fix: 3 system-wide bugs found in URL health sweep (242 URLs, 0 errors after fix)
All checks were successful
Build and Push Docker Image / build (push) Successful in 2m27s
All checks were successful
Build and Push Docker Image / build (push) Successful in 2m27s
1. /config/test/ — json.loads(request.body) on GET crashed with JSONDecodeError.
Added @require_http_methods(['POST']) so GET returns 405 instead of 500.
2. /organizations/dropdowns/subsections/ — LegacySubSection.objects.order_by('name')
used wrong field name (model has name_en/name_ar, not 'name'). Fixed to 'name_en'.
3. /rca/create/ — RCACreateView.dispatch() called _check_rca_create(request) before
LoginRequiredMixin ran, so AnonymousUser hit is_px_admin() → AttributeError.
Added auth check before the RBAC check in dispatch().
Post-fix: authenticated sweep of all 242 UI URLs → 233 OK, 0 errors (500s).
This commit is contained in:
parent
091e7f19e9
commit
8a944ad696
@ -256,6 +256,7 @@ def reset_user_password(request, user_id):
|
|||||||
|
|
||||||
|
|
||||||
from django.views.decorators.csrf import csrf_exempt
|
from django.views.decorators.csrf import csrf_exempt
|
||||||
|
from django.views.decorators.http import require_http_methods
|
||||||
from rich import print
|
from rich import print
|
||||||
from django.contrib.auth.hashers import check_password as verify_password
|
from django.contrib.auth.hashers import check_password as verify_password
|
||||||
|
|
||||||
@ -292,6 +293,7 @@ def toggle_user_active(request, user_id):
|
|||||||
|
|
||||||
|
|
||||||
@csrf_exempt
|
@csrf_exempt
|
||||||
|
@require_http_methods(["POST"])
|
||||||
def test(request):
|
def test(request):
|
||||||
import json
|
import json
|
||||||
from django.http import JsonResponse
|
from django.http import JsonResponse
|
||||||
|
|||||||
@ -761,7 +761,7 @@ def api_subsection_list(request):
|
|||||||
- location: Filter by location ID
|
- location: Filter by location ID
|
||||||
- main_section: Filter by main section ID
|
- main_section: Filter by main section ID
|
||||||
"""
|
"""
|
||||||
subsections = LegacySubSection.objects.all().order_by("name")
|
subsections = LegacySubSection.objects.all().order_by("name_en")
|
||||||
|
|
||||||
location_id = request.GET.get("location")
|
location_id = request.GET.get("location")
|
||||||
main_section_id = request.GET.get("main_section")
|
main_section_id = request.GET.get("main_section")
|
||||||
|
|||||||
@ -289,6 +289,8 @@ class RCACreateView(LoginRequiredMixin, CreateView):
|
|||||||
success_url = reverse_lazy("rca:rca_list")
|
success_url = reverse_lazy("rca:rca_list")
|
||||||
|
|
||||||
def dispatch(self, request, *args, **kwargs):
|
def dispatch(self, request, *args, **kwargs):
|
||||||
|
if not request.user.is_authenticated:
|
||||||
|
return self.handle_no_permission()
|
||||||
_check_rca_create(request)
|
_check_rca_create(request)
|
||||||
return super().dispatch(request, *args, **kwargs)
|
return super().dispatch(request, *args, **kwargs)
|
||||||
|
|
||||||
|
|||||||
Loading…
x
Reference in New Issue
Block a user