mirror of
https://github.com/paperless-ngx/paperless-ngx.git
synced 2026-10-05 07:40:31 +00:00
Fix: reject non-dict user_args/barcode_tag_mapping in config API (#14118)
JSONField(binary=True) accepts any JSON value, so a truthy non-dict (bool/int/list/string) silently passed validation. Additionally, require string substitutes in barcode_tag_mapping, a non-string substitute value made the barcode tag substitution fail inside get_tag_ids, and the tag was silently skipped. barcode_tag_mapping values must now be strings (empty still means "use the raw barcode").
This commit is contained in:
@@ -235,6 +235,24 @@ class ApplicationConfigurationSerializer(
|
||||
) -> list[str]:
|
||||
return sorted(name for name in os.environ if name.startswith("PAPERLESS_"))
|
||||
|
||||
@staticmethod
|
||||
def _require_json_object(field: str, value: object) -> None:
|
||||
if value is not None and not isinstance(value, dict):
|
||||
raise serializers.ValidationError(f"{field} must be a JSON object.")
|
||||
|
||||
def validate_user_args(self, value):
|
||||
self._require_json_object("user_args", value)
|
||||
return value
|
||||
|
||||
def validate_barcode_tag_mapping(self, value):
|
||||
self._require_json_object("barcode_tag_mapping", value)
|
||||
# Each value is the regex substitute applied to a matching barcode
|
||||
if value is not None and not all(isinstance(v, str) for v in value.values()):
|
||||
raise serializers.ValidationError(
|
||||
"barcode_tag_mapping values must be strings.",
|
||||
)
|
||||
return value
|
||||
|
||||
def run_validation(self, data):
|
||||
# Empty strings treated as None to avoid unexpected behavior
|
||||
if "user_args" in data and data["user_args"] == "":
|
||||
|
||||
Reference in New Issue
Block a user