From a60532fcffee80512db4cb5590e33d2bad062c8d Mon Sep 17 00:00:00 2001 From: Jeremy Kersten Date: Mon, 5 Sep 2022 14:07:36 +0000 Subject: [PATCH] [FIX] website: accept 'all' google console search key MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit lstrip remove each letter, and not only once in this order. So a google console key like googleeef88156 will be never trusted. 'googleeef88156'.lstrip('google') = 'f88156' and not 'eef88156' Now we ensure that it starts with google or ends with .html and remove exactly what we know. To replace with removeprefix/removesuffix once we have py3.9 as minimal version. closes odoo/odoo#99776 X-original-commit: 44c08f18de9b2f25d1c716319ad287a409d2384d Signed-off-by: Romain Derie (rde) Signed-off-by: Jérémy Kersten --- addons/website/controllers/main.py | 3 ++- 1 file changed, 2 insertions(+), 1 deletion(-) diff --git a/addons/website/controllers/main.py b/addons/website/controllers/main.py index 911d4b95a0d..9130fbddcd8 100644 --- a/addons/website/controllers/main.py +++ b/addons/website/controllers/main.py @@ -651,8 +651,9 @@ class Website(Home): if not request.website.google_search_console: logger.warning('Google Search Console not enable') raise werkzeug.exceptions.NotFound() + gsc = request.website.google_search_console + trusted = gsc[gsc.startswith('google') and len('google'):gsc.endswith('.html') and -len('.html') or None] - trusted = request.website.google_search_console.lstrip('google').rstrip('.html') if key != trusted: if key.startswith(trusted): request.website.sudo().google_search_console = "google%s.html" % key