cf805f530f
Make sure that fields specified in filter, sortBy, etc. are model fields and may be accessed. This is fixes a potential security issue. The filter() function allowed guessing the content of password hashes one character at a time. The sort() function allowed the user to call an arbitrary method of an arbitrary model attribute, for example sortBy=id&sortDir=distinct would produce an unexpected error. |
||
---|---|---|
.. | ||
__init__.py | ||
models.py | ||
schemas.py | ||
service.py | ||
views.py |