From 190e07ef90741fe9f8df10426cf5ad2534465104 Mon Sep 17 00:00:00 2001 From: j Date: Mon, 9 Jul 2018 17:21:28 +0200 Subject: [PATCH] ignore plugins with \x00 in name --- pandora/user/migrations/0004_jsonfield.py | 15 +++++++++++++++ pandora/user/models.py | 5 +++++ 2 files changed, 20 insertions(+) diff --git a/pandora/user/migrations/0004_jsonfield.py b/pandora/user/migrations/0004_jsonfield.py index 90a5548a..99493930 100644 --- a/pandora/user/migrations/0004_jsonfield.py +++ b/pandora/user/migrations/0004_jsonfield.py @@ -6,6 +6,20 @@ import django.contrib.postgres.fields.jsonb from django.db import migrations, models +def cleanup_sessiondata(apps, schema_editor): + SessionData = apps.get_model("user", "SessionData") + for data in SessionData.objects.all(): + changed = False + plugins = [] + for p in data.info.get('navigator', {}).get('plugins', []): + if p and '\x00' not in p: + plugins.append(p) + else: + changed = True + if changed: + data.info['navigator']['plugins'] = plugins + data.save() + class Migration(migrations.Migration): dependencies = [ @@ -13,6 +27,7 @@ class Migration(migrations.Migration): ] operations = [ + migrations.RunPython(cleanup_sessiondata), migrations.RunSQL( 'ALTER TABLE "user_sessiondata" ALTER COLUMN "info" TYPE jsonb USING "info"::text::jsonb' ), diff --git a/pandora/user/models.py b/pandora/user/models.py index 7994651c..44cd0fde 100644 --- a/pandora/user/models.py +++ b/pandora/user/models.py @@ -111,6 +111,11 @@ class SessionData(models.Model): info = json.loads(request.POST.get('data', '{}')) if info and isinstance(info, dict): data.info = info + if data.info.get('navigator', {}).get('plugins'): + data.info['navigator']['plugins'] = [ + p for p in data.info['navigator']['plugins'] + if p and '\x00' not in p + ] screen = data.info.get('screen', {}) if screen and 'height' in screen and 'width' in screen: data.screensize = u'%s\xd7%s' % (screen['width'], screen['height'])