forked from retoor/devplacepy
Compare commits
1
Commits
| Author | SHA1 | Date | |
|---|---|---|---|
|
|
a8ed5b690f |
@@ -44,7 +44,6 @@ from devplacepy.templating import templates, jinja_unread_count
|
|||||||
from devplacepy.cache import TTLCache
|
from devplacepy.cache import TTLCache
|
||||||
from devplacepy.responses import respond, wants_json, json_error
|
from devplacepy.responses import respond, wants_json, json_error
|
||||||
from devplacepy.schemas import LandingOut, ValidationErrorOut
|
from devplacepy.schemas import LandingOut, ValidationErrorOut
|
||||||
from devplacepy.attachments import get_attachments_batch
|
|
||||||
from fastapi.responses import JSONResponse
|
from fastapi.responses import JSONResponse
|
||||||
from devplacepy.utils import get_current_user, time_ago, safe_next, client_ip
|
from devplacepy.utils import get_current_user, time_ago, safe_next, client_ip
|
||||||
from devplacepy.seo import base_seo_context, site_url, website_schema
|
from devplacepy.seo import base_seo_context, site_url, website_schema
|
||||||
@@ -672,7 +671,6 @@ def _landing_recent_posts(blocked):
|
|||||||
authors = get_users_by_uids(author_uids)
|
authors = get_users_by_uids(author_uids)
|
||||||
comment_counts = get_comment_counts_by_post_uids(post_uids)
|
comment_counts = get_comment_counts_by_post_uids(post_uids)
|
||||||
upvotes, downvotes = get_vote_counts(post_uids)
|
upvotes, downvotes = get_vote_counts(post_uids)
|
||||||
attachments_map = get_attachments_batch("post", post_uids)
|
|
||||||
for p in raw_posts:
|
for p in raw_posts:
|
||||||
posts.append(
|
posts.append(
|
||||||
{
|
{
|
||||||
@@ -682,7 +680,6 @@ def _landing_recent_posts(blocked):
|
|||||||
"comment_count": comment_counts.get(p["uid"], 0),
|
"comment_count": comment_counts.get(p["uid"], 0),
|
||||||
"stars": upvotes.get(p["uid"], 0) - downvotes.get(p["uid"], 0),
|
"stars": upvotes.get(p["uid"], 0) - downvotes.get(p["uid"], 0),
|
||||||
"slug": p.get("slug", "") or p["uid"],
|
"slug": p.get("slug", "") or p["uid"],
|
||||||
"attachments": attachments_map.get(p["uid"], []),
|
|
||||||
}
|
}
|
||||||
)
|
)
|
||||||
if not blocked:
|
if not blocked:
|
||||||
|
|||||||
@@ -470,9 +470,19 @@ class SeoRunForm(BaseModel):
|
|||||||
text = value.strip()
|
text = value.strip()
|
||||||
if not text:
|
if not text:
|
||||||
raise ValueError("A URL is required")
|
raise ValueError("A URL is required")
|
||||||
|
if "://" in text:
|
||||||
|
scheme = text.split("://", 1)[0]
|
||||||
|
if scheme not in ("http", "https"):
|
||||||
|
raise ValueError(f"Only http and https URLs are allowed; got '{scheme}://'")
|
||||||
|
else:
|
||||||
|
text = f"https://{text}"
|
||||||
|
if not SEO_URL_PATTERN.match(text):
|
||||||
|
raise ValueError("URL must be a valid http or https source location")
|
||||||
return text
|
return text
|
||||||
|
|
||||||
|
|
||||||
|
SEO_URL_PATTERN = re.compile(r"^https?://[a-zA-Z0-9][\w./:@~^?&#%=;-]*$")
|
||||||
|
|
||||||
ISSLOP_URL_PATTERN = re.compile(r"^(https?://|git://|ssh://|git@)[\w./:@~^-]+$", re.IGNORECASE)
|
ISSLOP_URL_PATTERN = re.compile(r"^(https?://|git://|ssh://|git@)[\w./:@~^-]+$", re.IGNORECASE)
|
||||||
ISSLOP_SINGLE_SLASH_PATTERN = re.compile(r"^(https?|git|ssh):/(?!/)", re.IGNORECASE)
|
ISSLOP_SINGLE_SLASH_PATTERN = re.compile(r"^(https?|git|ssh):/(?!/)", re.IGNORECASE)
|
||||||
ISSLOP_SCHEME_PATTERN = re.compile(r"^[a-z][a-z0-9+.-]*://", re.IGNORECASE)
|
ISSLOP_SCHEME_PATTERN = re.compile(r"^[a-z][a-z0-9+.-]*://", re.IGNORECASE)
|
||||||
|
|||||||
@@ -7,6 +7,7 @@ from devplacepy.models import ProfileForm
|
|||||||
from fastapi.responses import HTMLResponse, JSONResponse
|
from fastapi.responses import HTMLResponse, JSONResponse
|
||||||
from devplacepy.database import (
|
from devplacepy.database import (
|
||||||
get_table,
|
get_table,
|
||||||
|
db,
|
||||||
get_customization_prefs,
|
get_customization_prefs,
|
||||||
get_notification_prefs,
|
get_notification_prefs,
|
||||||
get_user_stars,
|
get_user_stars,
|
||||||
@@ -47,7 +48,6 @@ from devplacepy.utils import (
|
|||||||
)
|
)
|
||||||
from devplacepy.responses import respond, action_result, wants_json
|
from devplacepy.responses import respond, action_result, wants_json
|
||||||
from devplacepy.schemas import ProfileOut
|
from devplacepy.schemas import ProfileOut
|
||||||
from devplacepy.attachments import get_attachments_batch
|
|
||||||
from devplacepy.avatar import avatar_url, avatar_seed
|
from devplacepy.avatar import avatar_url, avatar_seed
|
||||||
from devplacepy.seo import (
|
from devplacepy.seo import (
|
||||||
base_seo_context,
|
base_seo_context,
|
||||||
@@ -188,10 +188,8 @@ async def profile_page(
|
|||||||
else set()
|
else set()
|
||||||
)
|
)
|
||||||
polls_map = get_polls_by_post_uids(post_uids, current_user)
|
polls_map = get_polls_by_post_uids(post_uids, current_user)
|
||||||
attachments_map = get_attachments_batch("post", post_uids)
|
|
||||||
for item in posts:
|
for item in posts:
|
||||||
uid = item["post"]["uid"]
|
uid = item["post"]["uid"]
|
||||||
item["attachments"] = attachments_map.get(uid, [])
|
|
||||||
item["reactions"] = reactions_map.get(uid, {"counts": {}, "mine": []})
|
item["reactions"] = reactions_map.get(uid, {"counts": {}, "mine": []})
|
||||||
item["bookmarked"] = uid in bookmark_set
|
item["bookmarked"] = uid in bookmark_set
|
||||||
item["poll"] = polls_map.get(uid)
|
item["poll"] = polls_map.get(uid)
|
||||||
|
|||||||
@@ -5,7 +5,7 @@ from __future__ import annotations
|
|||||||
from typing import Any, Optional
|
from typing import Any, Optional
|
||||||
|
|
||||||
from devplacepy.schemas.base import _Out
|
from devplacepy.schemas.base import _Out
|
||||||
from devplacepy.schemas.content import AttachmentOut, UserOut
|
from devplacepy.schemas.content import UserOut
|
||||||
|
|
||||||
|
|
||||||
class AuthPageOut(_Out):
|
class AuthPageOut(_Out):
|
||||||
@@ -38,7 +38,6 @@ class LandingPostOut(_Out):
|
|||||||
comment_count: int = 0
|
comment_count: int = 0
|
||||||
stars: int = 0
|
stars: int = 0
|
||||||
slug: str = ""
|
slug: str = ""
|
||||||
attachments: list[AttachmentOut] = []
|
|
||||||
|
|
||||||
|
|
||||||
class TrendingTopicOut(_Out):
|
class TrendingTopicOut(_Out):
|
||||||
|
|||||||
@@ -89,6 +89,53 @@ def test_run_clamps_max_pages_above_cap(app_server):
|
|||||||
_clear_seo_jobs()
|
_clear_seo_jobs()
|
||||||
|
|
||||||
|
|
||||||
|
def test_run_rejects_malformed_scheme(app_server):
|
||||||
|
r = requests.post(
|
||||||
|
f"{BASE_URL}/tools/seo/run",
|
||||||
|
headers=_json_headers(),
|
||||||
|
data={"url": "ahttps://devplace.net/sitem", "mode": "url"},
|
||||||
|
allow_redirects=False,
|
||||||
|
)
|
||||||
|
assert r.status_code in (400, 422), r.text
|
||||||
|
|
||||||
|
|
||||||
|
def test_run_rejects_relative_path(app_server):
|
||||||
|
r = requests.post(
|
||||||
|
f"{BASE_URL}/tools/seo/run",
|
||||||
|
headers=_json_headers(),
|
||||||
|
data={"url": "/feed", "mode": "url"},
|
||||||
|
allow_redirects=False,
|
||||||
|
)
|
||||||
|
assert r.status_code in (400, 422), r.text
|
||||||
|
|
||||||
|
|
||||||
|
def test_run_normalizes_missing_scheme(app_server):
|
||||||
|
try:
|
||||||
|
r = requests.post(
|
||||||
|
f"{BASE_URL}/tools/seo/run",
|
||||||
|
headers=_json_headers(),
|
||||||
|
data={"url": "example.com", "mode": "url", "max_pages": "5"},
|
||||||
|
)
|
||||||
|
assert r.status_code == 200, r.text
|
||||||
|
uid = r.json()["uid"]
|
||||||
|
refresh_snapshot()
|
||||||
|
job = queue.get_job(uid)
|
||||||
|
assert job is not None
|
||||||
|
assert job["payload"]["url"] == "https://example.com"
|
||||||
|
finally:
|
||||||
|
_clear_seo_jobs()
|
||||||
|
|
||||||
|
|
||||||
|
def test_run_rejects_non_http_scheme(app_server):
|
||||||
|
r = requests.post(
|
||||||
|
f"{BASE_URL}/tools/seo/run",
|
||||||
|
headers=_json_headers(),
|
||||||
|
data={"url": "ftp://example.com", "mode": "url"},
|
||||||
|
allow_redirects=False,
|
||||||
|
)
|
||||||
|
assert r.status_code in (400, 422), r.text
|
||||||
|
|
||||||
|
|
||||||
def test_run_enforces_one_active_job_per_owner(app_server):
|
def test_run_enforces_one_active_job_per_owner(app_server):
|
||||||
try:
|
try:
|
||||||
first = requests.post(
|
first = requests.post(
|
||||||
|
|||||||
Reference in New Issue
Block a user