Coverage for utilities/constants.py: 100%

15 statements  

« prev     ^ index     » next       coverage.py v7.15.2, created at 2026-10-10 18:35 +0000

1# 

2# Filter lookup expressions 

3# 

4 

5FILTER_CHAR_BASED_LOOKUP_MAP = dict( 

6 n='exact', 

7 ic='icontains', 

8 nic='icontains', 

9 iew='iendswith', 

10 niew='iendswith', 

11 isw='istartswith', 

12 nisw='istartswith', 

13 ie='iexact', 

14 nie='iexact', 

15 empty='empty', 

16 regex='regex', 

17 iregex='iregex', 

18) 

19 

20# A member is a scalar inside a stored array, so negation cannot fall back to equality 

21FILTER_ARRAY_BASED_LOOKUP_MAP = { 

22 **FILTER_CHAR_BASED_LOOKUP_MAP, 

23 'n': 'contains', 

24} 

25 

26FILTER_NUMERIC_BASED_LOOKUP_MAP = dict( 

27 n='exact', 

28 lte='lte', 

29 lt='lt', 

30 gte='gte', 

31 gt='gt', 

32 empty='isnull', 

33) 

34 

35FILTER_NEGATION_LOOKUP_MAP = dict( 

36 n='exact' 

37) 

38 

39FILTER_TAG_LOOKUP_MAP = dict( 

40 n='exact', 

41 any='exact', 

42) 

43 

44FILTER_TREENODE_NEGATION_LOOKUP_MAP = dict( 

45 n='in' 

46) 

47 

48# 

49# HTTP Request META safe copy 

50# 

51 

52# Non-HTTP_ META keys to include when copying a request (whitelist) 

53HTTP_REQUEST_META_SAFE_COPY = [ 

54 'CONTENT_LENGTH', 

55 'CONTENT_TYPE', 

56 'HTTP_ACCEPT', 

57 'HTTP_ACCEPT_ENCODING', 

58 'HTTP_ACCEPT_LANGUAGE', 

59 'HTTP_HOST', 

60 'HTTP_REFERER', 

61 'HTTP_USER_AGENT', 

62 'HTTP_X_FORWARDED_FOR', 

63 'HTTP_X_FORWARDED_HOST', 

64 'HTTP_X_FORWARDED_PORT', 

65 'HTTP_X_FORWARDED_PROTO', 

66 'HTTP_X_REAL_IP', 

67 'QUERY_STRING', 

68 'REMOTE_ADDR', 

69 'REMOTE_HOST', 

70 'REMOTE_USER', 

71 'REQUEST_METHOD', 

72 'SERVER_NAME', 

73 'SERVER_PORT', 

74] 

75 

76# HTTP_ META keys known to carry sensitive data; excluded when copying a request (denylist) 

77HTTP_REQUEST_META_SENSITIVE = { 

78 'HTTP_AUTHORIZATION', 

79 'HTTP_COOKIE', 

80 'HTTP_PROXY_AUTHORIZATION', 

81} 

82 

83 

84# 

85# CSV-style format delimiters 

86# 

87 

88CSV_DELIMITERS = { 

89 'comma': ',', 

90 'semicolon': ';', 

91 'pipe': '|', 

92 'tab': '\t', 

93} 

94 

95 

96# 

97# HTML allowed tags & attributes 

98# 

99 

100HTML_ALLOWED_TAGS = { 

101 "a", "b", "blockquote", "br", "code", "dd", "del", "div", "dl", "dt", "em", "h1", "h2", "h3", "h4", "h5", "h6", 

102 "hr", "i", "img", "li", "ol", "p", "pre", "strong", "table", "tbody", "td", "th", "thead", "tr", "ul" 

103} 

104 

105HTML_ALLOWED_ATTRIBUTES = { 

106 "a": {"href", "title"}, 

107 "div": {"class"}, 

108 "h1": {"id"}, 

109 "h2": {"id"}, 

110 "h3": {"id"}, 

111 "h4": {"id"}, 

112 "h5": {"id"}, 

113 "h6": {"id"}, 

114 "img": {"alt", "src", "title"}, 

115 "td": {"align"}, 

116 "th": {"align"}, 

117} 

118 

119# Allowed URL schemes for image sources (img[src]); applied in addition to ALLOWED_URL_SCHEMES 

120IMAGE_URL_SCHEMES = {'http', 'https'} 

121 

122HTTP_PROXY_SUPPORTED_SOCK_SCHEMAS = ['socks4', 'socks4a', 'socks4h', 'socks5', 'socks5a', 'socks5h'] 

123HTTP_PROXY_SOCK_RDNS_SCHEMAS = ['socks4h', 'socks4a', 'socks5h', 'socks5a'] 

124HTTP_PROXY_SUPPORTED_SCHEMAS = ['http', 'https', 'socks4', 'socks4a', 'socks4h', 'socks5', 'socks5a', 'socks5h']