Skip to content

Reject a trailing newline in SlugField - #10075

Open
mohamed-alired wants to merge 1 commit into
encode:mainfrom
mohamed-alired:fix-slugfield-trailing-newline
Open

mohamed-alired wants to merge 1 commit into
encode:mainfrom
mohamed-alired:fix-slugfield-trailing-newline

Conversation

@mohamed-alired

Copy link
Copy Markdown
Contributor

Description

The ASCII SlugField regex ends in $, which in Python also matches just before a trailing newline, so with trim_whitespace=False the value 'slug\n' is accepted:

serializers.SlugField(trim_whitespace=False).run_validation('slug-99\n')
# 'slug-99\n'

The allow_unicode=True branch already uses \Z, as does Django's validate_slug. This change uses \Z for the ASCII regex too. The OpenAPI generator already translates \Z to \z for pattern, so schemas stay valid.

Tests: test_trailing_newline_is_invalid covers both branches. It fails on main and passes with this change.

The ASCII slug regex ended in `$`, which also matches just before a
trailing newline, so with trim_whitespace=False 'slug\n' was accepted.
Use `\Z`, as the allow_unicode branch and Django's validate_slug already
do.

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant