details: https://code.tryton.org/tryton/commit/c7e33ba0f7c2
branch: default
user: Cédric Krier <[email protected]>
date: Wed Sep 02 12:18:08 2026 +0200
description:
Check if the user argument is a string on login and reset password
Those entrypoints do not require authentication so we must enforce
explicitly
the type of argument.
Closes #15048
diffstat:
trytond/trytond/protocols/dispatcher.py | 4 ++++
1 files changed, 4 insertions(+), 0 deletions(-)
diffs (21 lines):
diff -r 8633e8e87ea5 -r c7e33ba0f7c2 trytond/trytond/protocols/dispatcher.py
--- a/trytond/trytond/protocols/dispatcher.py Mon Aug 31 18:36:13 2026 +0200
+++ b/trytond/trytond/protocols/dispatcher.py Wed Sep 02 12:18:08 2026 +0200
@@ -46,6 +46,8 @@
'language': language,
'_request': request.context,
}
+ if not isinstance(user, str):
+ abort(HTTPStatus.BAD_REQUEST, "user argument must be a string")
try:
session = security.login(
database_name, user, parameters, context=context)
@@ -103,6 +105,8 @@
'language': language,
'_request': request.context,
}
+ if not isinstance(user, str):
+ abort(HTTPStatus.BAD_REQUEST, "user argument must be a string")
try:
security.reset_password(database_name, user, context=context)
except backend.DatabaseOperationalError: