-
-
Notifications
You must be signed in to change notification settings - Fork 3.7k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Middleware errors / responses during preview should be returned to the user #5427
Closed
Closed
Changes from all commits
Commits
Show all changes
4 commits
Select commit
Hold shift + click to select a range
a26abef
Add (failing) test for middleware responses during preview
gasman 97a746f
Introduce make_preview_request method to supersede dummy_request
gasman fd65094
Update dummy_request tests to use make_preview_request
gasman 92e5bf9
Deprecation note for dummy_request
gasman File filter
Filter by extension
Conversations
Failed to load comments.
Jump to
Jump to file
Failed to load files.
Diff view
Diff view
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,8 @@ | ||
from django.http import HttpResponseForbidden | ||
from django.utils.deprecation import MiddlewareMixin | ||
|
||
|
||
class BlockDodgyUserAgentMiddleware(MiddlewareMixin): | ||
def process_request(self, request): | ||
if not request.path.startswith('/admin/') and request.META.get('HTTP_USER_AGENT') == 'EvilHacker': | ||
return HttpResponseForbidden("Forbidden") |
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
I had to stare at this for a while to understand how this was working in the new test since that test is making a client request to a path that does start with
/admin/
. Eventually I figured out that what's being tested is the "path" of the page being previewed (in this case/hello-world/
).I'd be curious about real world use cases where Wagtail users might encounter non-200 responses from preview middleware. For example, say you had a middleware that redirects under certain conditions, say if a page has certain configuration settings. If you preview a page in that case, your "preview view" would end up redirecting. This makes logical sense but does feel a bit unexpected; as a Wagtail user I might expect some kind of interstitial page indicating that the preview had redirected.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
@chosak Yep, the
not request.path.startswith('/admin/')
needs to be there because the same HTTP headers are reused for the real request (to the admin view) and the faked request used to perform the preview, and we're testing the case where the latter triggers a middleware response. Can add a comment to clarify this if you think it'll help.As far as I can see, the most common reason for middleware to return a non-200 response (or indeed to return early with its own 200 response rather than proceeding to the next middleware / view) is if the user has failed an authentication check - in this case it'll probably be clear to the user what has happened. Either way, returning that response as-is will definitely be an improvement over the current behaviour (i.e. forging ahead and attempting to serve the preview using the possibly-incomplete request object).
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
That makes sense, thanks. A comment might help to indicate why that clause is necessary.