From 8e35f7aabda064aa30546fba7c9326bdd2539ca6 Mon Sep 17 00:00:00 2001 From: Emilian Schweikert Date: Wed, 19 Aug 2026 14:15:54 +0200 Subject: [PATCH 1/2] fix(dim): reject attribute names with colons on deletion - Prevent silent failure when a user mistakenly passes a colon-separated key-value pair to 'remove attrs' (e.g. 'remove attrs key:value') by raising an exception in 'WithAttr.delete_attrs'. - Add comprehensive unit/integration test coverage in 'dim-testsuite/tests/pool_test.py' to verify that trying to delete an attribute containing a colon raises an Exception. - Document this change in 'dim/CHANGES'. Co-authored-by: Gemini --- dim-testsuite/tests/pool_test.py | 4 ++++ dim/CHANGES | 1 + dim/dim/models/util.py | 3 +++ 3 files changed, 8 insertions(+) diff --git a/dim-testsuite/tests/pool_test.py b/dim-testsuite/tests/pool_test.py index 03f62485..190f98ed 100644 --- a/dim-testsuite/tests/pool_test.py +++ b/dim-testsuite/tests/pool_test.py @@ -110,6 +110,10 @@ def test_attrs(self): self.r.ippool_delete_attrs('pool_attrs', ['team']) assert 'team' not in self.r.ippool_get_attrs('pool_attrs') + # Test that deleting an attribute with a colon raises an exception + with raises(Exception): + self.r.ippool_delete_attrs('pool_attrs', ['team:value']) + assert self.r.ippool_get_attrs('control')['team'] == '1' assert 'country' not in self.r.ippool_get_attrs('control') diff --git a/dim/CHANGES b/dim/CHANGES index 1dc85a0e..b14ecd20 100644 --- a/dim/CHANGES +++ b/dim/CHANGES @@ -1,5 +1,6 @@ unreleased ---------- +* reject attribute names containing colons during deletion to prevent silent failure from incorrect key-value input * fix revoking attribute rights on pools when utilizing trailing dots or prefix strings * add support for ALIAS resource records (coexists with other types at zone apex, mutually exclusive with CNAME, disabled in DNSSEC-enabled zones) * add support for DNAME resource records according to RFC 6672 (prevents DNAME at zone apex, prevents records under DNAME subtrees) diff --git a/dim/dim/models/util.py b/dim/dim/models/util.py index 7654f540..2a00cb46 100644 --- a/dim/dim/models/util.py +++ b/dim/dim/models/util.py @@ -81,6 +81,9 @@ def delete_attrs(self, attribute_names): from .history import record_history if not attribute_names: return + for name in attribute_names: + if ':' in name: + raise Exception("Attribute name '%s' contains ':'. Did you mean to specify only the attribute name?" % name) current = self.AttrClass.query\ .filter_by(**{self.attr_backref: self})\ .join(self.AttrNameClass)\ From 644b50a3929f41ffb85d8a2b61039b4dce233ace Mon Sep 17 00:00:00 2001 From: Emilian Schweikert Date: Wed, 19 Aug 2026 15:20:47 +0200 Subject: [PATCH 2/2] test(dim): add CLI integration tests for pool attr rights and colon deletion - Add end-to-end CLI integration test cases in 'dim-testsuite/t/pool-list-rights.t' for pool attr rights trailing-dot revoke and prefix symmetry. - Add test case in 'dim-testsuite/t/pool-list-rights.t' for the new colon-rejection validation when removing attributes. Co-authored-by: Gemini --- dim-testsuite/t/pool-list-rights.t | 30 ++++++++++++++++++++++++++++++ 1 file changed, 30 insertions(+) diff --git a/dim-testsuite/t/pool-list-rights.t b/dim-testsuite/t/pool-list-rights.t index 1d65f505..50f734c0 100644 --- a/dim-testsuite/t/pool-list-rights.t +++ b/dim-testsuite/t/pool-list-rights.t @@ -18,6 +18,36 @@ action object group allocate some-pool all_users allocate some-pool testgroup +# Test granting and revoking attr rights (dot-suffix and prefix symmetry) +$ ndcli modify user-group testgroup grant attr audit some-pool +$ ndcli modify user-group testgroup grant attr audit. some-pool +$ ndcli list pool some-pool rights +action object group +allocate some-pool all_users +allocate some-pool testgroup +attr.audit some-pool testgroup +attr.audit. some-pool testgroup + +# Revoke using the short name without prefix or trailing dot +$ ndcli modify user-group testgroup revoke attr audit some-pool +$ ndcli list pool some-pool rights +action object group +allocate some-pool all_users +allocate some-pool testgroup +attr.audit. some-pool testgroup + +# Revoke using the full right name including dot +$ ndcli modify user-group testgroup revoke attr attr.audit. some-pool +$ ndcli list pool some-pool rights +action object group +allocate some-pool all_users +allocate some-pool testgroup + +# Test our second fix: warning/error on remove attrs with colon +$ ndcli modify pool some-pool set attrs mykey:myvalue +$ ndcli modify pool some-pool remove attrs mykey:myvalue +ERROR - Attribute name 'mykey:myvalue' contains ':'. Did you mean to specify only the attribute name? + $ ndcli modify pool some-pool remove subnet 10.0.0.0/24 INFO - Deleting zone 0.0.10.in-addr.arpa $ ndcli delete pool some-pool