Coverage for utilities/constants.py: 100%
15 statements
« prev ^ index » next coverage.py v7.15.2, created at 2026-10-10 18:35 +0000
« prev ^ index » next coverage.py v7.15.2, created at 2026-10-10 18:35 +0000
1#
2# Filter lookup expressions
3#
5FILTER_CHAR_BASED_LOOKUP_MAP = dict(
6 n='exact',
7 ic='icontains',
8 nic='icontains',
9 iew='iendswith',
10 niew='iendswith',
11 isw='istartswith',
12 nisw='istartswith',
13 ie='iexact',
14 nie='iexact',
15 empty='empty',
16 regex='regex',
17 iregex='iregex',
18)
20# A member is a scalar inside a stored array, so negation cannot fall back to equality
21FILTER_ARRAY_BASED_LOOKUP_MAP = {
22 **FILTER_CHAR_BASED_LOOKUP_MAP,
23 'n': 'contains',
24}
26FILTER_NUMERIC_BASED_LOOKUP_MAP = dict(
27 n='exact',
28 lte='lte',
29 lt='lt',
30 gte='gte',
31 gt='gt',
32 empty='isnull',
33)
35FILTER_NEGATION_LOOKUP_MAP = dict(
36 n='exact'
37)
39FILTER_TAG_LOOKUP_MAP = dict(
40 n='exact',
41 any='exact',
42)
44FILTER_TREENODE_NEGATION_LOOKUP_MAP = dict(
45 n='in'
46)
48#
49# HTTP Request META safe copy
50#
52# Non-HTTP_ META keys to include when copying a request (whitelist)
53HTTP_REQUEST_META_SAFE_COPY = [
54 'CONTENT_LENGTH',
55 'CONTENT_TYPE',
56 'HTTP_ACCEPT',
57 'HTTP_ACCEPT_ENCODING',
58 'HTTP_ACCEPT_LANGUAGE',
59 'HTTP_HOST',
60 'HTTP_REFERER',
61 'HTTP_USER_AGENT',
62 'HTTP_X_FORWARDED_FOR',
63 'HTTP_X_FORWARDED_HOST',
64 'HTTP_X_FORWARDED_PORT',
65 'HTTP_X_FORWARDED_PROTO',
66 'HTTP_X_REAL_IP',
67 'QUERY_STRING',
68 'REMOTE_ADDR',
69 'REMOTE_HOST',
70 'REMOTE_USER',
71 'REQUEST_METHOD',
72 'SERVER_NAME',
73 'SERVER_PORT',
74]
76# HTTP_ META keys known to carry sensitive data; excluded when copying a request (denylist)
77HTTP_REQUEST_META_SENSITIVE = {
78 'HTTP_AUTHORIZATION',
79 'HTTP_COOKIE',
80 'HTTP_PROXY_AUTHORIZATION',
81}
84#
85# CSV-style format delimiters
86#
88CSV_DELIMITERS = {
89 'comma': ',',
90 'semicolon': ';',
91 'pipe': '|',
92 'tab': '\t',
93}
96#
97# HTML allowed tags & attributes
98#
100HTML_ALLOWED_TAGS = {
101 "a", "b", "blockquote", "br", "code", "dd", "del", "div", "dl", "dt", "em", "h1", "h2", "h3", "h4", "h5", "h6",
102 "hr", "i", "img", "li", "ol", "p", "pre", "strong", "table", "tbody", "td", "th", "thead", "tr", "ul"
103}
105HTML_ALLOWED_ATTRIBUTES = {
106 "a": {"href", "title"},
107 "div": {"class"},
108 "h1": {"id"},
109 "h2": {"id"},
110 "h3": {"id"},
111 "h4": {"id"},
112 "h5": {"id"},
113 "h6": {"id"},
114 "img": {"alt", "src", "title"},
115 "td": {"align"},
116 "th": {"align"},
117}
119# Allowed URL schemes for image sources (img[src]); applied in addition to ALLOWED_URL_SCHEMES
120IMAGE_URL_SCHEMES = {'http', 'https'}
122HTTP_PROXY_SUPPORTED_SOCK_SCHEMAS = ['socks4', 'socks4a', 'socks4h', 'socks5', 'socks5a', 'socks5h']
123HTTP_PROXY_SOCK_RDNS_SCHEMAS = ['socks4h', 'socks4a', 'socks5h', 'socks5a']
124HTTP_PROXY_SUPPORTED_SCHEMAS = ['http', 'https', 'socks4', 'socks4a', 'socks4h', 'socks5', 'socks5a', 'socks5h']