English 中文(简体)
Django:当使用@login_required和设置LOGIN时信息泄漏问题
原标题:Django: information leakage problem when using @login_required and setting LOGIN_URL

我在使用“@login_required decorator”和确定LOGIN_URL变量时发现一种信息泄漏形式。

我有一个网站,要求所有内容都必须登录。 问题在于,你在挂上现有一页时,将下个变量重新定位到日志上。

因此,如果不gged,要求:

 http://localhost:8000/validurl/

阁下:

 http://localhost:8000/login/?next=/validurl/

在要求使用非现有网页时:

 http://localhost:8000/faultyurl/

阁下:

 http://localhost:8000/login/

这些信息揭示了我想要的一些信息。 我认为, overrid倒了原木方法,迫使下方 empty空,并 calling上这一分层方法。

另一个问题是,我的一些测试没有LOGIN-URL套。 转至账户/记录/记录/而不是/记录。 因此,我想利用LOGIN_URL,但去掉下一个汽车特征。

任何人都能够说明这个问题?

抽签。

Gerard。

最佳回答

您可将这一条列作您的<代码>urls.py文档中的最后一种格式。 它将重新计算与任何其它模式不匹配的圆顶。

urlpatterns = patterns(  ,

    ...

    (r ^(?P<path>.+)$ ,  django.views.generic.simple.redirect_to , {
         url :  /login/?next=/%(path)s , 
         permanent : False
    }),
)

EDIT: 不断提高404页,供认证用户使用:

from django.http import Http404, HttpResponseRedirect
def fake_redirect(request, path):
    if request.user.is_authenticated:
        raise Http404()
    else:
        return HttpResponseRedirect( /login/?next=/%s  % path)

urlpatterns = patterns(  ,

    ...

    (r ^(?P<path>.+)$ , fake_redirect),
)
问题回答

暂无回答




相关问题
Can Django models use MySQL functions?

Is there a way to force Django models to pass a field to a MySQL function every time the model data is read or loaded? To clarify what I mean in SQL, I want the Django model to produce something like ...

An enterprise scheduler for python (like quartz)

I am looking for an enterprise tasks scheduler for python, like quartz is for Java. Requirements: Persistent: if the process restarts or the machine restarts, then all the jobs must stay there and ...

How to remove unique, then duplicate dictionaries in a list?

Given the following list that contains some duplicate and some unique dictionaries, what is the best method to remove unique dictionaries first, then reduce the duplicate dictionaries to single ...

What is suggested seed value to use with random.seed()?

Simple enough question: I m using python random module to generate random integers. I want to know what is the suggested value to use with the random.seed() function? Currently I am letting this ...

How can I make the PyDev editor selectively ignore errors?

I m using PyDev under Eclipse to write some Jython code. I ve got numerous instances where I need to do something like this: import com.work.project.component.client.Interface.ISubInterface as ...

How do I profile `paster serve` s startup time?

Python s paster serve app.ini is taking longer than I would like to be ready for the first request. I know how to profile requests with middleware, but how do I profile the initialization time? I ...

Pragmatically adding give-aways/freebies to an online store

Our business currently has an online store and recently we ve been offering free specials to our customers. Right now, we simply display the special and give the buyer a notice stating we will add the ...

Converting Dictionary to List? [duplicate]

I m trying to convert a Python dictionary into a Python list, in order to perform some calculations. #My dictionary dict = {} dict[ Capital ]="London" dict[ Food ]="Fish&Chips" dict[ 2012 ]="...

热门标签