Skip to content
Projects
Groups
Snippets
Help
This project
Loading...
Sign in / Register
Toggle navigation
E
edx-platform
Overview
Overview
Details
Activity
Cycle Analytics
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Charts
Issues
0
Issues
0
List
Board
Labels
Milestones
Merge Requests
0
Merge Requests
0
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Charts
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Charts
Create a new issue
Jobs
Commits
Issue Boards
Open sidebar
edx
edx-platform
Commits
bd2330a8
Commit
bd2330a8
authored
Apr 10, 2013
by
Sef Kloninger
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
press releases: more explicitly match on slug (safety)
parent
bcdc6db4
Hide whitespace changes
Inline
Side-by-side
Showing
2 changed files
with
9 additions
and
1 deletions
+9
-1
lms/djangoapps/static_template_view/tests.py
+8
-0
lms/urls.py
+1
-1
No files found.
lms/djangoapps/static_template_view/tests.py
View file @
bd2330a8
...
...
@@ -51,3 +51,11 @@ class SimpleTest(TestCase):
response
=
self
.
client
.
get
(
"/press/this-shouldnt-work"
)
self
.
assertEqual
(
response
.
status_code
,
404
)
# can someone do something fishy? no.
response
=
self
.
client
.
get
(
"/press/../homework.html"
)
self
.
assertEqual
(
response
.
status_code
,
404
)
# "." in is ascii 2E
response
=
self
.
client
.
get
(
"/press/
%2
E
%2
E/homework.html"
)
self
.
assertEqual
(
response
.
status_code
,
404
)
lms/urls.py
View file @
bd2330a8
...
...
@@ -117,7 +117,7 @@ urlpatterns = ('',
{
'template'
:
'honor.html'
},
name
=
"honor"
),
#Press releases
url
(
r'^press/([
^/
]+)$'
,
'static_template_view.views.render_press_release'
,
name
=
'press_release'
),
url
(
r'^press/([
_a-zA-Z0-9-
]+)$'
,
'static_template_view.views.render_press_release'
,
name
=
'press_release'
),
# Favicon
(
r'^favicon\.ico$'
,
'django.views.generic.simple.redirect_to'
,
{
'url'
:
'/static/images/favicon.ico'
}),
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment