mirror of
https://github.com/django-q2/django-q2.git
synced 2026-10-07 10:38:13 +08:00
Replace use of eval() by ast.parse() + ast.literal_eval() (#10)
Co-authored-by: Marc Sabatier <marc@sabatier.online>
This commit is contained in:
co-authored by
Marc Sabatier
parent
803618da03
commit
4aa6325ae8
+9
-4
@@ -603,10 +603,15 @@ def scheduler(broker: Broker = None):
|
|||||||
# get args, kwargs and hook
|
# get args, kwargs and hook
|
||||||
if s.kwargs:
|
if s.kwargs:
|
||||||
try:
|
try:
|
||||||
# eval should be safe here because dict()
|
# first try the dict syntax
|
||||||
kwargs = eval(f"dict({s.kwargs})")
|
kwargs = ast.literal_eval(s.kwargs)
|
||||||
except SyntaxError:
|
except (SyntaxError, ValueError):
|
||||||
kwargs = {}
|
# else use the kwargs syntax
|
||||||
|
try:
|
||||||
|
parsed_kwargs = ast.parse(f"f({s.kwargs})").body[0].value.keywords
|
||||||
|
kwargs = {kwarg.arg: ast.literal_eval(kwarg.value) for kwarg in parsed_kwargs}
|
||||||
|
except (SyntaxError, ValueError):
|
||||||
|
kwargs = {}
|
||||||
if s.args:
|
if s.args:
|
||||||
args = ast.literal_eval(s.args)
|
args = ast.literal_eval(s.args)
|
||||||
# single value won't eval to tuple, so:
|
# single value won't eval to tuple, so:
|
||||||
|
|||||||
Reference in New Issue
Block a user