mirror of
https://github.com/GSA/notifications-admin.git
synced 2026-09-08 19:23:12 -04:00
Bump WTForms and Flask-WTF to latest versions
WTForms versions less than 3.0.0 have a security vulnerability where arbitrary HTML can be inserted into the label of a form, allowing the possibility of a cross-site scripting attack. I don’t know if there’s anywhere we put user-generated content into form labels but it’s possible we are vulnerable somewhere. This require moving some imports because as of https://github.com/wtforms/wtforms/pull/614/files there is no longer a separate module for HTML 5 fields, they are now considered core fields. As of https://github.com/wtforms/wtforms/issues/445/files custom implementations of `pre_validate` or `post_validate` must raise `ValidationError` to trigger a validation message, where we were raising `ValueError` this was no longer being caught. As of https://github.com/wtforms/wtforms/pull/355/files `StringField` returns `None` for empty data, not `''` but our `validate_email_address` function only accepts strings.
This commit is contained in:
@@ -69,7 +69,7 @@ flask-login==0.5.0
|
||||
# via -r requirements.in
|
||||
flask-redis==0.4.0
|
||||
# via notifications-utils
|
||||
flask-wtf==0.15.1
|
||||
flask-wtf==1.0.0
|
||||
# via -r requirements.in
|
||||
gds-metrics==0.2.4
|
||||
# via -r requirements.in
|
||||
@@ -225,8 +225,10 @@ werkzeug==2.0.2
|
||||
# via
|
||||
# -r requirements.in
|
||||
# flask
|
||||
wtforms==2.3.3
|
||||
# via flask-wtf
|
||||
wtforms==3.0.0
|
||||
# via
|
||||
# -r requirements.in
|
||||
# flask-wtf
|
||||
xlrd==1.2.0
|
||||
# via pyexcel-xls
|
||||
xlwt==1.3.0
|
||||
|
||||
Reference in New Issue
Block a user