a-zA-Z0-9][a-zA-Z0-9_.-]+$'
#----------------------------------------------------------
# OpenERP Web helpers
#----------------------------------------------------------
@@ -630,6 +632,7 @@ class Database(http.Controller):
d['list_db'] = openerp.tools.config['list_db']
d['langs'] = openerp.service.db.exp_list_lang()
d['countries'] = openerp.service.db.exp_list_countries()
d['pattern'] = DBNAME_PATTERN
# databases list
d['databases'] = []
try:
@@ -651,6 +654,8 @@ class Database(http.Controller):
@http.route('/web/database/create', type='http', auth="none", methods=['POST'], csrf=False)
def create(self, master_pwd, name, lang, password, **post):
try:
if not re.match(DBNAME_PATTERN, name):
raise Exception(_('Invalid database name. Only alphanumerical characters, underscore, hyphen and dot are allowed.'))
# country code could be = "False" which is actually True in python
country_code = post.get('country_code') or False
request.session.proxy("db").create_database(master_pwd, name, bool(post.get('demo')), lang, password, post['login'], country_code)
@@ -663,6 +668,8 @@ class Database(http.Controller):
@http.route('/web/database/duplicate', type='http', auth="none", methods=['POST'], csrf=False)
def duplicate(self, master_pwd, name, new_name):
try:
if not re.match(DBNAME_PATTERN, new_name):
raise Exception(_('Invalid database name. Only alphanumerical characters, underscore, hyphen and dot are allowed.'))
request.session.proxy("db").duplicate_database(master_pwd, name, new_name)
return http.local_redirect('/web/database/manager')
except Exception, e:
+7
View File
@@ -1148,6 +1148,13 @@ msgstr ""
msgid "Invalid data"
msgstr ""
#. module: web
#: code:addons/web/controllers/main.py:655
#: code:addons/web/controllers/main.py:669
#, python-format
msgid "Invalid database name. Only alphanumerical characters, underscore, hyphen and dot are allowed."
msgstr ""
#. module: web
#. openerp-web
#: code:addons/web/static/src/js/widgets/debug_manager.js:106
+3 -3
View File
@@ -61,7 +61,7 @@
<div class="row">
<div class="col-md-12">
<label for="name" class="control-label">Database Name</label>
<input id="name" type="text" name="name" class="form-control" required="required" autocomplete="off"/>
<input id="name" type="text" name="name" class="form-control" required="required" autocomplete="off" pattern="{{ pattern }}" title="Only alphanumerical characters, underscore, hyphen and dot are allowed"/>
</div>
</div>
</div>
@@ -207,7 +207,7 @@
</div>
<div class="form-group">
<label for="name" class="control-label">Database Name</label>
<input id="name" type="text" name="name" class="form-control" required="required"/>
<input id="name" type="text" name="name" class="form-control" required="required" pattern="{{ pattern }}" title="Only alphanumerical characters, underscore, hyphen and dot are allowed"/>
</div>
<div class="form-group">
<label for="copy">This database might have been moved or copied.</label>
@@ -280,7 +280,7 @@
</div>
<div class="form-group">
<label for="new_name" class="control-label">New Name</label>
<input id="new_name" type="text" name="new_name" class="form-control" required="required"/>
<input id="new_name" type="text" name="new_name" class="form-control" required="required" pattern="{{ pattern }}" title="Only alphanumerical characters, underscore, hyphen and dot are allowed"/>
</div>
</div>
<div class="modal-footer">