* make CSRF protection the default on all non-SAFE methods note: there currently is no way to call a CSRF-protected endpoint without a form-encoded entity-body as that's the only place we get the CSRF token from. * simple CSRF token generation: just use the HMAC'd session id, no generating a new random token per session then HMAC it * use constant-time equal function to avoid timing attacks * assert that a database secret is configured before hashing/validating the CSRF token * opt-out database manager from CSRF: The super-admin password serves the purpose of a CSRF token in the database manager screens. There is no request database to obtain the secret and generate a CSRF token.
19 lines
581 B
Python
19 lines
581 B
Python
# -*- coding: utf-8 -*-
|
|
import json
|
|
|
|
from openerp.http import Controller, route
|
|
|
|
class ImportController(Controller):
|
|
@route('/base_import/set_file', methods=['POST'])
|
|
def set_file(self, req, file, import_id, jsonp='callback'):
|
|
import_id = int(import_id)
|
|
|
|
written = req.session.model('base_import.import').write(import_id, {
|
|
'file': file.read(),
|
|
'file_name': file.filename,
|
|
'file_type': file.content_type,
|
|
}, req.context)
|
|
|
|
return 'window.top.%s(%s)' % (
|
|
jsonp, json.dumps({'result': written}))
|