Skip to content
Projects
Groups
Snippets
Help
Loading...
Help
Support
Keyboard shortcuts
?
Submit feedback
Contribute to GitLab
Sign in / Register
Toggle navigation
erp5
Project overview
Project overview
Details
Activity
Releases
Repository
Repository
Files
Commits
Branches
Tags
Contributors
Graph
Compare
Labels
Merge Requests
144
Merge Requests
144
CI / CD
CI / CD
Pipelines
Jobs
Schedules
Analytics
Analytics
CI / CD
Repository
Value Stream
Wiki
Wiki
Snippets
Snippets
Members
Members
Collapse sidebar
Close sidebar
Activity
Graph
Jobs
Commits
Open sidebar
nexedi
erp5
Commits
b9d3b61d
Commit
b9d3b61d
authored
Jan 27, 2020
by
Jérome Perrin
Browse files
Options
Browse Files
Download
Email Patches
Plain Diff
patches/Restricted: allow collections.namedtuple
parent
543f64f8
Pipeline
#8644
failed with stage
in 0 seconds
Changes
3
Pipelines
1
Hide whitespace changes
Inline
Side-by-side
Showing
3 changed files
with
90 additions
and
0 deletions
+90
-0
bt5/erp5_core_test/TestTemplateItem/portal_components/test.erp5.testRestrictedPythonSecurity.py
...rtal_components/test.erp5.testRestrictedPythonSecurity.py
+44
-0
product/ERP5Type/Collections.py
product/ERP5Type/Collections.py
+43
-0
product/ERP5Type/patches/Restricted.py
product/ERP5Type/patches/Restricted.py
+3
-0
No files found.
bt5/erp5_core_test/TestTemplateItem/portal_components/test.erp5.testRestrictedPythonSecurity.py
View file @
b9d3b61d
...
...
@@ -276,3 +276,47 @@ class TestRestrictedPythonSecurity(ERP5TypeTestCase):
expected
=
[(
'a'
,
3
)]
)
def
test_collections_defaultdict
(
self
):
self
.
createAndRunScript
(
textwrap
.
dedent
(
'''
\
from collections import defaultdict
d = defaultdict(list)
d["x"].append(1)
return d
'''
),
expected
=
{
"x"
:
[
1
]}
)
def
test_collections_namedtuple
(
self
):
self
.
createAndRunScript
(
textwrap
.
dedent
(
'''
\
from collections import namedtuple
Object = namedtuple("Object", ["a", "b", "c"])
return Object(a=1, b=2, c=3).a
'''
),
expected
=
1
)
# also make sure we can iterate on nametuples
self
.
createAndRunScript
(
textwrap
.
dedent
(
'''
\
from collections import namedtuple
Object = namedtuple("Object", ["a", "b", "c"])
returned = []
for x in Object(a=1, b=2, c=3):
returned.append(x)
return returned
'''
),
expected
=
[
1
,
2
,
3
]
)
def
test_collections_OrderedDict
(
self
):
self
.
createAndRunScript
(
textwrap
.
dedent
(
'''
\
from collections import OrderedDict
d = OrderedDict()
d["a"] = 1
d["b"] = 2
return list(d.items())
'''
),
expected
=
[(
"a"
,
1
),
(
"b"
,
2
)]
)
product/ERP5Type/Collections.py
0 → 100644
View file @
b9d3b61d
##############################################################################
#
# Copyright (c) 2020 Nexedi SA and Contributors. All Rights Reserved.
#
# WARNING: This program as such is intended to be used by professional
# programmers who take the whole responsability of assessing all potential
# consequences resulting from its eventual inadequacies and bugs
# End users who are looking for a ready-to-use solution with commercial
# garantees and support are strongly adviced to contract a Free Software
# Service Company
#
# This program is Free Software; you can redistribute it and/or
# modify it under the terms of the GNU General Public License
# as published by the Free Software Foundation; either version 2
# of the License, or (at your option) any later version.
#
# This program is distributed in the hope that it will be useful,
# but WITHOUT ANY WARRANTY; without even the implied warranty of
# MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the
# GNU General Public License for more details.
#
# You should have received a copy of the GNU General Public License
# along with this program; if not, write to the Free Software
# Foundation, Inc., 59 Temple Place - Suite 330, Boston, MA 02111-1307, USA.
#
##############################################################################
"""
Restricted collections module.
From restricted python, use "import collections" (see patches/Restricted.py).
"""
from
AccessControl
import
allow_class
as
_allow_class
import
collections
as
_collections
Counter
=
_collections
.
Counter
defaultdict
=
_collections
.
defaultdict
deque
=
_collections
.
deque
OrderedDict
=
_collections
.
OrderedDict
def
namedtuple
(
typename
,
field_names
,
verbose
=
False
,
rename
=
False
):
ret
=
_collections
.
namedtuple
(
typename
,
field_names
,
verbose
,
rename
)
ret
.
__allow_access_to_unprotected_subobjects__
=
1
return
ret
product/ERP5Type/patches/Restricted.py
View file @
b9d3b61d
...
...
@@ -211,6 +211,8 @@ ContainerAssertions[Counter] = _check_access_wrapper(Counter, _counter_white_lis
Counter
.
__guarded_setitem__
=
dict
.
__setitem__
Counter
.
__guarded_delitem__
=
dict
.
__delitem__
ModuleSecurityInfo
(
'collections'
).
declarePublic
(
'namedtuple'
)
# given as example in Products.PythonScripts.module_access_examples
allow_module
(
'base64'
)
allow_module
(
'binascii'
)
...
...
@@ -302,6 +304,7 @@ ModuleSecurityInfo('email.mime.text').declarePublic('MIMEText')
MNAME_MAP
=
{
'zipfile'
:
'Products.ERP5Type.ZipFile'
,
'calendar'
:
'Products.ERP5Type.Calendar'
,
'collections'
:
'Products.ERP5Type.Collections'
,
}
for
alias
,
real
in
MNAME_MAP
.
items
():
assert
'.'
not
in
alias
,
alias
# TODO: support this
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment