-
Notifications
You must be signed in to change notification settings - Fork 265
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Fix bug #1782, forbidden chars in ID PATCH v2 #1787
Changes from 1 commit
File filter
Filter by extension
Conversations
Jump to
Diff view
Diff view
There are no files selected for viewing
Original file line number | Diff line number | Diff line change |
---|---|---|
|
@@ -28,7 +28,7 @@ | |
#include "common/statistics.h" | ||
#include "common/clockFunctions.h" | ||
#include "common/errorMessages.h" | ||
|
||
#include "parse/forbiddenChars.h" | ||
#include "rest/ConnectionInfo.h" | ||
#include "ngsi/ParseData.h" | ||
#include "apiTypesV2/Entities.h" | ||
|
@@ -71,6 +71,12 @@ std::string patchEntity | |
eP->id = compV[2]; | ||
eP->type = ciP->uriParam["type"]; | ||
|
||
if (forbiddenIdChars(ciP->apiVersion, eP->id.c_str() , NULL)) | ||
{ | ||
OrionError oe(SccBadRequest, "invalid character in URI"); | ||
return oe.render(ciP, ""); | ||
} | ||
|
||
There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. This seems like something that should be done for all v2 requests (perhaps v1 also), There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. Ah, it's only about the ID, not the whole path ... NTC There was a problem hiding this comment. Choose a reason for hiding this commentThe reason will be displayed to describe this comment to others. Learn more. I'll check other 'paths' with ID for this point. If any is found, we can create an issue for all them and solve them in the same PR ... |
||
// 01. Fill in UpdateContextRequest | ||
parseDataP->upcr.res.fill(eP, "UPDATE"); | ||
|
||
|
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,60 @@ | ||
# Copyright 2016 Telefonica Investigacion y Desarrollo, S.A.U | ||
# | ||
# This file is part of Orion Context Broker. | ||
# | ||
# Orion Context Broker is free software: you can redistribute it and/or | ||
# modify it under the terms of the GNU Affero General Public License as | ||
# published by the Free Software Foundation, either version 3 of the | ||
# License, or (at your option) any later version. | ||
# | ||
# Orion Context Broker is distributed in the hope that it will be useful, | ||
# but WITHOUT ANY WARRANTY; without even the implied warranty of | ||
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the GNU Affero | ||
# General Public License for more details. | ||
# | ||
# You should have received a copy of the GNU Affero General Public License | ||
# along with Orion Context Broker. If not, see http://www.gnu.org/licenses/. | ||
# | ||
# For those usages not covered by this license please contact with | ||
# iot_support at tid dot es | ||
|
||
# VALGRIND_READY - to mark the test ready for valgrindTestSuite.sh | ||
|
||
--NAME-- | ||
PATCH /v2/entities/E& forbidden chars in ID | ||
|
||
--SHELL-INIT-- | ||
dbInit CB | ||
brokerStart CB | ||
|
||
--SHELL-- | ||
|
||
# | ||
# 01. PATCH entity with forbidden char in ID | ||
# | ||
|
||
echo "01. PATCH entity with forbidden char in ID" | ||
echo "==========================================" | ||
payload='{ "attr1": 1 }' | ||
orionCurl --url '/v2/entities/E&?options=keyValues' -X PATCH --payload "$payload" --json | ||
echo | ||
echo | ||
|
||
|
||
--REGEXPECT-- | ||
01. PATCH entity with forbidden char in ID | ||
========================================== | ||
HTTP/1.1 400 Bad Request | ||
Content-Length: 63 | ||
Content-Type: application/json | ||
Date: REGEX(.*) | ||
|
||
{ | ||
"description": "invalid character in URI", | ||
"error": "BadRequest" | ||
} | ||
|
||
|
||
--TEARDOWN-- | ||
brokerStop CB | ||
dbDrop CB |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
in ID -> in entityID ?
PATH -> PATCH ?
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Fixed 297de23