From 0d8fa2012c0f95e82590a51930c9cd7177c33b97 Mon Sep 17 00:00:00 2001 From: Greg Von Kuster Date: Wed, 18 Dec 2013 19:03:05 -0500 Subject: [PATCH 1/6] Fix for determining a guid in the install_manager. --- .../galaxy_install/install_manager.py | 19 +++++++++---------- 1 file changed, 9 insertions(+), 10 deletions(-) diff --git a/lib/tool_shed/galaxy_install/install_manager.py b/lib/tool_shed/galaxy_install/install_manager.py index 302fe351c10..a15eb000769 100644 --- a/lib/tool_shed/galaxy_install/install_manager.py +++ b/lib/tool_shed/galaxy_install/install_manager.py @@ -244,21 +244,20 @@ class InstallManager( object ): def get_guid( self, repository_clone_url, relative_install_dir, tool_config ): if self.shed_config_dict.get( 'tool_path' ): - relative_install_dir = os.path.join( self.shed_config_dict['tool_path'], relative_install_dir ) - found = False + relative_install_dir = os.path.join( self.shed_config_dict[ 'tool_path' ], relative_install_dir ) + tool_config_filename = suc.strip_path( tool_config ) for root, dirs, files in os.walk( relative_install_dir ): if root.find( '.hg' ) < 0 and root.find( 'hgrc' ) < 0: if '.hg' in dirs: dirs.remove( '.hg' ) for name in files: - if name == tool_config: - found = True - break - if found: - break - full_path = str( os.path.abspath( os.path.join( root, name ) ) ) - tool = self.toolbox.load_tool( full_path ) - return suc.generate_tool_guid( repository_clone_url, tool ) + filename = suc.strip_path( name ) + if filename == tool_config_filename: + full_path = str( os.path.abspath( os.path.join( root, name ) ) ) + tool = self.toolbox.load_tool( full_path ) + return suc.generate_tool_guid( repository_clone_url, tool ) + # Not quite sure what should happen here, throw an exception or what? + return None def get_prior_install_required_dict( self, tool_shed_repositories, repository_dependencies_dict ): """ From 549461d4d93419f6c91dcdee8ab9a65272c5c2a1 Mon Sep 17 00:00:00 2001 From: Dannon Baker Date: Thu, 19 Dec 2013 14:38:03 -0500 Subject: [PATCH 2/6] Fix workflow import url XSS. --- templates/webapps/galaxy/workflow/import.mako | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/templates/webapps/galaxy/workflow/import.mako b/templates/webapps/galaxy/workflow/import.mako index fc50d54df9b..411f1ffb750 100644 --- a/templates/webapps/galaxy/workflow/import.mako +++ b/templates/webapps/galaxy/workflow/import.mako @@ -31,7 +31,7 @@
- +
If the workflow is accessible via a URL, enter the URL above and click Import.
From 28123bdde5de26e3eea7aa6acdc9df99f2bf3a70 Mon Sep 17 00:00:00 2001 From: Aysam Guerler Date: Thu, 2 Jan 2014 23:25:22 -0500 Subject: [PATCH 3/6] Fix XSS issue in former grids code --- templates/grid_base.mako | 19 ++++++++++++++----- 1 file changed, 14 insertions(+), 5 deletions(-) diff --git a/templates/grid_base.mako b/templates/grid_base.mako index f6e8f8661d7..9bb5fd1dfb9 100644 --- a/templates/grid_base.mako +++ b/templates/grid_base.mako @@ -56,6 +56,14 @@ ${h.js("libs/jquery/jquery.autocomplete", "galaxy.autocom_tagging", "libs/jquery/jquery.rating", "galaxy.grids" )} ${handle_refresh_frames()} + <% + self.grid_options = { + 'sort_key' : sort_key, + 'use_async' : grid.use_async, + 'cur_page_num' : cur_page_num, + 'num_pages' : num_pages + } + %>