Skip to content

Commit

Permalink
Use defusedxml for untrusted xml data in deserialization (#2829)
Browse files Browse the repository at this point in the history
  • Loading branch information
msyyc authored Sep 10, 2024
1 parent db304e9 commit 2005007
Show file tree
Hide file tree
Showing 138 changed files with 144 additions and 137 deletions.
7 changes: 7 additions & 0 deletions .chronus/changes/fix-xml-2024-8-10-11-42-32.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,7 @@
---
changeKind: fix
packages:
- "@azure-tools/typespec-python"
---

Fix bandit error in serialization
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -1130,7 +1130,7 @@ def _deserialize_xml(
deserializer: typing.Any,
value: str,
) -> typing.Any:
element = ET.fromstring(value)
element = ET.fromstring(value) # nosec
return _deserialize(deserializer, element)


Expand Down
Loading

0 comments on commit 2005007

Please sign in to comment.