From f558832cd2908e2279e080f682a71ded0dab6139 Mon Sep 17 00:00:00 2001 From: Louis Date: Wed, 5 Aug 2026 13:13:46 +0200 Subject: [PATCH] fix: use form URL for progress requests --- netbox_export/__init__.py | 2 +- netbox_export/services/exporter.py | 2 +- .../templates/netbox_export/dashboard.html | 6 ++++-- pyproject.toml | 2 +- tests/test_dashboard_template.py | 15 +++++++++++++++ 5 files changed, 22 insertions(+), 5 deletions(-) create mode 100644 tests/test_dashboard_template.py diff --git a/netbox_export/__init__.py b/netbox_export/__init__.py index b1d2eca..b1005e9 100644 --- a/netbox_export/__init__.py +++ b/netbox_export/__init__.py @@ -7,7 +7,7 @@ class NetBoxExportConfig(PluginConfig): name = "netbox_export" verbose_name = "NetBox-Export" description = "Portable ZIP export and import for tenants and locations" - version = "0.3.1" + version = "0.3.2" author = "NetBox Export contributors" base_url = "netbox-export" min_version = "4.6.0" diff --git a/netbox_export/services/exporter.py b/netbox_export/services/exporter.py index 72d659e..17cc0a6 100644 --- a/netbox_export/services/exporter.py +++ b/netbox_export/services/exporter.py @@ -39,7 +39,7 @@ def export_scope( "created_at": datetime.now(UTC).isoformat(), "source_instance": str(InstanceIdentity.local_id()), "source_netbox_version": getattr(getattr(settings, "RELEASE", None), "version", "4.6"), - "plugin_version": "0.3.1", + "plugin_version": "0.3.2", "scope": { "type": scope_type, "source_pk": str(scope_id), diff --git a/netbox_export/templates/netbox_export/dashboard.html b/netbox_export/templates/netbox_export/dashboard.html index f7cb8ba..29e014a 100644 --- a/netbox_export/templates/netbox_export/dashboard.html +++ b/netbox_export/templates/netbox_export/dashboard.html @@ -149,6 +149,8 @@ form.setAttribute('aria-busy', busy ? 'true' : 'false'); }; + const formTarget = (form) => form.getAttribute('action') || window.location.href; + const updateProgress = (container, label, percent = null, state = 'active') => { const bar = container.querySelector('.progress-bar'); const progress = container.querySelector('[role="progressbar"]'); @@ -179,7 +181,7 @@ updateProgress(exportProgress, 'Export wird vorbereitet ...'); const request = new XMLHttpRequest(); - request.open('POST', exportForm.action || window.location.href); + request.open('POST', formTarget(exportForm)); request.responseType = 'blob'; request.onprogress = (progressEvent) => { if (!progressEvent.lengthComputable) return; @@ -220,7 +222,7 @@ updateProgress(importProgress, 'Archiv wird hochgeladen ...', 0); const request = new XMLHttpRequest(); - request.open('POST', importForm.action || window.location.href); + request.open('POST', formTarget(importForm)); request.upload.onprogress = (progressEvent) => { if (!progressEvent.lengthComputable) return; const percent = Math.min(100, Math.round((progressEvent.loaded / progressEvent.total) * 100)); diff --git a/pyproject.toml b/pyproject.toml index 684fe5f..ecede7f 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta" [project] name = "netbox-export" -version = "0.3.1" +version = "0.3.2" description = "Portable ZIP export and import for scoped NetBox data" readme = "README.md" requires-python = ">=3.12" diff --git a/tests/test_dashboard_template.py b/tests/test_dashboard_template.py new file mode 100644 index 0000000..39a10d0 --- /dev/null +++ b/tests/test_dashboard_template.py @@ -0,0 +1,15 @@ +from pathlib import Path + + +def test_form_action_field_cannot_shadow_request_target(): + template = ( + Path(__file__).parents[1] + / "netbox_export" + / "templates" + / "netbox_export" + / "dashboard.html" + ).read_text(encoding="utf-8") + + assert "form.getAttribute('action')" in template + assert "exportForm.action" not in template + assert "importForm.action" not in template