Flagsmith / Flagsmith/flagsmith
Null-terminated query parameters cause server errors in the Core SDK endpoints
- Dominant language
- Python
- Stars
- 6.6k
- Forks
- 567
- Avg merge
- 1d 13h
- Merged PRs (30d)
- 121
Description
Example Sentry issue: [FLAGSMITH-API-3TZ](https://flagsmith.sentry.io/issues/4585843809/?referrer=github_integration)
```
ValueError: A string literal cannot contain NUL (0x00) characters.
(15 additional frame(s) were not displayed)
...
File "environments/identities/views.py", line 185, in get
.get_or_create(identifier=identifier, environment=request.environment)
```
This should be a problem for every view that accesses query parameters directly.
A quick search yields 8 occurences of this: https://github.com/search?q=repo%3AFlagsmith%2Fflagsmith+query_params.get&type=code
For each of those we need to assess the performance impact of using a serializer (DRF's `CharField` handles null chars).
Contributor guide
Assessment
This issue has not been assessed yet.