# -*- coding: utf-8 -*- # Licensed to the Apache Software Foundation (ASF) under one # or more contributor license agreements. See the NOTICE file # distributed with this work for additional information # regarding copyright ownership. The ASF licenses this file # to you under the Apache License, Version 2.0 (the # "License"); you may not use this file except in compliance # with the License. You may obtain a copy of the License at # # http://www.apache.org/licenses/LICENSE-2.0 # # Unless required by applicable law or agreed to in writing, # software distributed under the License is distributed on an # "AS IS" BASIS, WITHOUT WARRANTIES OR CONDITIONS OF ANY # KIND, either express or implied. See the License for the # specific language governing permissions and limitations # under the License. import pytest from superset.utils.urls import modify_url_query EXPLORE_CHART_LINK = "http://localhost:9000/explore/?form_data=%7B%22slice_id%22%3A+76%7D&standalone=true&force=false" EXPLORE_DASHBOARD_LINK = "http://localhost:9000/superset/dashboard/3/?standalone=3" def test_convert_chart_link() -> None: test_url = modify_url_query(EXPLORE_CHART_LINK, standalone="0") assert ( test_url == "http://localhost:9000/explore/?form_data=%7B%22slice_id%22%3A%2076%7D&standalone=0&force=false" ) def test_convert_dashboard_link() -> None: test_url = modify_url_query(EXPLORE_DASHBOARD_LINK, standalone="0") assert test_url == "http://localhost:9000/superset/dashboard/3/?standalone=0" @pytest.mark.parametrize( "url,is_safe", [ ("http://localhost/", True), ("http://localhost/superset/1", True), ("https://localhost/", False), ("https://localhost/superset/1", False), ("localhost/superset/1", False), ("ftp://localhost/superset/1", False), ("http://external.com", False), ("https://external.com", False), ("external.com", False), ("///localhost", False), ("xpto://localhost:[3/1/", False), ], ) def test_is_safe_url(url: str, is_safe: bool) -> None: from superset import app from superset.utils.urls import is_safe_url with app.test_request_context("/"): assert is_safe_url(url) == is_safe