From aa0b1a2e52b817c8a6014e360fcdf47aa1d33015 Mon Sep 17 00:00:00 2001 From: Ilia Tetin Date: Wed, 26 Mar 2025 19:15:33 +0000 Subject: server: prevent cache key collision for unsafe posts --- server/szurubooru/search/configs/post_search_config.py | 5 +++++ server/szurubooru/search/executor.py | 5 ++++- 2 files changed, 9 insertions(+), 1 deletion(-) (limited to 'server') diff --git a/server/szurubooru/search/configs/post_search_config.py b/server/szurubooru/search/configs/post_search_config.py index 5bf95d7..222718e 100644 --- a/server/szurubooru/search/configs/post_search_config.py +++ b/server/szurubooru/search/configs/post_search_config.py @@ -341,6 +341,11 @@ class PostSearchConfig(BaseSearchConfig): ) return query.order_by(model.Post.post_id.desc()) + + @property + def can_list_unsafe(self) -> bool: + return self.user and auth.has_privilege(self.user, "posts:list:unsafe") + @property def id_column(self) -> SaColumn: return model.Post.post_id diff --git a/server/szurubooru/search/executor.py b/server/szurubooru/search/executor.py index 5302b14..bf95cc0 100644 --- a/server/szurubooru/search/executor.py +++ b/server/szurubooru/search/executor.py @@ -95,7 +95,10 @@ class Executor: if token.name == "random": disable_eager_loads = True - key = (id(self.config), hash(search_query), offset, limit) + + can_list_unsafe = getattr(self.config, "can_list_unsafe", False) + + key = (id(self.config), hash(search_query), offset, limit, can_list_unsafe) if not disable_eager_loads and cache.has(key): return cache.get(key) -- cgit v1.3