fix: call validate_import_csv_rows in parse_export_format - #831
Closed
PRAteek-singHWY wants to merge 3 commits into
Closed
fix: call validate_import_csv_rows in parse_export_format#831PRAteek-singHWY wants to merge 3 commits into
PRAteek-singHWY wants to merge 3 commits into
Conversation
Contributor
Author
|
Hi @northdpole @Pa04rth Context: I previously worked on the CSV import validation path during MyOpenCRE ( |
AyeshaaRafaqat
added a commit
to AyeshaaRafaqat/OpenCRE
that referenced
this pull request
Aug 11, 2026
…e_import_csv_rows (OWASP#554) OWASP#682/OWASP#683 already landed the intended shared validator, spreadsheet_parsers.validate_import_csv_rows, but the live MyOpenCRE import path (myopencre_parser -> export_format_parser.parse_export_format) never called it, and this PR's own validate_cre_csv_rows duplicated the same check instead of reusing it. - Drop myopencre_parser.validate_cre_csv_rows; parse_rows_to_documents now calls spreadsheet_parsers.validate_import_csv_rows directly. - Tighten validate_import_csv_rows's CRE-cell check to XXX-XXX|Name so every caller gets the stricter format, not just MyOpenCRE imports. - Keep the web_main UTF-8 decode / triple-quote / csv.Error -> 400 guards on /rest/v1/cre_csv_import unchanged. - Move the CRE-cell format unit tests to spreadsheet_parsers_test.py, where the validator now lives; leave a thin wiring test in myopencre_parser_test.py proving parse_rows_to_documents delegates to the shared validator. web_main_test.py's HTTP 400 coverage is unchanged. Verified locally: black, mypy (no new errors vs. main baseline), targeted + full web_main_test.py suite (pre-existing unrelated Redis failures on gap-analysis endpoints aside), and a live run against /rest/v1/cre_csv_import with well-formed and malformed CSVs. OWASP#831 (NameError: validate_export_csv_rows) is now obsolete; already fixed on main by a different commit (89b1643).
AyeshaaRafaqat
added a commit
to AyeshaaRafaqat/OpenCRE
that referenced
this pull request
Aug 11, 2026
…e_import_csv_rows (OWASP#554) OWASP#682/OWASP#683 already landed the intended shared validator, spreadsheet_parsers.validate_import_csv_rows, but the live MyOpenCRE import path (myopencre_parser -> export_format_parser.parse_export_format) never called it, and this PR's own validate_cre_csv_rows duplicated the same check instead of reusing it. - Drop myopencre_parser.validate_cre_csv_rows; parse_rows_to_documents now calls spreadsheet_parsers.validate_import_csv_rows directly. - Tighten validate_import_csv_rows's CRE-cell check to XXX-XXX|Name so every caller gets the stricter format, not just MyOpenCRE imports. - Keep the web_main UTF-8 decode / triple-quote / csv.Error -> 400 guards on /rest/v1/cre_csv_import unchanged. - Move the CRE-cell format unit tests to spreadsheet_parsers_test.py, where the validator now lives; leave a thin wiring test in myopencre_parser_test.py proving parse_rows_to_documents delegates to the shared validator. web_main_test.py's HTTP 400 coverage is unchanged. Verified locally: black, mypy (no new errors vs. main baseline), targeted + full web_main_test.py suite (pre-existing unrelated Redis failures on gap-analysis endpoints aside), and a live run against /rest/v1/cre_csv_import with well-formed and malformed CSVs. OWASP#831 (NameError: validate_export_csv_rows) is now obsolete; already fixed on main by a different commit (89b1643).
northdpole
pushed a commit
that referenced
this pull request
Aug 18, 2026
…e_import_csv_rows (#554) #682/#683 already landed the intended shared validator, spreadsheet_parsers.validate_import_csv_rows, but the live MyOpenCRE import path (myopencre_parser -> export_format_parser.parse_export_format) never called it, and this PR's own validate_cre_csv_rows duplicated the same check instead of reusing it. - Drop myopencre_parser.validate_cre_csv_rows; parse_rows_to_documents now calls spreadsheet_parsers.validate_import_csv_rows directly. - Tighten validate_import_csv_rows's CRE-cell check to XXX-XXX|Name so every caller gets the stricter format, not just MyOpenCRE imports. - Keep the web_main UTF-8 decode / triple-quote / csv.Error -> 400 guards on /rest/v1/cre_csv_import unchanged. - Move the CRE-cell format unit tests to spreadsheet_parsers_test.py, where the validator now lives; leave a thin wiring test in myopencre_parser_test.py proving parse_rows_to_documents delegates to the shared validator. web_main_test.py's HTTP 400 coverage is unchanged. Verified locally: black, mypy (no new errors vs. main baseline), targeted + full web_main_test.py suite (pre-existing unrelated Redis failures on gap-analysis endpoints aside), and a live run against /rest/v1/cre_csv_import with well-formed and malformed CSVs. #831 (NameError: validate_export_csv_rows) is now obsolete; already fixed on main by a different commit (89b1643).
Collaborator
|
Closing — the branch has no diff (+0/−0). The fix appears already present on main or was addressed elsewhere. |
Bornunique911
pushed a commit
to Bornunique911/OpenCRE
that referenced
this pull request
Aug 20, 2026
…e_import_csv_rows (OWASP#554) OWASP#682/OWASP#683 already landed the intended shared validator, spreadsheet_parsers.validate_import_csv_rows, but the live MyOpenCRE import path (myopencre_parser -> export_format_parser.parse_export_format) never called it, and this PR's own validate_cre_csv_rows duplicated the same check instead of reusing it. - Drop myopencre_parser.validate_cre_csv_rows; parse_rows_to_documents now calls spreadsheet_parsers.validate_import_csv_rows directly. - Tighten validate_import_csv_rows's CRE-cell check to XXX-XXX|Name so every caller gets the stricter format, not just MyOpenCRE imports. - Keep the web_main UTF-8 decode / triple-quote / csv.Error -> 400 guards on /rest/v1/cre_csv_import unchanged. - Move the CRE-cell format unit tests to spreadsheet_parsers_test.py, where the validator now lives; leave a thin wiring test in myopencre_parser_test.py proving parse_rows_to_documents delegates to the shared validator. web_main_test.py's HTTP 400 coverage is unchanged. Verified locally: black, mypy (no new errors vs. main baseline), targeted + full web_main_test.py suite (pre-existing unrelated Redis failures on gap-analysis endpoints aside), and a live run against /rest/v1/cre_csv_import with well-formed and malformed CSVs. OWASP#831 (NameError: validate_export_csv_rows) is now obsolete; already fixed on main by a different commit (89b1643).
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Fixes a runtime regression in CSV import parsing.
parse_export_format()currently callsvalidate_export_csv_rows(...), but the validator defined inspreadsheet_parsers.pyisvalidate_import_csv_rows(...).This causes:
NameError: name 'validate_export_csv_rows' is not definedContext
This validation flow was already introduced during the MyOpenCRE work, where CSV import validation logic was moved into
spreadsheet_parsers.pyviavalidate_import_csv_rows(see discussion in#584comment and related work in#682/#683).This PR is a focused follow-up to restore that intended path on latest
main.Change
application/utils/spreadsheet_parsers.py:validate_export_csv_rows(lfile)->validate_import_csv_rows(lfile)Validation
./venv/bin/python -m pytest application/tests/spreadsheet_parsers_test.py -q2 passedScope