Strip obscure whitespace from form submissions

We strip most whitespace as of:
https://github.com/alphagov/notifications-admin/pull/1701

However we are still getting some bad email addresses through, for
example one that had a leading zero-width space character. This means
that the user sees a validation error; really we should just deal with
the mess for them.

So this commit also includes characters without Unicode character
property "WSpace=Y" (which includes zero-width space) to those which are
stripped from form submissions.

List taken from here: https://en.wikipedia.org/wiki/Whitespace_character

See issue and discussion here: https://bugs.python.org/issue13391
This commit is contained in:
Chris Hill-Scott
2018-04-25 15:48:01 +01:00
parent 511ca8f652
commit 9e78c5f575
2 changed files with 43 additions and 1 deletions

View File

@@ -1,3 +1,4 @@
import string
import weakref
from datetime import datetime, timedelta
from itertools import chain
@@ -40,6 +41,15 @@ from app.main.validators import (
ValidGovEmail,
)
OBSCURE_WHITESPACE = (
'\u180E' # Mongolian vowel separator
'\u200B' # zero width space
'\u200C' # zero width non-joiner
'\u200D' # zero width joiner
'\u2060' # word joiner
'\uFEFF' # zero width non-breaking space
)
def get_time_value_and_label(future_time):
return (
@@ -110,7 +120,7 @@ def email_address(label='Email address', gov_user=True):
def strip_whitespace(value):
if value is not None and hasattr(value, 'strip'):
return value.strip()
return value.strip(string.whitespace + OBSCURE_WHITESPACE)
return value