[FIX] website: accept 'all' google console search key

lstrip remove each letter, and not only once in this order.
So a google console key like googleeef88156 will be never trusted.
'googleeef88156'.lstrip('google') = 'f88156' and not 'eef88156'

Now we ensure that it starts with google or ends with .html and remove
exactly what we know.

To replace with removeprefix/removesuffix once we have py3.9 as minimal
version.

closes odoo/odoo#99776

X-original-commit: 44c08f18de9b2f25d1c716319ad287a409d2384d
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
Signed-off-by: Jérémy Kersten <jke@odoo.com>
This commit is contained in:
Jeremy Kersten
2022-09-08 10:42:49 +02:00
parent 980a9f0cd6
commit a60532fcff
+2 -1
View File
@@ -651,8 +651,9 @@ class Website(Home):
if not request.website.google_search_console:
logger.warning('Google Search Console not enable')
raise werkzeug.exceptions.NotFound()
gsc = request.website.google_search_console
trusted = gsc[gsc.startswith('google') and len('google'):gsc.endswith('.html') and -len('.html') or None]
trusted = request.website.google_search_console.lstrip('google').rstrip('.html')
if key != trusted:
if key.startswith(trusted):
request.website.sudo().google_search_console = "google%s.html" % key