Opened 54 minutes ago
#37417 new Bug
Date-based generic views crash with OverflowError at the date range limits
| Reported by: | Philip Sørensen | Owned by: | |
|---|---|---|---|
| Component: | Generic views | Version: | 6.1 |
| Severity: | Normal | Keywords: | |
| Cc: | Philip Sørensen | Triage Stage: | Unreviewed |
| Has patch: | yes | Needs documentation: | no |
| Needs tests: | no | Patch needs improvement: | no |
| Easy pickings: | no | UI/UX: | no |
Description
#28209 made the date-based generic views return a 404 rather than crash when given an out-of-range date. The fix caught the ValueError from date.replace() in _get_next_year() and _get_next_month(), and _get_next_week() catches OverflowError. However, two other paths do timedelta arithmetic at datetime.date.max / datetime.date.min with no handling, and they still crash with OverflowError: date value out of range (HTTP 500):
DayMixin._get_next_day()— e.g. aDayArchiveViewwithallow_empty=Trueat/9999/dec/31/. This is reachable with the URL pattern from the docs,<int:year>/<str:month>/<int:day>/. (#28209 comment 5 lists_get_next_day()as affected, but the committed fix didn't touch it.)_get_next_prev()computing the previous period withallow_empty=True:get_current(start - timedelta(days=1)). This crashes forYearArchiveView,MonthArchiveView,WeekArchiveViewandDayArchiveViewwhen the date is in year 1, e.g.year="0001". (A<int:year>converter strips the leading zeros, so this needs a 4-digit regex or str pattern.)
Patch: raise Http404(_("Date out of range")) in both places. That is the same behavior and message as the existing _get_next_week() handling and test_year_out_of_range. An alternative for the "previous" case would be returning None (no previous link), but I kept it consistent with the #28209 approach.