mirror of
https://github.com/blakeblackshear/frigate.git
synced 2026-10-11 09:12:48 +03:00
Reject dot-only usernames (#24611)
* reject usernames made only of dots
A username of "." or ".." passed validation, but browsers resolve those as path segments, so requests to /users/{username} never reached the API and the user could not be deleted or edited from the UI. User creation now rejects dot-only names in both the API and the create user dialog.
* show a specific error for dot-only usernames
Entering "." or ".." in the create user dialog showed the message listing periods as allowed characters, which didn't explain the rejection. The dialog now checks for dot-only names separately and shows its own message.
This commit is contained in:
@@ -0,0 +1,33 @@
|
||||
"""Tests for user creation."""
|
||||
|
||||
from unittest.mock import MagicMock
|
||||
|
||||
from frigate.models import User
|
||||
from frigate.test.http_api.base_http_test import AuthTestClient, BaseTestHttp
|
||||
|
||||
PASSWORD = "a-valid-password-123"
|
||||
|
||||
|
||||
class TestCreateUser(BaseTestHttp):
|
||||
def setUp(self):
|
||||
super().setUp([User])
|
||||
self.app = super().create_app()
|
||||
self.app.config_publisher = MagicMock()
|
||||
|
||||
def _create(self, username: str):
|
||||
with AuthTestClient(self.app) as client:
|
||||
return client.post(
|
||||
"/users",
|
||||
json={"username": username, "password": PASSWORD, "role": "viewer"},
|
||||
)
|
||||
|
||||
def test_rejects_dot_only_usernames(self):
|
||||
# browsers resolve these as URL path segments, so the per-user
|
||||
# endpoints can never be reached for them
|
||||
for username in (".", "..", "..."):
|
||||
assert self._create(username).status_code == 400
|
||||
assert User.get_or_none(User.username == username) is None
|
||||
|
||||
def test_accepts_username_containing_dots(self):
|
||||
assert self._create("john.doe_1").status_code == 200
|
||||
assert User.get_or_none(User.username == "john.doe_1") is not None
|
||||
Reference in New Issue
Block a user