[FIX] website: accept 'all' google console search key
lstrip remove each letter, and not only once in this order.
So a google console key like googleeef88156 will be never trusted.
'googleeef88156'.lstrip('google') = 'f88156' and not 'eef88156'
Now we ensure that it starts with google or ends with .html and remove
exactly what we know.
To replace with removeprefix/removesuffix once we have py3.9 as minimal
version.
closes odoo/odoo#99776
X-original-commit: 44c08f18de9b2f25d1c716319ad287a409d2384d
Signed-off-by: Romain Derie (rde) <rde@odoo.com>
Signed-off-by: Jérémy Kersten <jke@odoo.com>
This commit is contained in:
@@ -651,8 +651,9 @@ class Website(Home):
|
||||
if not request.website.google_search_console:
|
||||
logger.warning('Google Search Console not enable')
|
||||
raise werkzeug.exceptions.NotFound()
|
||||
gsc = request.website.google_search_console
|
||||
trusted = gsc[gsc.startswith('google') and len('google'):gsc.endswith('.html') and -len('.html') or None]
|
||||
|
||||
trusted = request.website.google_search_console.lstrip('google').rstrip('.html')
|
||||
if key != trusted:
|
||||
if key.startswith(trusted):
|
||||
request.website.sudo().google_search_console = "google%s.html" % key
|
||||
|
||||
Reference in New Issue
Block a user