The version of werkzeug installed can vary from one deployment to another, as we recommend to use the operating system package, and the version can therefore change according to the operating system version. e.g. the werkzeug version installed using `apt install python3-werkzeug` varies between Ubuntu 18.04, 20.04, 22.04, 23.10, ... We want to keep under control the attributes developers use on werkzeug.wrappers.Request, to avoid compatibility issues from one version to another. Therefore, this revision aims to subclass werkzeug.wrappers.Request to limit the attributes which can be used. task-3734305 Part-of: odoo/odoo#78857 Signed-off-by: Julien Castiaux (juc) <juc@odoo.com>
18 lines
634 B
Python
18 lines
634 B
Python
import json
|
|
from .test_common import TestHttpBase
|
|
|
|
|
|
class TestHttpSecurity(TestHttpBase):
|
|
def test_httprequest_attrs(self):
|
|
res = self.db_url_open('/test_http/httprequest_attrs')
|
|
result = json.loads(res.content)
|
|
self.assertNotIn('user_agent_class', result)
|
|
self.assertNotIn('parameter_storage_class', result)
|
|
|
|
def test_httprequest_environ(self):
|
|
res = self.db_url_open('/test_http/httprequest_environ')
|
|
result = json.loads(res.content)
|
|
self.assertNotIn('wsgi.input', result)
|
|
self.assertNotIn('werkzeug.socket', result)
|
|
self.assertNotIn('socket', result)
|