Skip to content

Use xml.etree through defusedxml#19640

Merged
fabaff merged 1 commit intohome-assistant:devfrom
scop:defusedxml
Dec 29, 2018
Merged

Use xml.etree through defusedxml#19640
fabaff merged 1 commit intohome-assistant:devfrom
scop:defusedxml

Conversation

@scop
Copy link
Copy Markdown
Member

@scop scop commented Dec 29, 2018

Description:

...for security reasons. Untested apart from tox/Travis, I don't have these devices around.

Related issue (if applicable): fixes #

Pull request in home-assistant.io with documentation (if applicable): home-assistant/home-assistant.io#<home-assistant.io PR number goes here>

Example entry for configuration.yaml (if applicable):

Checklist:

  • The code change is tested and works locally.
  • Local tests pass with tox. Your PR cannot be merged unless tests pass
  • There is no commented out code in this PR.

If user exposed functionality or configuration variables are added/changed:

If the code communicates with devices, web services, or third-party tools:

  • New dependencies have been added to the REQUIREMENTS variable (example).
  • New dependencies are only imported inside functions that use them (example).
  • New or updated dependencies have been added to requirements_all.txt by running script/gen_requirements_all.py.
  • New files were added to .coveragerc.

If the code does not interact with devices:

  • Tests have been added to verify that the new code works.

@fabaff
Copy link
Copy Markdown
Member

fabaff commented Dec 29, 2018

Isn't defusedxml as drop-in replacement? If so, I think that we are fine.

@scop
Copy link
Copy Markdown
Member Author

scop commented Dec 29, 2018

Yep, for ElementTree it just installs a few handlers that disable entity declarations and external entity fetches; the actual parser is still the same ElementTree. https://github.com/tiran/defusedxml/blob/master/defusedxml/ElementTree.py

@fabaff fabaff merged commit f925d9c into home-assistant:dev Dec 29, 2018
@ghost ghost removed the in progress label Dec 29, 2018
@scop scop deleted the defusedxml branch December 30, 2018 20:05
@balloob balloob mentioned this pull request Jan 10, 2019
alandtse pushed a commit to alandtse/home-assistant that referenced this pull request Feb 12, 2019
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants