Skip to content

Commit 10e48c2

Browse files
tcleonardThomas Leonard
and
Thomas Leonard
authored
Validate in and range filter inputs (#1090)
Co-authored-by: Thomas Leonard <[email protected]>
1 parent ea84827 commit 10e48c2

File tree

6 files changed

+209
-33
lines changed

6 files changed

+209
-33
lines changed

graphene_django/filter/__init__.py

+1-1
Original file line numberDiff line numberDiff line change
@@ -9,7 +9,7 @@
99
)
1010
else:
1111
from .fields import DjangoFilterConnectionField
12-
from .filterset import GlobalIDFilter, GlobalIDMultipleChoiceFilter
12+
from .filters import GlobalIDFilter, GlobalIDMultipleChoiceFilter
1313

1414
__all__ = [
1515
"DjangoFilterConnectionField",

graphene_django/filter/filters.py

+75
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,75 @@
1+
from django.core.exceptions import ValidationError
2+
from django.forms import Field
3+
4+
from django_filters import Filter, MultipleChoiceFilter
5+
6+
from graphql_relay.node.node import from_global_id
7+
8+
from ..forms import GlobalIDFormField, GlobalIDMultipleChoiceField
9+
10+
11+
class GlobalIDFilter(Filter):
12+
"""
13+
Filter for Relay global ID.
14+
"""
15+
16+
field_class = GlobalIDFormField
17+
18+
def filter(self, qs, value):
19+
""" Convert the filter value to a primary key before filtering """
20+
_id = None
21+
if value is not None:
22+
_, _id = from_global_id(value)
23+
return super(GlobalIDFilter, self).filter(qs, _id)
24+
25+
26+
class GlobalIDMultipleChoiceFilter(MultipleChoiceFilter):
27+
field_class = GlobalIDMultipleChoiceField
28+
29+
def filter(self, qs, value):
30+
gids = [from_global_id(v)[1] for v in value]
31+
return super(GlobalIDMultipleChoiceFilter, self).filter(qs, gids)
32+
33+
34+
class InFilter(Filter):
35+
"""
36+
Filter for a list of value using the `__in` Django filter.
37+
"""
38+
39+
def filter(self, qs, value):
40+
"""
41+
Override the default filter class to check first weather the list is
42+
empty or not.
43+
This needs to be done as in this case we expect to get an empty output
44+
(if not an exclude filter) but django_filter consider an empty list
45+
to be an empty input value (see `EMPTY_VALUES`) meaning that
46+
the filter does not need to be applied (hence returning the original
47+
queryset).
48+
"""
49+
if value is not None and len(value) == 0:
50+
if self.exclude:
51+
return qs
52+
else:
53+
return qs.none()
54+
else:
55+
return super().filter(qs, value)
56+
57+
58+
def validate_range(value):
59+
"""
60+
Validator for range filter input: the list of value must be of length 2.
61+
Note that validators are only run if the value is not empty.
62+
"""
63+
if len(value) != 2:
64+
raise ValidationError(
65+
"Invalid range specified: it needs to contain 2 values.", code="invalid"
66+
)
67+
68+
69+
class RangeField(Field):
70+
default_validators = [validate_range]
71+
empty_values = [None]
72+
73+
74+
class RangeFilter(Filter):
75+
field_class = RangeField

graphene_django/filter/filterset.py

+1-22
Original file line numberDiff line numberDiff line change
@@ -5,28 +5,7 @@
55
from django_filters.filterset import BaseFilterSet, FilterSet
66
from django_filters.filterset import FILTER_FOR_DBFIELD_DEFAULTS
77

8-
from graphql_relay.node.node import from_global_id
9-
10-
from ..forms import GlobalIDFormField, GlobalIDMultipleChoiceField
11-
12-
13-
class GlobalIDFilter(Filter):
14-
field_class = GlobalIDFormField
15-
16-
def filter(self, qs, value):
17-
""" Convert the filter value to a primary key before filtering """
18-
_id = None
19-
if value is not None:
20-
_, _id = from_global_id(value)
21-
return super(GlobalIDFilter, self).filter(qs, _id)
22-
23-
24-
class GlobalIDMultipleChoiceFilter(MultipleChoiceFilter):
25-
field_class = GlobalIDMultipleChoiceField
26-
27-
def filter(self, qs, value):
28-
gids = [from_global_id(v)[1] for v in value]
29-
return super(GlobalIDMultipleChoiceFilter, self).filter(qs, gids)
8+
from .filters import GlobalIDFilter, GlobalIDMultipleChoiceFilter
309

3110

3211
GRAPHENE_FILTER_SET_OVERRIDES = {

graphene_django/filter/tests/test_in_filter.py

+4-8
Original file line numberDiff line numberDiff line change
@@ -157,20 +157,19 @@ def test_int_in_filter():
157157
]
158158

159159

160-
def test_int_range_filter():
160+
def test_in_filter_with_empty_list():
161161
"""
162-
Test in filter on an integer field.
162+
Check that using a in filter with an empty list provided as input returns no objects.
163163
"""
164164
Pet.objects.create(name="Brutus", age=12)
165165
Pet.objects.create(name="Mimi", age=8)
166-
Pet.objects.create(name="Jojo, the rabbit", age=3)
167166
Pet.objects.create(name="Picotin", age=5)
168167

169168
schema = Schema(query=Query)
170169

171170
query = """
172171
query {
173-
pets (age_Range: [4, 9]) {
172+
pets (name_In: []) {
174173
edges {
175174
node {
176175
name
@@ -181,7 +180,4 @@ def test_int_range_filter():
181180
"""
182181
result = schema.execute(query)
183182
assert not result.errors
184-
assert result.data["pets"]["edges"] == [
185-
{"node": {"name": "Mimi"}},
186-
{"node": {"name": "Picotin"}},
187-
]
183+
assert len(result.data["pets"]["edges"]) == 0
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,114 @@
1+
import json
2+
import pytest
3+
4+
from django_filters import FilterSet
5+
from django_filters import rest_framework as filters
6+
from graphene import ObjectType, Schema
7+
from graphene.relay import Node
8+
from graphene_django import DjangoObjectType
9+
from graphene_django.tests.models import Pet
10+
from graphene_django.utils import DJANGO_FILTER_INSTALLED
11+
12+
pytestmark = []
13+
14+
if DJANGO_FILTER_INSTALLED:
15+
from graphene_django.filter import DjangoFilterConnectionField
16+
else:
17+
pytestmark.append(
18+
pytest.mark.skipif(
19+
True, reason="django_filters not installed or not compatible"
20+
)
21+
)
22+
23+
24+
class PetNode(DjangoObjectType):
25+
class Meta:
26+
model = Pet
27+
interfaces = (Node,)
28+
filter_fields = {
29+
"name": ["exact", "in"],
30+
"age": ["exact", "in", "range"],
31+
}
32+
33+
34+
class Query(ObjectType):
35+
pets = DjangoFilterConnectionField(PetNode)
36+
37+
38+
def test_int_range_filter():
39+
"""
40+
Test range filter on an integer field.
41+
"""
42+
Pet.objects.create(name="Brutus", age=12)
43+
Pet.objects.create(name="Mimi", age=8)
44+
Pet.objects.create(name="Jojo, the rabbit", age=3)
45+
Pet.objects.create(name="Picotin", age=5)
46+
47+
schema = Schema(query=Query)
48+
49+
query = """
50+
query {
51+
pets (age_Range: [4, 9]) {
52+
edges {
53+
node {
54+
name
55+
}
56+
}
57+
}
58+
}
59+
"""
60+
result = schema.execute(query)
61+
assert not result.errors
62+
assert result.data["pets"]["edges"] == [
63+
{"node": {"name": "Mimi"}},
64+
{"node": {"name": "Picotin"}},
65+
]
66+
67+
68+
def test_range_filter_with_invalid_input():
69+
"""
70+
Test range filter used with invalid inputs raise an error.
71+
"""
72+
Pet.objects.create(name="Brutus", age=12)
73+
Pet.objects.create(name="Mimi", age=8)
74+
Pet.objects.create(name="Jojo, the rabbit", age=3)
75+
Pet.objects.create(name="Picotin", age=5)
76+
77+
schema = Schema(query=Query)
78+
79+
query = """
80+
query ($rangeValue: [Int]) {
81+
pets (age_Range: $rangeValue) {
82+
edges {
83+
node {
84+
name
85+
}
86+
}
87+
}
88+
}
89+
"""
90+
expected_error = json.dumps(
91+
{
92+
"age__range": [
93+
{
94+
"message": "Invalid range specified: it needs to contain 2 values.",
95+
"code": "invalid",
96+
}
97+
]
98+
}
99+
)
100+
101+
# Empty list
102+
result = schema.execute(query, variables={"rangeValue": []})
103+
assert len(result.errors) == 1
104+
assert result.errors[0].message == f"['{expected_error}']"
105+
106+
# Only one item in the list
107+
result = schema.execute(query, variables={"rangeValue": [1]})
108+
assert len(result.errors) == 1
109+
assert result.errors[0].message == f"['{expected_error}']"
110+
111+
# More than 2 items in the list
112+
result = schema.execute(query, variables={"rangeValue": [1, 2, 3]})
113+
assert len(result.errors) == 1
114+
assert result.errors[0].message == f"['{expected_error}']"

graphene_django/filter/utils.py

+14-2
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
from django_filters.filters import Filter, BaseCSVFilter
55

66
from .filterset import custom_filterset_factory, setup_filterset
7+
from .filters import InFilter, RangeFilter
78

89

910
def get_filtering_args_from_filterset(filterset_class, type):
@@ -78,9 +79,20 @@ def replace_csv_filters(filterset_class):
7879
"""
7980
for name, filter_field in list(filterset_class.base_filters.items()):
8081
filter_type = filter_field.lookup_expr
81-
if filter_type in ["in", "range"]:
82+
if filter_type == "in":
83+
assert isinstance(filter_field, BaseCSVFilter)
84+
filterset_class.base_filters[name] = InFilter(
85+
field_name=filter_field.field_name,
86+
lookup_expr=filter_field.lookup_expr,
87+
label=filter_field.label,
88+
method=filter_field.method,
89+
exclude=filter_field.exclude,
90+
**filter_field.extra
91+
)
92+
93+
if filter_type == "range":
8294
assert isinstance(filter_field, BaseCSVFilter)
83-
filterset_class.base_filters[name] = Filter(
95+
filterset_class.base_filters[name] = RangeFilter(
8496
field_name=filter_field.field_name,
8597
lookup_expr=filter_field.lookup_expr,
8698
label=filter_field.label,

0 commit comments

Comments
 (0)