mirror of
https://github.com/pretix/pretix.git
synced 2026-09-30 19:04:43 +00:00
Prevent parsing non-standard-compliant JSON float values (Z#23245937 / PRT-021)
This commit is contained in:
committed by
Raphael Michel
parent
c65e8835f8
commit
463f0d6499
@@ -250,6 +250,13 @@ def monkeypatch_reportlab_imagereader():
|
||||
utils.ImageReader.__init__ = new_init
|
||||
|
||||
|
||||
def monkeypatch_json_constants():
|
||||
from json.decoder import _CONSTANTS # noqa
|
||||
del _CONSTANTS['-Infinity']
|
||||
del _CONSTANTS['Infinity']
|
||||
del _CONSTANTS['NaN']
|
||||
|
||||
|
||||
def monkeypatch_all_at_ready():
|
||||
monkeypatch_vobject_performance()
|
||||
monkeypatch_pillow_safer()
|
||||
@@ -257,3 +264,4 @@ def monkeypatch_all_at_ready():
|
||||
monkeypatch_urllib3_ssrf_protection()
|
||||
monkeypatch_cookie_morsel()
|
||||
monkeypatch_reportlab_imagereader()
|
||||
monkeypatch_json_constants()
|
||||
|
||||
@@ -0,0 +1,39 @@
|
||||
#
|
||||
# This file is part of pretix (Community Edition).
|
||||
#
|
||||
# Copyright (C) 2014-2020 Raphael Michel and contributors
|
||||
# Copyright (C) 2020-today pretix GmbH and contributors
|
||||
#
|
||||
# This program is free software: you can redistribute it and/or modify it under the terms of the GNU Affero General
|
||||
# Public License as published by the Free Software Foundation in version 3 of the License.
|
||||
#
|
||||
# ADDITIONAL TERMS APPLY: Pursuant to Section 7 of the GNU Affero General Public License, additional terms are
|
||||
# applicable granting you additional permissions and placing additional restrictions on your usage of this software.
|
||||
# Please refer to the pretix LICENSE file to obtain the full terms applicable to this work. If you did not receive
|
||||
# this file, see <https://pretix.eu/about/en/license>.
|
||||
#
|
||||
# This program is distributed in the hope that it will be useful, but WITHOUT ANY WARRANTY; without even the implied
|
||||
# warranty of MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Affero General Public License for more
|
||||
# details.
|
||||
#
|
||||
# You should have received a copy of the GNU Affero General Public License along with this program. If not, see
|
||||
# <https://www.gnu.org/licenses/>.
|
||||
#
|
||||
import json
|
||||
|
||||
import pytest
|
||||
|
||||
|
||||
def test_allowed_json():
|
||||
assert json.loads('{"float":1.5,"int":161,"arr":[]}') == {"float": 1.5, "int": 161, "arr": []}
|
||||
|
||||
|
||||
def test_disallowed_json_float_consts():
|
||||
with pytest.raises(KeyError):
|
||||
json.loads("Infinity")
|
||||
with pytest.raises(KeyError):
|
||||
json.loads("-Infinity")
|
||||
with pytest.raises(KeyError):
|
||||
json.loads("NaN")
|
||||
with pytest.raises(KeyError):
|
||||
json.loads("[123, NaN, Infinity, -Infinity]")
|
||||
Reference in New Issue
Block a user