diff --git a/backend/open_webui/test/utils/test_misc.py b/backend/open_webui/test/utils/test_misc.py new file mode 100644 index 0000000000..9ce6289d06 --- /dev/null +++ b/backend/open_webui/test/utils/test_misc.py @@ -0,0 +1,33 @@ +import sys +import types + +# Stub lightweight dependencies that misc.py imports at module level so tests +# can run without a full application bootstrap. +_env = types.ModuleType('open_webui.env') +_env.CHAT_STREAM_RESPONSE_CHUNK_MAX_BUFFER_SIZE = 16384 +sys.modules.setdefault('open_webui.env', _env) +sys.modules.setdefault('mimeparse', types.ModuleType('mimeparse')) +sys.modules.setdefault('aiohttp', types.ModuleType('aiohttp')) + +from open_webui.utils.misc import sanitize_data_for_db # noqa: E402 + + +class TestSanitizeDataForDb: + def test_string_null_bytes_removed(self): + assert sanitize_data_for_db('a\x00b') == 'ab' + + def test_dict_value_null_bytes_removed(self): + result = sanitize_data_for_db({'key': 'val\x00ue'}) + assert result == {'key': 'value'} + + def test_nested_dict_value_null_bytes_removed(self): + result = sanitize_data_for_db({'a': {'b': 'c\x00'}}) + assert result == {'a': {'b': 'c'}} + + def test_list_value_null_bytes_removed(self): + result = sanitize_data_for_db(['a\x00', {'b': 'c\x00'}]) + assert result == ['a', {'b': 'c'}] + + def test_clean_data_returned_unchanged(self): + data = {'key': 'value', 'items': ['a', 'b'], 'num': 42} + assert sanitize_data_for_db(data) is data diff --git a/backend/open_webui/utils/misc.py b/backend/open_webui/utils/misc.py index 58a038791d..dbf1ef1a30 100644 --- a/backend/open_webui/utils/misc.py +++ b/backend/open_webui/utils/misc.py @@ -653,7 +653,7 @@ def sanitize_data_for_db(obj): # json.dumps is implemented in C and much faster than a Python-level # recursive walk over every leaf string. try: - if '\x00' not in json.dumps(obj, ensure_ascii=False): + if '\\u0000' not in json.dumps(obj): return obj except (TypeError, ValueError): pass