mirror of
https://github.com/django/django.git
synced 2025-10-28 16:16:12 +00:00
Fixed #6209: handle BooleanFields in FormPreview and FormWizard. In the process, broke the the security hash calculation out to a helper function. Thanks to mcroydon and rajeshdhawan.
git-svn-id: http://code.djangoproject.com/svn/django/trunk@8597 bcc190cf-cafb-0310-a4f2-bffc1f526a37
This commit is contained in:
39
django/contrib/formtools/utils.py
Normal file
39
django/contrib/formtools/utils.py
Normal file
@@ -0,0 +1,39 @@
|
||||
try:
|
||||
import cPickle as pickle
|
||||
except ImportError:
|
||||
import pickle
|
||||
|
||||
from django.conf import settings
|
||||
from django.utils.hashcompat import md5_constructor
|
||||
from django.forms import BooleanField
|
||||
|
||||
def security_hash(request, form, *args):
|
||||
"""
|
||||
Calculates a security hash for the given Form instance.
|
||||
|
||||
This creates a list of the form field names/values in a deterministic
|
||||
order, pickles the result with the SECRET_KEY setting, then takes an md5
|
||||
hash of that.
|
||||
"""
|
||||
# Ensure that the hash does not change when a BooleanField's bound
|
||||
# data is a string `False' or a boolean False.
|
||||
# Rather than re-coding this special behaviour here, we
|
||||
# create a dummy BooleanField and call its clean method to get a
|
||||
# boolean True or False verdict that is consistent with
|
||||
# BooleanField.clean()
|
||||
dummy_bool = BooleanField(required=False)
|
||||
def _cleaned_data(bf):
|
||||
if isinstance(bf.field, BooleanField):
|
||||
return dummy_bool.clean(bf.data)
|
||||
return bf.data
|
||||
|
||||
data = [(bf.name, _cleaned_data(bf) or '') for bf in form]
|
||||
data.extend(args)
|
||||
data.append(settings.SECRET_KEY)
|
||||
|
||||
# Use HIGHEST_PROTOCOL because it's the most efficient. It requires
|
||||
# Python 2.3, but Django requires 2.3 anyway, so that's OK.
|
||||
pickled = pickle.dumps(data, pickle.HIGHEST_PROTOCOL)
|
||||
|
||||
return md5_constructor(pickled).hexdigest()
|
||||
|
||||
Reference in New Issue
Block a user