|
| 1 | +import json |
| 2 | + |
| 3 | +from django import forms |
| 4 | +from django.core import signing |
| 5 | +from django.core.exceptions import ValidationError |
| 6 | +from django.utils.encoding import force_str |
| 7 | + |
| 8 | + |
| 9 | +class SignedDataForm(forms.Form): |
| 10 | + """Helper form that wraps a form to validate its contents on post. |
| 11 | +
|
| 12 | + class PanelForm(forms.Form): |
| 13 | + # fields |
| 14 | +
|
| 15 | + On render: |
| 16 | + form = SignedDataForm(initial=PanelForm(initial=data).initial) |
| 17 | +
|
| 18 | + On POST: |
| 19 | + signed_form = SignedDataForm(request.POST) |
| 20 | + if signed_form.is_valid(): |
| 21 | + panel_form = PanelForm(signed_form.verified_data) |
| 22 | + if panel_form.is_valid(): |
| 23 | + # Success |
| 24 | + Or wrap the FBV with ``debug_toolbar.decorators.signed_data_view`` |
| 25 | + """ |
| 26 | + |
| 27 | + salt = "django_debug_toolbar" |
| 28 | + signed = forms.CharField(required=True, widget=forms.HiddenInput) |
| 29 | + |
| 30 | + def __init__(self, *args, **kwargs): |
| 31 | + initial = kwargs.pop("initial", None) |
| 32 | + if initial: |
| 33 | + initial = {"signed": self.sign(initial)} |
| 34 | + super().__init__(*args, initial=initial, **kwargs) |
| 35 | + |
| 36 | + def clean_signed(self): |
| 37 | + try: |
| 38 | + verified = json.loads( |
| 39 | + signing.Signer(salt=self.salt).unsign(self.cleaned_data["signed"]) |
| 40 | + ) |
| 41 | + return verified |
| 42 | + except signing.BadSignature: |
| 43 | + raise ValidationError("Bad signature") |
| 44 | + |
| 45 | + def verified_data(self): |
| 46 | + return self.is_valid() and self.cleaned_data["signed"] |
| 47 | + |
| 48 | + @classmethod |
| 49 | + def sign(cls, data): |
| 50 | + items = sorted(data.items(), key=lambda item: item[0]) |
| 51 | + return signing.Signer(salt=cls.salt).sign( |
| 52 | + json.dumps({key: force_str(value) for key, value in items}) |
| 53 | + ) |
0 commit comments