mirror of
https://github.com/django/django.git
synced 2025-10-26 15:16:09 +00:00
Fixed #21345: Don't evaluate callable settings in the debug page.
Thanks to crass for the report.
This commit is contained in:
@@ -46,6 +46,10 @@ def cleanse_setting(key, value):
|
||||
except TypeError:
|
||||
# If the key isn't regex-able, just return as-is.
|
||||
cleansed = value
|
||||
|
||||
if callable(cleansed):
|
||||
cleansed.do_not_call_in_templates = True
|
||||
|
||||
return cleansed
|
||||
|
||||
def get_safe_settings():
|
||||
|
||||
Reference in New Issue
Block a user