[FIX] base: ir.binary - return valid filename in Stream

Before this commit, if you have some special char like a return line \n,
or \r the get_stream_from method will crash with exception:

```
File "/home/odoo/src/odoo/odoo/addons/web/controllers/binary.py", line 163, in content_image
  return stream.get_response(**send_file_kwargs)
File "/home/odoo/src/odoo/odoo/odoo/http.py", line 578, in get_response
  res = _send_file(self.path, **send_file_kwargs)
File "/home/odoo/src/odoo/odoo/odoo/tools/_vendor/send_file.py", line 156, in send_file
  headers.set("Content-Disposition", value, **names)
File "/usr/local/lib/python3.9/dist-packages/werkzeug/datastructures.py", line 1218, in set
  self._validate_value(_value)
File "/usr/local/lib/python3.9/dist-packages/werkzeug/datastructures.py", line 1182, in _validate_value
  raise ValueError(

ValueError: Detected newline in header value.  This is a potential security problem
```

Now we replace `\n` `\r` by `_` before to serve the stream to avoid this
security exception from a safe way.
We decided to not use secure_filename from werzkeug because we want to
continue the support of non ascii char.

closes odoo/odoo#111851

X-original-commit: 95584e71a898017a92112f89e8a94315dd9235ac
Signed-off-by: Jérémy Kersten <jke@odoo.com>
This commit is contained in:
Jeremy Kersten
2023-02-03 16:32:24 +01:00
parent 277ff4f469
commit fb8765b494
2 changed files with 42 additions and 0 deletions
+41
View File
@@ -91,3 +91,44 @@ class TestImage(HttpCase):
res = self.url_open('/web/image/%s/0x0/custom.png?download=true' % att.id)
res.raise_for_status()
self.assertEqual(res.headers['Content-Disposition'], 'attachment; filename=custom.png')
def test_04_web_content_filename_secure(self):
"""This test makes sure the Content-Disposition header matches the given filename"""
att = self.env['ir.attachment'].create({
'datas': b'R0lGODdhAQABAIAAAP///////ywAAAAAAQABAAACAkQBADs=',
'name': """fô☺o-l'éb \n a"!r".gif""",
'public': True,
'mimetype': 'image/gif'
})
res = self.url_open(f'/web/image/{att.id}')
self.assertEqual(res.headers['Content-Disposition'], 'inline; filename="foo-l\'eb _ a\\"!r\\".gif"; filename*=UTF-8\'\'f%C3%B4%E2%98%BAo-l%27%C3%A9b%20_%20a%22%21r%22.gif')
res.raise_for_status()
res = self.url_open(f'/web/image/{att.id}/custom_invalid_name\nis-ok.gif')
self.assertEqual(res.headers['Content-Disposition'], 'inline; filename=custom_invalid_name_is-ok.gif')
res.raise_for_status()
res = self.url_open(f'/web/image/{att.id}/\r\n')
self.assertEqual(res.headers['Content-Disposition'], 'inline; filename=__.gif')
res.raise_for_status()
res = self.url_open(f'/web/image/{att.id}/你好')
self.assertEqual(res.headers['Content-Disposition'], 'inline; filename=.gif; filename*=UTF-8\'\'%E4%BD%A0%E5%A5%BD.gif')
res.raise_for_status()
res = self.url_open(f'/web/image/{att.id}/%E9%9D%A2%E5%9B%BE.gif')
self.assertEqual(res.headers['Content-Disposition'], 'inline; filename=.gif; filename*=UTF-8\'\'%E9%9D%A2%E5%9B%BE.gif')
res.raise_for_status()
res = self.url_open(f'/web/image/{att.id}/hindi_नमस्ते.gif')
self.assertEqual(res.headers['Content-Disposition'], 'inline; filename=hindi_.gif; filename*=UTF-8\'\'hindi_%E0%A4%A8%E0%A4%AE%E0%A4%B8%E0%A5%8D%E0%A4%A4%E0%A5%87.gif')
res.raise_for_status()
res = self.url_open(f'/web/image/{att.id}/arabic_مرحبا.gif')
self.assertEqual(res.headers['Content-Disposition'], 'inline; filename=arabic_.gif; filename*=UTF-8\'\'arabic_%D9%85%D8%B1%D8%AD%D8%A8%D8%A7.gif')
res.raise_for_status()
res = self.url_open(f'/web/image/{att.id}/4wzb_!!63148-0-t1.jpg_360x1Q75.jpg_.webp')
self.assertEqual(res.headers['Content-Disposition'], 'inline; filename=4wzb_!!63148-0-t1.jpg_360x1Q75.jpg_.webp')
res.raise_for_status()
+1
View File
@@ -139,6 +139,7 @@ class IrBinary(models.AbstractModel):
if not stream.download_name:
stream.download_name = f'{record._table}-{record.id}-{field_name}'
stream.download_name = stream.download_name.replace('\n', '_').replace('\r', '_')
if (not get_extension(stream.download_name)
and stream.mimetype != 'application/octet-stream'):
stream.download_name += guess_extension(stream.mimetype) or ''