Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
12 changes: 4 additions & 8 deletions README.md
Original file line number Diff line number Diff line change
@@ -1,16 +1,12 @@
# Secure Coding with Python.

## Chapter 2: SQL Injection
### Fix part 2
In order to fix the SQL injetion once and for all, we should rely on prepared statements, and let the DB engine do the param sanitization, like this:
```python
sql = "INSERT INTO listings (title, description) VALUES (%s, %s)"
cur.execute(sql, (title, description))
```
### Fix part 3
An even better approach is to use an ORM, in this case we set up SQLAlchemy, by using the standard methods the ORM will do the sanitization so we don't need to worry about it.

Now both our unit test and bandit are happy!
**Note**: Most ORMs in some special use cases can still allow SQL Injections to happen, if you are using non-standard methods, review the ORMs security guidelines and test your application.

**Proceed to [next section](https://github.com/nxvl/secure-coding-with-python/tree/2.3-sql-injection/fix)**
**Proceed to [next section](https://github.com/nxvl/secure-coding-with-python/tree/3.1-weak-password-storage/code)**

## Index
### 1. Vulnerable Components
Expand Down
12 changes: 10 additions & 2 deletions marketplace/__init__.py
Original file line number Diff line number Diff line change
@@ -1,21 +1,29 @@
import os

from flask import Flask
from flask_sqlalchemy import SQLAlchemy
from flask_migrate import Migrate


db = SQLAlchemy()
migrate = Migrate()

def create_app(test_config=None):
app = Flask(__name__, instance_relative_config=True)
app.config.from_mapping(
SECRET_KEY='dev',
DATABASE='marketplace',
SQLALCHEMY_DATABASE_URI='postgresql:///marketplace',
SQLALCHEMY_TRACK_MODIFICATIONS=False,
)

try:
os.makedirs(app.instance_path)
except OSError:
pass

from . import db
from . import models
db.init_app(app)
migrate.init_app(app, db)

from . import listings
app.register_blueprint(listings.bp)
Expand Down
37 changes: 0 additions & 37 deletions marketplace/db.py

This file was deleted.

28 changes: 10 additions & 18 deletions marketplace/listings.py
Original file line number Diff line number Diff line change
@@ -1,32 +1,24 @@
import sys

from flask import Blueprint, request, redirect, render_template, url_for

from marketplace.db import get_db


from . import db
from .models import Listing

bp = Blueprint('listings', __name__, url_prefix='/listings')

@bp.route('/')
def index():
cur = get_db().cursor()
cur.execute(
'SELECT id, title, description'
' FROM listings'
)
listings = cur.fetchall()
listings = Listing.query.all()
return render_template('listings/index.html', listings=listings)

@bp.route('/create', methods=('GET', 'POST'))
def register():
if request.method == 'POST':
title = request.form['title']
description = request.form['description']
db = get_db()
cur = db.cursor()
listing = Listing(title=request.form['title'], description=request.form['description'])
db.session.add(listing)
db.session.commit()

sql = "INSERT INTO listings (title, description) VALUES (%s, %s)"
cur.execute(sql, (title, description))
db.commit()
return redirect(url_for('listings.index'))

return render_template('listings/create.html')
Expand Down
8 changes: 8 additions & 0 deletions marketplace/models.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,8 @@
from . import db

class Listing(db.Model):
__tablename__ = 'listings'

id = db.Column(db.Integer, primary_key=True)
title = db.Column(db.String(120))
description = db.Column(db.Text())
4 changes: 2 additions & 2 deletions marketplace/templates/listings/index.html
Original file line number Diff line number Diff line change
Expand Up @@ -9,10 +9,10 @@ <h1>{% block title %}Listings{% endblock %}</h1>
<article class="listing">
<header>
<div>
<h1>{{ listing[1] }}</h1>
<h1>{{ listing.title }}</h1>
</div>
</header>
<p class="body">{{ listing[2] }}</p>
<p class="body">{{ listing.description }}</p>
</article>
{% if not loop.last %}
<hr>
Expand Down
1 change: 1 addition & 0 deletions migrations/README
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
Generic single-database configuration.
45 changes: 45 additions & 0 deletions migrations/alembic.ini
Original file line number Diff line number Diff line change
@@ -0,0 +1,45 @@
# A generic, single database configuration.

[alembic]
# template used to generate migration files
# file_template = %%(rev)s_%%(slug)s

# set to 'true' to run the environment during
# the 'revision' command, regardless of autogenerate
# revision_environment = false


# Logging configuration
[loggers]
keys = root,sqlalchemy,alembic

[handlers]
keys = console

[formatters]
keys = generic

[logger_root]
level = WARN
handlers = console
qualname =

[logger_sqlalchemy]
level = WARN
handlers =
qualname = sqlalchemy.engine

[logger_alembic]
level = INFO
handlers =
qualname = alembic

[handler_console]
class = StreamHandler
args = (sys.stderr,)
level = NOTSET
formatter = generic

[formatter_generic]
format = %(levelname)-5.5s [%(name)s] %(message)s
datefmt = %H:%M:%S
96 changes: 96 additions & 0 deletions migrations/env.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,96 @@
from __future__ import with_statement

import logging
from logging.config import fileConfig

from sqlalchemy import engine_from_config
from sqlalchemy import pool

from alembic import context

# this is the Alembic Config object, which provides
# access to the values within the .ini file in use.
config = context.config

# Interpret the config file for Python logging.
# This line sets up loggers basically.
fileConfig(config.config_file_name)
logger = logging.getLogger('alembic.env')

# add your model's MetaData object here
# for 'autogenerate' support
# from myapp import mymodel
# target_metadata = mymodel.Base.metadata
from flask import current_app
config.set_main_option(
'sqlalchemy.url', current_app.config.get(
'SQLALCHEMY_DATABASE_URI').replace('%', '%%'))
target_metadata = current_app.extensions['migrate'].db.metadata

# other values from the config, defined by the needs of env.py,
# can be acquired:
# my_important_option = config.get_main_option("my_important_option")
# ... etc.


def run_migrations_offline():
"""Run migrations in 'offline' mode.

This configures the context with just a URL
and not an Engine, though an Engine is acceptable
here as well. By skipping the Engine creation
we don't even need a DBAPI to be available.

Calls to context.execute() here emit the given string to the
script output.

"""
url = config.get_main_option("sqlalchemy.url")
context.configure(
url=url, target_metadata=target_metadata, literal_binds=True
)

with context.begin_transaction():
context.run_migrations()


def run_migrations_online():
"""Run migrations in 'online' mode.

In this scenario we need to create an Engine
and associate a connection with the context.

"""

# this callback is used to prevent an auto-migration from being generated
# when there are no changes to the schema
# reference: http://alembic.zzzcomputing.com/en/latest/cookbook.html
def process_revision_directives(context, revision, directives):
if getattr(config.cmd_opts, 'autogenerate', False):
script = directives[0]
if script.upgrade_ops.is_empty():
directives[:] = []
logger.info('No changes in schema detected.')

connectable = engine_from_config(
config.get_section(config.config_ini_section),
prefix='sqlalchemy.',
poolclass=pool.NullPool,
)

with connectable.connect() as connection:
context.configure(
connection=connection,
target_metadata=target_metadata,
process_revision_directives=process_revision_directives,
**current_app.extensions['migrate'].configure_args
)

with context.begin_transaction():
context.run_migrations()


if context.is_offline_mode():
run_migrations_offline()
else:
run_migrations_online()
24 changes: 24 additions & 0 deletions migrations/script.py.mako
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
"""${message}

Revision ID: ${up_revision}
Revises: ${down_revision | comma,n}
Create Date: ${create_date}

"""
from alembic import op
import sqlalchemy as sa
${imports if imports else ""}

# revision identifiers, used by Alembic.
revision = ${repr(up_revision)}
down_revision = ${repr(down_revision)}
branch_labels = ${repr(branch_labels)}
depends_on = ${repr(depends_on)}


def upgrade():
${upgrades if upgrades else "pass"}


def downgrade():
${downgrades if downgrades else "pass"}
33 changes: 33 additions & 0 deletions migrations/versions/d018d799acf7_.py
Original file line number Diff line number Diff line change
@@ -0,0 +1,33 @@
"""empty message

Revision ID: d018d799acf7
Revises:
Create Date: 2019-07-10 15:21:38.057975

"""
from alembic import op
import sqlalchemy as sa


# revision identifiers, used by Alembic.
revision = 'd018d799acf7'
down_revision = None
branch_labels = None
depends_on = None


def upgrade():
# ### commands auto generated by Alembic - please adjust! ###
op.create_table('listings',
sa.Column('id', sa.Integer(), nullable=False),
sa.Column('title', sa.String(length=120), nullable=True),
sa.Column('description', sa.String(length=500), nullable=True),
sa.PrimaryKeyConstraint('id')
)
# ### end Alembic commands ###


def downgrade():
# ### commands auto generated by Alembic - please adjust! ###
op.drop_table('listings')
# ### end Alembic commands ###
2 changes: 2 additions & 0 deletions requirements.txt
Original file line number Diff line number Diff line change
Expand Up @@ -3,3 +3,5 @@ safety==1.8.5
psycopg2==2.8.3
pytest==5.1.0
bandit==1.6.2
Flask-Migrate==2.5.2
Flask-SQLAlchemy==2.4.0
5 changes: 1 addition & 4 deletions tests/conftest.py
Original file line number Diff line number Diff line change
Expand Up @@ -3,7 +3,7 @@

import pytest
from marketplace import create_app
from marketplace.db import get_db, init_db
from marketplace import db

sys.path.append(os.path.join(os.path.dirname(__file__), 'helpers'))

Expand All @@ -14,9 +14,6 @@ def app():
'DATABASE': 'marketplace_test',
})

with app.app_context():
init_db()

yield app

@pytest.fixture
Expand Down