- Add _validate_json_path(): each __-separated path segment must match [A-Za-z0-9_][A-Za-z0-9_-]* (allows leading underscores per Jeremy's suggestion; ORM operator names like 'date'/'regex' are valid JSON keys and are not blocked — the trailing __ JSONFilter appends makes them key traversal steps, not ORM transforms) - Add JSONStringLookup: explicit string-filter type for JSONLookup. regex/i_regex are included (they offer no additional oracle power beyond starts_with, which is also present, per Jeremy's observation) - JSONFilter.filter() validates self.path and returns empty Q() on invalid input rather than passing untrusted user input to the ORM - 19 unit tests for path validation and JSONStringLookup field presence Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com> |
||
|---|---|---|
| .. | ||
| account | ||
| circuits | ||
| core | ||
| dcim | ||
| extras | ||
| ipam | ||
| media | ||
| netbox | ||
| project-static | ||
| reports | ||
| scripts | ||
| templates | ||
| tenancy | ||
| translations | ||
| users | ||
| utilities | ||
| virtualization | ||
| vpn | ||
| wireless | ||
| generate_secret_key.py | ||
| manage.py | ||
| release.yaml | ||