Files
odoo_source/addons/base_import/controllers.py
T
Christophe Simonis 7636b510a2 [ADD] *: CSRF protection in forms and routes
* make CSRF protection the default on all non-SAFE methods
  note: there currently is no way to call a CSRF-protected endpoint
  without a form-encoded entity-body as that's the only place we get the
  CSRF token from.
* simple CSRF token generation: just use the HMAC'd session id, no
  generating a new random token per session then HMAC it
* use constant-time equal function to avoid timing attacks
* assert that a database secret is configured before hashing/validating
  the CSRF token
* opt-out database manager from CSRF: The super-admin password serves
  the purpose of a CSRF token in the database manager screens.
  There is no request database to obtain the
  secret and generate a CSRF token.
2015-10-01 01:36:50 +02:00

19 lines
581 B
Python

# -*- coding: utf-8 -*-
import json
from openerp.http import Controller, route
class ImportController(Controller):
@route('/base_import/set_file', methods=['POST'])
def set_file(self, req, file, import_id, jsonp='callback'):
import_id = int(import_id)
written = req.session.model('base_import.import').write(import_id, {
'file': file.read(),
'file_name': file.filename,
'file_type': file.content_type,
}, req.context)
return 'window.top.%s(%s)' % (
jsonp, json.dumps({'result': written}))