Statistics
| Branch: | Tag: | Revision:

root / snf-django-lib / snf_django / lib / api / urls.py @ aad21b81

History | View | Annotate | Download (2.6 kB)

1
# Copyright 2012, 2013 GRNET S.A. All rights reserved.
2
#
3
# Redistribution and use in source and binary forms, with or
4
# without modification, are permitted provided that the following
5
# conditions are met:
6
#
7
#   1. Redistributions of source code must retain the above
8
#      copyright notice, this list of conditions and the following
9
#      disclaimer.
10
#
11
#   2. Redistributions in binary form must reproduce the above
12
#      copyright notice, this list of conditions and the following
13
#      disclaimer in the documentation and/or other materials
14
#      provided with the distribution.
15
#
16
# THIS SOFTWARE IS PROVIDED BY GRNET S.A. ``AS IS'' AND ANY EXPRESS
17
# OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED
18
# WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR
19
# PURPOSE ARE DISCLAIMED. IN NO EVENT SHALL GRNET S.A OR
20
# CONTRIBUTORS BE LIABLE FOR ANY DIRECT, INDIRECT, INCIDENTAL,
21
# SPECIAL, EXEMPLARY, OR CONSEQUENTIAL DAMAGES (INCLUDING, BUT NOT
22
# LIMITED TO, PROCUREMENT OF SUBSTITUTE GOODS OR SERVICES; LOSS OF
23
# USE, DATA, OR PROFITS; OR BUSINESS INTERRUPTION) HOWEVER CAUSED
24
# AND ON ANY THEORY OF LIABILITY, WHETHER IN CONTRACT, STRICT
25
# LIABILITY, OR TORT (INCLUDING NEGLIGENCE OR OTHERWISE) ARISING IN
26
# ANY WAY OUT OF THE USE OF THIS SOFTWARE, EVEN IF ADVISED OF THE
27
# POSSIBILITY OF SUCH DAMAGE.
28
#
29
# The views and conclusions contained in the software and
30
# documentation are those of the authors and should not be
31
# interpreted as representing official policies, either expressed
32
# or implied, of GRNET S.A.
33

    
34
from django.core import urlresolvers
35
from django.views.decorators import csrf
36
from django.conf.urls import patterns
37

    
38

    
39
def _patch_pattern(regex_pattern):
40
    """
41
    Patch pattern callback using csrf_exempt. Enforce
42
    RegexURLPattern callback to get resolved if required.
43

44
    """
45
    regex_pattern._callback = \
46
        csrf.csrf_exempt(regex_pattern.callback)
47

    
48

    
49
def _patch_resolver(r):
50
    """
51
    Patch all patterns found in resolver with _patch_pattern
52
    """
53
    if hasattr(r, 'url_patterns'):
54
        entries = r.url_patterns
55
    else:
56
        # first level view in patterns ?
57
        entries = [r]
58

    
59
    for entry in entries:
60
        if isinstance(entry, urlresolvers.RegexURLResolver):
61
            _patch_resolver(entry)
62
        #if isinstance(entry, urlresolvers.RegexURLPattern):
63
        # let it break...
64
        else:
65
            _patch_pattern(entry)
66

    
67

    
68
def api_patterns(*args, **kwargs):
69
    """
70
    Protect all url patterns from csrf attacks.
71
    """
72
    _patterns = patterns(*args, **kwargs)
73
    for entry in _patterns:
74
        _patch_resolver(entry)
75
    return _patterns