fix: sanitize null bytes in nested db data

This commit is contained in:
IVVI0927 2026-05-22 00:04:10 -07:00
parent 359590ca9d
commit 6732ac33b7
2 changed files with 34 additions and 1 deletions

View file

@ -0,0 +1,33 @@
import sys
import types
# Stub lightweight dependencies that misc.py imports at module level so tests
# can run without a full application bootstrap.
_env = types.ModuleType('open_webui.env')
_env.CHAT_STREAM_RESPONSE_CHUNK_MAX_BUFFER_SIZE = 16384
sys.modules.setdefault('open_webui.env', _env)
sys.modules.setdefault('mimeparse', types.ModuleType('mimeparse'))
sys.modules.setdefault('aiohttp', types.ModuleType('aiohttp'))
from open_webui.utils.misc import sanitize_data_for_db # noqa: E402
class TestSanitizeDataForDb:
def test_string_null_bytes_removed(self):
assert sanitize_data_for_db('a\x00b') == 'ab'
def test_dict_value_null_bytes_removed(self):
result = sanitize_data_for_db({'key': 'val\x00ue'})
assert result == {'key': 'value'}
def test_nested_dict_value_null_bytes_removed(self):
result = sanitize_data_for_db({'a': {'b': 'c\x00'}})
assert result == {'a': {'b': 'c'}}
def test_list_value_null_bytes_removed(self):
result = sanitize_data_for_db(['a\x00', {'b': 'c\x00'}])
assert result == ['a', {'b': 'c'}]
def test_clean_data_returned_unchanged(self):
data = {'key': 'value', 'items': ['a', 'b'], 'num': 42}
assert sanitize_data_for_db(data) is data

View file

@ -653,7 +653,7 @@ def sanitize_data_for_db(obj):
# json.dumps is implemented in C and much faster than a Python-level
# recursive walk over every leaf string.
try:
if '\x00' not in json.dumps(obj, ensure_ascii=False):
if '\\u0000' not in json.dumps(obj):
return obj
except (TypeError, ValueError):
pass