Statistics
| Branch: | Tag: | Revision:

root / snf-django-lib / snf_django / lib / api / urls.py @ 06014b1c

History | View | Annotate | Download (3 kB)

1
# Copyright 2012, 2013 GRNET S.A. All rights reserved.
2
#
3
# Redistribution and use in source and binary forms, with or
4
# without modification, are permitted provided that the following
5
# conditions are met:
6
#
7
#   1. Redistributions of source code must retain the above
8
#      copyright notice, this list of conditions and the following
9
#      disclaimer.
10
#
11
#   2. Redistributions in binary form must reproduce the above
12
#      copyright notice, this list of conditions and the following
13
#      disclaimer in the documentation and/or other materials
14
#      provided with the distribution.
15
#
16
# THIS SOFTWARE IS PROVIDED BY GRNET S.A. ``AS IS'' AND ANY EXPRESS
17
# OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
18
# WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
19
# PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL GRNET S.A OR
20
# CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
21
# SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
22
# LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
23
# USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
24
# AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
25
# LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN
26
# ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
27
# POSSIBILITY OF SUCH DAMAGE.
28
#
29
# The views and conclusions contained in the software and
30
# documentation are those of the authors and should not be
31
# interpreted as representing official policies, either expressed
32
# or implied, of GRNET S.A.
33

    
34
from django.core import urlresolvers
35
from django.views.decorators import csrf
36
from django.conf.urls.defaults import patterns
37

    
38

    
39
def _patch_pattern(regex_pattern):
40
    """
41
    Patch pattern callback using csrf_exempt. Enforce
42
    RegexURLPattern callback to get resolved if required.
43

44
    """
45
    if hasattr(regex_pattern, "_get_callback"):  # Django==1.2
46
        if not regex_pattern._callback:
47
            # enforce _callback resolving
48
            regex_pattern._get_callback()
49

    
50
        regex_pattern._callback = \
51
            csrf.csrf_exempt(regex_pattern._callback)
52
    else:
53
        regex_pattern._callback = \
54
            csrf.csrf_exempt(regex_pattern.callback)
55

    
56

    
57
def _patch_resolver(r):
58
    """
59
    Patch all patterns found in resolver with _patch_pattern
60
    """
61
    if hasattr(r, '_get_url_patterns'):  # Django ==1.2
62
        entries = r._get_url_patterns()
63
    elif hasattr(r, 'url_patterns'):
64
        entries = r.url_patterns
65
    else:
66
        # first level view in patterns ?
67
        entries = [r]
68

    
69
    for entry in entries:
70
        if isinstance(entry, urlresolvers.RegexURLResolver):
71
            _patch_resolver(entry)
72
        #if isinstance(entry, urlresolvers.RegexURLPattern):
73
        # let it break...
74
        else:
75
            _patch_pattern(entry)
76

    
77

    
78
def api_patterns(*args, **kwargs):
79
    """
80
    Protect all url patterns from csrf attacks.
81
    """
82
    _patterns = patterns(*args, **kwargs)
83
    for entry in _patterns:
84
        _patch_resolver(entry)
85
    return _patterns