Address openid session crashes on invalid input - #592
Merged
Conversation
especially the input validation ones. Show a generic error page and only write log warnings rather than errors in that case. Check the openid library could in fact decode user query to a request before using the result in order to avoid some NoneType object attribute errors when it couldn't.
Removed unused parent openid module import and left it to the openid.x module imports to fail hard if missing.
…o avoid redundancy.
Contributor
Author
|
UPDATE: the above turned out to be my browser settings preventing full page load and now I can see that it's just one of the old lint errors covered in #338. |
jonasbardino
marked this pull request as ready for review
July 15, 2026 09:41
Martin-Rehr
reviewed
Jul 28, 2026
Martin-Rehr
reviewed
Jul 28, 2026
Martin-Rehr
reviewed
Jul 28, 2026
Martin-Rehr
reviewed
Jul 28, 2026
Martin-Rehr
reviewed
Jul 28, 2026
Martin-Rehr
reviewed
Jul 28, 2026
Martin-Rehr
reviewed
Jul 28, 2026
Martin-Rehr
approved these changes
Jul 28, 2026
Martin-Rehr
left a comment
Contributor
There was a problem hiding this comment.
Approved with a few comments
jonasbardino
added a commit
that referenced
this pull request
Jul 30, 2026
…rict and avoid greedy swallowing of ValueError triggered outside the actual validation. This is follow-up to #592 in relation to the post-merge discussion there. Add 'better safe than sorry' validation of all query components. Switch `invalid_argument` helper to reusing `InputException` to let exception handlers focus on that kind only. Avoid potential clashes with 2nd (key, val)-iterator in same scope.
jonasbardino
added a commit
that referenced
this pull request
Jul 30, 2026
…rict after PR592 (#634) * Rework the built-in openid 2.0 service input validation to be more strict and avoid greedy swallowing of ValueError triggered outside the actual validation. This is follow-up to #592 in relation to the post-merge discussion there. Add 'better safe than sorry' validation of all query components. Switch `invalid_argument` helper to reusing `InputException` to let exception handlers focus on that kind only. Avoid potential clashes with 2nd (key, val)-iterator in same scope.
jonasbardino
added a commit
that referenced
this pull request
Aug 18, 2026
…hitting openid message objects that it doesn't know what to do about. Force to string to make it succeed.
jonasbardino
added a commit
that referenced
this pull request
Aug 18, 2026
…hitting openid message objects that it doesn't know what to do about. Force to string to make it succeed.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Attempt to address #589 with more robust handling of various errors and especially the input validation ones. Show a generic error page and only write log warnings rather than errors in that case.
Check the openid library could in fact decode user query to a request before using the result in order to avoid some NoneType object attribute errors when it couldn't.
Some generic lint fixes and polish of error messages to properly show support email.