Opened 5 years ago

Closed 4 years ago

#20784 closed New feature (fixed)

RegexValidator should accept a new parameter to perform reversed validation

Reported by: Si Feng Owned by: nobody
Component: Core (Other) Version: master
Severity: Normal Keywords: RegexValidator
Cc: Triage Stage: Accepted
Has patch: yes Needs documentation: no
Needs tests: no Patch needs improvement: yes
Easy pickings: no UI/UX: no


In current implementation, RegexValidator only raises ValidationError when pattern DOES NOT match regex, while it is pretty common to use a "reversed" RegexValidator that raises ValidationError when pattern MATCHES regex. A typical scenario is to catch potential XSS inputs in form field validation (if it matches then the validator should panic).

Technically such reversed match could be performed by tweaking the regex itself, however in real world, not everybody is a regex master and there are a lot of people who may prefer a more straightforward solution as simple as "not some_condition".

In my own projects, I've written a ReversedRegexValidator by subclassing RegexValidator and overriding the call() method to change it's behavior (basically it just copied everything and then removed the "not" statement). It worked well, however there are some problems:

  1. RegexValidator uses some Django internal utils that are not documented during upgrades. For example, in Django 1.4.x, RegexValidator used smart_unicode() from utils.encoding, while in Django 1.5.x, it changed to force_text(). The custom ReversedRegexValidator will need to be upgraded as well for such internal change.
  2. Overriding the whole call() method in order to just remove (or have) a "not" operation seems to be too much. But that's the current problem with RegexValidator.

So my suggestion is to add a new parameter, say "reverse", to RegexValidator. By default it's False and won't change anything to existing codes, but a user can very easily change it's matching behavior by passing reverse=True.

I've had my changes ready for review. Test cases have been updated as well.

Change History (9)

comment:2 Changed 5 years ago by Claude Paroz

Needs documentation: set
Triage Stage: UnreviewedAccepted

comment:3 Changed 5 years ago by Aymeric Augustin

I'm not strongly against this idea in general, however, I'm very concerned about the rationale.

A blacklist implemented with a regex is a textbook example of the worst possible way to defend against XSS!

Last edited 5 years ago by Aymeric Augustin (previous) (diff)

comment:4 Changed 5 years ago by Baptiste Mispelon


I think reverse is a confusing name for this feature because it already has a different meaning for lists (consider the reversed builtin or the reverse argument to sorted). Maybe something like invert would work better?

I also wonder if a separate validator wouldn't be a better approach since the two are fundamentally different. What do you think?

Finally, as noted by claudep, your patch will need documentation too: a new entry in the ref/validators page as well as a mention in the release notes for 1.7.


comment:5 in reply to:  1 Changed 5 years ago by Si Feng

Replying to devfeng:

Updated, please review. :)

comment:6 Changed 4 years ago by Tim Graham

Needs documentation: unset
Patch needs improvement: set

Patch needs updating to merge cleanly.

comment:7 in reply to:  6 ; Changed 4 years ago by Si Feng

Replying to timo:

Patch needs updating to merge cleanly.

comment:8 in reply to:  7 Changed 4 years ago by Si Feng

Replying to devfeng:

Replying to timo:

Patch needs updating to merge cleanly.

PR updated per Tim's comments.

comment:9 Changed 4 years ago by Tim Graham <timograham@…>

Resolution: fixed
Status: newclosed

In b102c27ff4d21ea6262e600227530f75337a5df2:

Fixed #20784 -- Added inverse_match parameter to RegexValidator.

Note: See TracTickets for help on using tickets.
Back to Top