Django-Filters空字符串查询参数导致验证错误

问题描述 投票:2回答:3

当使用带有django rest框架的django-filters时,默认查询过滤表单将为所有字段添加所有查询参数,空字段最终作为传递给后端的空字符串。空字符串不是None,所以status = self.request.query_params.get('status', None)仍会将空字符串添加到变量中,这将进入queryset.filter函数。当被过滤的字段不是字符串时,这非常糟糕。

所以我的问题是我做错了什么?有没有办法检查空字符串参数?我不确定我是否正在进行正确的过滤(我可能无缘无故地过滤了两次,但我想在那里使用django-filters,因为内置了与django-rest-frameworks可浏览API的集成。

我的解决方法是在调用query_params.get之后检查空字符串的三元运算符

以下是我的API视图代码:

class JobList(generics.ListCreateAPIView):
    serializer_class = JobCreateSerializer
    permission_classes = (permissions.IsAuthenticatedOrReadOnly,)

    filter_backends = (filters.OrderingFilter, DjangoFilterBackend)
    filterset_fields = ('status', 'success', 'worker_id', 'owner', 'job_type')
    ordering_fields = ('priority', 'submitted', 'assigned', 'completed')

    def perform_create(self, serializer):
        serializer.save(owner=self.request.user)

    def get(self, request, format=None):
        # IMPORTANT: use self.get_queryset() any place you want filtering to be enabled
        # for built in filtering or ordering you must call self.filter_queryset
        jobs = self.filter_queryset(self.get_queryset())
        serializer = JobSerializer(jobs, context={'request': request}, many=True)

        return Response(serializer.data)

    def get_queryset(self):
        """
        This view should return a list of all the purchases
        for the currently authenticated user.
        """
        queryset = Job.objects.all()

        status = self.request.query_params.get('status', None)
        status = status if not status == '' else None
        success = self.request.query_params.get('success', None)
        success = success if not success == '' else None
        worker_id = self.request.query_params.get('worker_id', None)
        worker_id = worker_id if not worker_id == '' else None
        owner_id = self.request.query_params.get('owner', None)
        owner_id = owner_id if not owner_id == '' else None
        job_type = self.request.query_params.get('job_type', None)
        job_type = job_type if not job_type == '' else None

        if status is not None:
            queryset = queryset.filter(status=status)
        if success is not None:
            queryset = queryset.filter(success=success)
        if worker_id is not None:
            queryset = queryset.filter(worker_id=worker_id)
        if owner_id is not None:
            queryset = queryset.filter(owner=owner_id)
        if job_type is not None:
            queryset = queryset.filter(job_type=job_type)

        return queryset
python django django-rest-framework django-filter
3个回答
0
投票

如果你使用if status:而不是if status is not None:,空字符串和None都会给False。这对于整数是危险的,因为0会返回false,但这不是问题,因为所有参数都是字符串。

您还可以将''定义为默认值,然后检查非零长度字符串:

status = self.request.query_params.get('status', '')
# ...
if len(status):

0
投票

为什么不将默认值设置为空字符串,并将其用作保护值而不是None

status = self.request.query_params.get("status", "")
success = self.request.query_params.get("success", "")
# ...
if status:
    queryset = queryset.filter(status=status)
if success:
    queryset = queryset.filter(success=success)
# ...

0
投票

谢谢你的答案,我认为它们是有效的方法,但他们都在进行人工检查。我一直在寻找一种内置的方法来将使用query_params的JSON本机类型转换为Python本机类​​型(false为False,null为None等)。希望避免手动检查和转换每个query_param。

如果Django Rest Framework中没有这样的东西,它实际上让我大吃一惊。所以我创建了一个辅助函数,可以从query_params到Python dict进行简单的一级深度转换。我希望这可以帮助别人,或者如果有人知道DRF中有类似的便利功能,我会很感激。或者,如果有人能告诉我为什么这是一个糟糕的方法,我也会很感激!

def query_params_parser(self, fields_list):

        json_values_dict = {}

        for field in fields_list:
            value = '"' + self.request.query_params.get(field) + '"' if not self.query_params.get(field, '') == '' else 'null'
            json_values_dict['"' + field + '"'] = value

        json_string = '{'

        for idx, (key, value) in enumerate(json_values_dict.items()):
            json_string += f'{key}: {value}'

            if idx < len(json_values_dict) - 1:
                json_string += ','

        json_string += '}'

        final_dict = json.loads(json_string)

        return final_dict


def get_queryset(self):
        """
        This view should return a list of all the purchases
        for the currently authenticated user.
        """
        queryset = Job.objects.all()

        # parse json query_params
        # query_params, list of fields
        # returns dict

        params_dict = self.query_params_parser(['status',
                                                'success',
                                                'worker_id',
                                                'owner',
                                                'job_type'])

        status = params_dict['status']
        success = params_dict['success']
        worker_id = params_dict['worker_id']
        owner = params_dict['owner']
        job_type = params_dict['job_type']

        if status is not None:
            queryset = queryset.filter(status=status)
        if success is not None:
            queryset = queryset.filter(success=success)
        if worker_id is not None:
            queryset = queryset.filter(worker_id=worker_id)
        if owner is not None:
            queryset = queryset.filter(owner=owner)
        if job_type is not None:
            queryset = queryset.filter(job_type=job_type)

        return queryset

上述功能在有限的测试下工作,因此可能存在很多错误。

© www.soinside.com 2019 - 2024. All rights reserved.