mirror of
https://github.com/fabro-sh/fabro.git
synced 2026-10-08 03:10:26 +00:00
parent
2e2625d66a
commit
14666944d8
5 changed files with 154 additions and 21 deletions
|
|
@ -1,13 +1,15 @@
|
|||
{
|
||||
"timestamp": "2026-03-16T05:33:45.145949Z",
|
||||
"current_node": "solve",
|
||||
"timestamp": "2026-03-16T05:33:47.387394Z",
|
||||
"current_node": "extract_patch",
|
||||
"completed_nodes": [
|
||||
"start",
|
||||
"setup",
|
||||
"solve"
|
||||
"solve",
|
||||
"extract_patch"
|
||||
],
|
||||
"node_retries": {
|
||||
"setup": 1,
|
||||
"extract_patch": 1,
|
||||
"solve": 1,
|
||||
"start": 1
|
||||
},
|
||||
|
|
@ -22,32 +24,22 @@
|
|||
"graph.rankdir": "LR",
|
||||
"graph.goal": "UsernameValidator allows trailing newline in usernames\nDescription\n\t\nASCIIUsernameValidator and UnicodeUsernameValidator use the regex \nr'^[\\w.@+-]+$'\nThe intent is to only allow alphanumeric characters as well as ., @, +, and -. However, a little known quirk of Python regexes is that $ will also match a trailing newline. Therefore, the user name validators will accept usernames which end with a newline. You can avoid this behavior by instead using \\A and \\Z to terminate regexes. For example, the validator regex could be changed to\nr'\\A[\\w.@+-]+\\Z'\nin order to reject usernames that end with a newline.\nI am not sure how to officially post a patch, but the required change is trivial - using the regex above in the two validators in contrib.auth.validators.\n",
|
||||
"internal.retry_count.solve": 1,
|
||||
"internal.thread_id": "setup",
|
||||
"internal.thread_id": "solve",
|
||||
"thread.solve.current_node": "extract_patch",
|
||||
"internal.retry_count.start": 1,
|
||||
"command.output": "fatal: destination path '.' already exists and is not an empty directory.\n",
|
||||
"current.preamble": "Goal: UsernameValidator allows trailing newline in usernames\nDescription\n\t\nASCIIUsernameValidator and UnicodeUsernameValidator use the regex \nr'^[\\w.@+-]+$'\nThe intent is to only allow alphanumeric characters as well as ., @, +, and -. However, a little known quirk of Python regexes is that $ will also match a trailing newline. Therefore, the user name validators will accept usernames which end with a newline. You can avoid this behavior by instead using \\A and \\Z to terminate regexes. For example, the validator regex could be changed to\nr'\\A[\\w.@+-]+\\Z'\nin order to reject usernames that end with a newline.\nI am not sure how to officially post a patch, but the required change is trivial - using the regex above in the two validators in contrib.auth.validators.\n\n\n## Completed stages\n- **setup**: fail\n - Script: `git clone https://github.com/django/django.git . && git checkout d26b2424437dabeeca94d7900b37d2df4410da0c && python -m pip install -e .`\n - Stdout:\n ```\n fatal: destination path '.' already exists and is not an empty directory.\n ```\n - Stderr: (empty)\n\n## Context\n- failure_class: deterministic\n- failure_signature: setup|deterministic|script failed with exit code: <n> ## stdout fatal: destination path '.' already exists and is not an empty directory.\n",
|
||||
"command.output": "",
|
||||
"current.preamble": "Goal: UsernameValidator allows trailing newline in usernames\nDescription\n\t\nASCIIUsernameValidator and UnicodeUsernameValidator use the regex \nr'^[\\w.@+-]+$'\nThe intent is to only allow alphanumeric characters as well as ., @, +, and -. However, a little known quirk of Python regexes is that $ will also match a trailing newline. Therefore, the user name validators will accept usernames which end with a newline. You can avoid this behavior by instead using \\A and \\Z to terminate regexes. For example, the validator regex could be changed to\nr'\\A[\\w.@+-]+\\Z'\nin order to reject usernames that end with a newline.\nI am not sure how to officially post a patch, but the required change is trivial - using the regex above in the two validators in contrib.auth.validators.\n\n\n## Completed stages\n- **setup**: fail\n - Script: `git clone https://github.com/django/django.git . && git checkout d26b2424437dabeeca94d7900b37d2df4410da0c && python -m pip install -e .`\n - Stdout:\n ```\n fatal: destination path '.' already exists and is not an empty directory.\n ```\n - Stderr: (empty)\n- **solve**: success\n - Model: claude-haiku-4-5, 15.5k tokens in / 5.7k out\n - Files: /home/daytona/workspace/SOLUTION.md, /tmp/django-repo/django/contrib/auth/validators.py, /tmp/test_regex.py, /tmp/test_validators.py\n",
|
||||
"thread.start.current_node": "setup",
|
||||
"failure_class": "",
|
||||
"internal.retry_count.setup": 1,
|
||||
"last_response": "## Summary\n\nI've successfully fixed the GitHub issue **\"UsernameValidator allows trailing newline in usernames\"** in Django.\n\n### The Problem\nThe username validators used regex patterns with `^` and `",
|
||||
"thread.setup.current_node": "solve",
|
||||
"internal.retry_count.extract_patch": 1,
|
||||
"last_stage": "solve",
|
||||
"current_node": "solve"
|
||||
"current_node": "extract_patch"
|
||||
},
|
||||
"logs": [],
|
||||
"node_outcomes": {
|
||||
"setup": {
|
||||
"status": "fail",
|
||||
"context_updates": {
|
||||
"command.output": "fatal: destination path '.' already exists and is not an empty directory.\n",
|
||||
"command.stderr": ""
|
||||
},
|
||||
"failure": {
|
||||
"message": "Script failed with exit code: 128\n\n## stdout\nfatal: destination path '.' already exists and is not an empty directory.\n",
|
||||
"failure_class": "deterministic"
|
||||
},
|
||||
"duration_ms": 48
|
||||
},
|
||||
"solve": {
|
||||
"status": "success",
|
||||
"context_updates": {
|
||||
|
|
@ -72,18 +64,40 @@
|
|||
],
|
||||
"duration_ms": 71292
|
||||
},
|
||||
"setup": {
|
||||
"status": "fail",
|
||||
"context_updates": {
|
||||
"command.output": "fatal: destination path '.' already exists and is not an empty directory.\n",
|
||||
"command.stderr": ""
|
||||
},
|
||||
"failure": {
|
||||
"message": "Script failed with exit code: 128\n\n## stdout\nfatal: destination path '.' already exists and is not an empty directory.\n",
|
||||
"failure_class": "deterministic"
|
||||
},
|
||||
"duration_ms": 48
|
||||
},
|
||||
"extract_patch": {
|
||||
"status": "success",
|
||||
"context_updates": {
|
||||
"command.output": "",
|
||||
"command.stderr": ""
|
||||
},
|
||||
"notes": "Script completed: git diff",
|
||||
"duration_ms": 54
|
||||
},
|
||||
"start": {
|
||||
"status": "success",
|
||||
"duration_ms": 0
|
||||
}
|
||||
},
|
||||
"next_node_id": "extract_patch",
|
||||
"next_node_id": "exit",
|
||||
"loop_failure_signatures": {
|
||||
"setup|deterministic|script failed with exit code: <n> ## stdout fatal: destination path '.' already exists and is not an empty directory.": 1
|
||||
},
|
||||
"node_visits": {
|
||||
"setup": 1,
|
||||
"solve": 1,
|
||||
"start": 1,
|
||||
"solve": 1
|
||||
"extract_patch": 1
|
||||
}
|
||||
}
|
||||
5
nodes/extract_patch/script_invocation.json
Normal file
5
nodes/extract_patch/script_invocation.json
Normal file
|
|
@ -0,0 +1,5 @@
|
|||
{
|
||||
"command": "git diff",
|
||||
"language": "shell",
|
||||
"timeout_ms": null
|
||||
}
|
||||
5
nodes/extract_patch/script_timing.json
Normal file
5
nodes/extract_patch/script_timing.json
Normal file
|
|
@ -0,0 +1,5 @@
|
|||
{
|
||||
"duration_ms": 52,
|
||||
"exit_code": 0,
|
||||
"timed_out": false
|
||||
}
|
||||
6
nodes/extract_patch/status.json
Normal file
6
nodes/extract_patch/status.json
Normal file
|
|
@ -0,0 +1,6 @@
|
|||
{
|
||||
"status": "success",
|
||||
"notes": "Script completed: git diff",
|
||||
"failure_reason": null,
|
||||
"timestamp": "2026-03-16T05:33:47.386118+00:00"
|
||||
}
|
||||
103
nodes/solve/diff.patch
Normal file
103
nodes/solve/diff.patch
Normal file
|
|
@ -0,0 +1,103 @@
|
|||
diff --git a/SOLUTION.md b/SOLUTION.md
|
||||
new file mode 100644
|
||||
index 0000000..9d5bb32
|
||||
--- /dev/null
|
||||
+++ b/SOLUTION.md
|
||||
@@ -0,0 +1,65 @@
|
||||
+# Fix: UsernameValidator allows trailing newline in usernames
|
||||
+
|
||||
+## Problem
|
||||
+The `ASCIIUsernameValidator` and `UnicodeUsernameValidator` classes in `django/contrib/auth/validators.py` used regex patterns with `^` and `$` anchors, which have a quirk in Python: `$` matches both the end of string AND before a trailing newline character.
|
||||
+
|
||||
+This caused the validators to incorrectly accept usernames ending with a newline (e.g., `"username\n"`).
|
||||
+
|
||||
+## Root Cause
|
||||
+The original regex patterns were:
|
||||
+```python
|
||||
+regex = r'^[\w.@+-]+$'
|
||||
+```
|
||||
+
|
||||
+The `$` anchor in Python regex matches:
|
||||
+1. The absolute end of string
|
||||
+2. **Also** before a trailing newline character (POSIX behavior)
|
||||
+
|
||||
+## Solution
|
||||
+Changed the regex patterns to use `\A` and `\Z` anchors instead:
|
||||
+```python
|
||||
+regex = r'\A[\w.@+-]+\Z'
|
||||
+```
|
||||
+
|
||||
+Where:
|
||||
+- `\A` - matches only the absolute start of string (not after newlines)
|
||||
+- `\Z` - matches only the absolute end of string (not before newlines)
|
||||
+
|
||||
+## Changes Made
|
||||
+Modified two validator classes in `django/contrib/auth/validators.py`:
|
||||
+
|
||||
+1. **ASCIIUsernameValidator** (line 10):
|
||||
+ - From: `regex = r'^[\w.@+-]+$'`
|
||||
+ - To: `regex = r'\A[\w.@+-]+\Z'`
|
||||
+
|
||||
+2. **UnicodeUsernameValidator** (line 20):
|
||||
+ - From: `regex = r'^[\w.@+-]+$'`
|
||||
+ - To: `regex = r'\A[\w.@+-]+\Z'`
|
||||
+
|
||||
+## Testing
|
||||
+Tested with both regexes to verify:
|
||||
+
|
||||
+### OLD regex behavior (`^[\w.@+-]+$`):
|
||||
+```
|
||||
+'validuser' -> MATCH ✓ (correct)
|
||||
+'user-name' -> MATCH ✓ (correct)
|
||||
+'validuser\n' -> MATCH ✗ (BUG - should not match)
|
||||
+'user-name\n' -> MATCH ✗ (BUG - should not match)
|
||||
+'user with space' -> NO MATCH ✓ (correct)
|
||||
+'user!invalid' -> NO MATCH ✓ (correct)
|
||||
+```
|
||||
+
|
||||
+### NEW regex behavior (`\A[\w.@+-]+\Z`):
|
||||
+```
|
||||
+'validuser' -> MATCH ✓ (correct)
|
||||
+'user-name' -> MATCH ✓ (correct)
|
||||
+'validuser\n' -> NO MATCH ✓ (FIXED)
|
||||
+'user-name\n' -> NO MATCH ✓ (FIXED)
|
||||
+'user with space' -> NO MATCH ✓ (correct)
|
||||
+'user!invalid' -> NO MATCH ✓ (correct)
|
||||
+```
|
||||
+
|
||||
+## Impact
|
||||
+- **Security**: Prevents acceptance of usernames with trailing newlines, which could bypass validation in some contexts
|
||||
+- **Correctness**: Makes the validators behave as intended, accepting only alphanumeric characters plus `.@+-_`
|
||||
+- **Compatibility**: No breaking changes - all previously valid usernames remain valid; only invalid usernames (with trailing newlines) are now properly rejected
|
||||
diff --git a/validators.py b/validators.py
|
||||
new file mode 100644
|
||||
index 0000000..74e31f5
|
||||
--- /dev/null
|
||||
+++ b/validators.py
|
||||
@@ -0,0 +1,25 @@
|
||||
+import re
|
||||
+
|
||||
+from django.core import validators
|
||||
+from django.utils.deconstruct import deconstructible
|
||||
+from django.utils.translation import gettext_lazy as _
|
||||
+
|
||||
+
|
||||
+@deconstructible
|
||||
+class ASCIIUsernameValidator(validators.RegexValidator):
|
||||
+ regex = r'\A[\w.@+-]+\Z'
|
||||
+ message = _(
|
||||
+ 'Enter a valid username. This value may contain only English letters, '
|
||||
+ 'numbers, and @/./+/-/_ characters.'
|
||||
+ )
|
||||
+ flags = re.ASCII
|
||||
+
|
||||
+
|
||||
+@deconstructible
|
||||
+class UnicodeUsernameValidator(validators.RegexValidator):
|
||||
+ regex = r'\A[\w.@+-]+\Z'
|
||||
+ message = _(
|
||||
+ 'Enter a valid username. This value may contain only letters, '
|
||||
+ 'numbers, and @/./+/-/_ characters.'
|
||||
+ )
|
||||
+ flags = 0
|
||||
\ No newline at end of file
|
||||
Loading…
Add table
Reference in a new issue