X-Git-Url: https://git.mdrn.pl/wolnelektury.git/blobdiff_plain/04474c1980a751d4b6ca205e47b82e6471028e7f..40a66c8feb465a5d40035272bfd2b95e9027b7dd:/apps/catalogue/views.py diff --git a/apps/catalogue/views.py b/apps/catalogue/views.py index ade37e52a..d8a61e35e 100644 --- a/apps/catalogue/views.py +++ b/apps/catalogue/views.py @@ -97,13 +97,17 @@ def book_list(request): def tagged_object_list(request, tags=''): + # Prevent DoS attacks on our database + if len(tags.split('/')) > 6: + raise Http404 + try: tags = models.Tag.get_tag_list(tags) except models.Tag.DoesNotExist: raise Http404 model = models.Book - shelf_is_set = any(tag.category == 'set' for tag in tags) + shelf_is_set = (len(tags) == 1 and tags[0].category == 'set') theme_is_set = any(tag.category == 'theme' for tag in tags) if theme_is_set: model = models.Fragment