From 9e6860a22808a114a2f745e4bfd288e08460151b Mon Sep 17 00:00:00 2001 From: Nicolas Martinelli Date: Fri, 21 Apr 2017 15:23:17 +0200 Subject: [PATCH] [FIX] web: make DB name more flexible --- addons/web/controllers/main.py | 7 +++++++ addons/web/i18n/web.pot | 7 +++++++ addons/web/views/database_manager.html | 6 +++--- 3 files changed, 17 insertions(+), 3 deletions(-) diff --git a/addons/web/controllers/main.py b/addons/web/controllers/main.py index cc62a287aca..3dc9d4526bc 100644 --- a/addons/web/controllers/main.py +++ b/addons/web/controllers/main.py @@ -52,6 +52,8 @@ env.filters["json"] = json.dumps # 1 week cache for asset bundles as advised by Google Page Speed BUNDLE_MAXAGE = 60 * 60 * 24 * 7 +DBNAME_PATTERN = '^[a-zA-Z0-9][a-zA-Z0-9_.-]+$' + #---------------------------------------------------------- # OpenERP Web helpers #---------------------------------------------------------- @@ -630,6 +632,7 @@ class Database(http.Controller): d['list_db'] = openerp.tools.config['list_db'] d['langs'] = openerp.service.db.exp_list_lang() d['countries'] = openerp.service.db.exp_list_countries() + d['pattern'] = DBNAME_PATTERN # databases list d['databases'] = [] try: @@ -651,6 +654,8 @@ class Database(http.Controller): @http.route('/web/database/create', type='http', auth="none", methods=['POST'], csrf=False) def create(self, master_pwd, name, lang, password, **post): try: + if not re.match(DBNAME_PATTERN, name): + raise Exception(_('Invalid database name. Only alphanumerical characters, underscore, hyphen and dot are allowed.')) # country code could be = "False" which is actually True in python country_code = post.get('country_code') or False request.session.proxy("db").create_database(master_pwd, name, bool(post.get('demo')), lang, password, post['login'], country_code) @@ -663,6 +668,8 @@ class Database(http.Controller): @http.route('/web/database/duplicate', type='http', auth="none", methods=['POST'], csrf=False) def duplicate(self, master_pwd, name, new_name): try: + if not re.match(DBNAME_PATTERN, new_name): + raise Exception(_('Invalid database name. Only alphanumerical characters, underscore, hyphen and dot are allowed.')) request.session.proxy("db").duplicate_database(master_pwd, name, new_name) return http.local_redirect('/web/database/manager') except Exception, e: diff --git a/addons/web/i18n/web.pot b/addons/web/i18n/web.pot index 6f67a15c487..f4594f3abee 100644 --- a/addons/web/i18n/web.pot +++ b/addons/web/i18n/web.pot @@ -1148,6 +1148,13 @@ msgstr "" msgid "Invalid data" msgstr "" +#. module: web +#: code:addons/web/controllers/main.py:655 +#: code:addons/web/controllers/main.py:669 +#, python-format +msgid "Invalid database name. Only alphanumerical characters, underscore, hyphen and dot are allowed." +msgstr "" + #. module: web #. openerp-web #: code:addons/web/static/src/js/widgets/debug_manager.js:106 diff --git a/addons/web/views/database_manager.html b/addons/web/views/database_manager.html index 65c368ea39a..bd834b612f9 100644 --- a/addons/web/views/database_manager.html +++ b/addons/web/views/database_manager.html @@ -61,7 +61,7 @@
- +
@@ -207,7 +207,7 @@
- +
@@ -280,7 +280,7 @@
- +