fix: use form URL for progress requests

This commit is contained in:
2026-08-05 13:13:46 +02:00
parent e061c2b02d
commit f558832cd2
5 changed files with 22 additions and 5 deletions
+1 -1
View File
@@ -7,7 +7,7 @@ class NetBoxExportConfig(PluginConfig):
name = "netbox_export"
verbose_name = "NetBox-Export"
description = "Portable ZIP export and import for tenants and locations"
version = "0.3.1"
version = "0.3.2"
author = "NetBox Export contributors"
base_url = "netbox-export"
min_version = "4.6.0"
+1 -1
View File
@@ -39,7 +39,7 @@ def export_scope(
"created_at": datetime.now(UTC).isoformat(),
"source_instance": str(InstanceIdentity.local_id()),
"source_netbox_version": getattr(getattr(settings, "RELEASE", None), "version", "4.6"),
"plugin_version": "0.3.1",
"plugin_version": "0.3.2",
"scope": {
"type": scope_type,
"source_pk": str(scope_id),
@@ -149,6 +149,8 @@
form.setAttribute('aria-busy', busy ? 'true' : 'false');
};
const formTarget = (form) => form.getAttribute('action') || window.location.href;
const updateProgress = (container, label, percent = null, state = 'active') => {
const bar = container.querySelector('.progress-bar');
const progress = container.querySelector('[role="progressbar"]');
@@ -179,7 +181,7 @@
updateProgress(exportProgress, 'Export wird vorbereitet ...');
const request = new XMLHttpRequest();
request.open('POST', exportForm.action || window.location.href);
request.open('POST', formTarget(exportForm));
request.responseType = 'blob';
request.onprogress = (progressEvent) => {
if (!progressEvent.lengthComputable) return;
@@ -220,7 +222,7 @@
updateProgress(importProgress, 'Archiv wird hochgeladen ...', 0);
const request = new XMLHttpRequest();
request.open('POST', importForm.action || window.location.href);
request.open('POST', formTarget(importForm));
request.upload.onprogress = (progressEvent) => {
if (!progressEvent.lengthComputable) return;
const percent = Math.min(100, Math.round((progressEvent.loaded / progressEvent.total) * 100));
+1 -1
View File
@@ -4,7 +4,7 @@ build-backend = "setuptools.build_meta"
[project]
name = "netbox-export"
version = "0.3.1"
version = "0.3.2"
description = "Portable ZIP export and import for scoped NetBox data"
readme = "README.md"
requires-python = ">=3.12"
+15
View File
@@ -0,0 +1,15 @@
from pathlib import Path
def test_form_action_field_cannot_shadow_request_target():
template = (
Path(__file__).parents[1]
/ "netbox_export"
/ "templates"
/ "netbox_export"
/ "dashboard.html"
).read_text(encoding="utf-8")
assert "form.getAttribute('action')" in template
assert "exportForm.action" not in template
assert "importForm.action" not in template