diff --git a/app/database/crud/user_message.py b/app/database/crud/user_message.py index 29159bf0..03960eff 100644 --- a/app/database/crud/user_message.py +++ b/app/database/crud/user_message.py @@ -6,7 +6,6 @@ from sqlalchemy import select, func, and_ from sqlalchemy.ext.asyncio import AsyncSession from app.database.models import User, UserMessage -from app.utils.validators import sanitize_html, validate_html_tags logger = logging.getLogger(__name__) @@ -18,10 +17,6 @@ async def create_user_message( is_active: bool = True, sort_order: int = 0 ) -> UserMessage: - is_valid, error_message = validate_html_tags(message_text) - if not is_valid: - raise ValueError(error_message) - resolved_creator = created_by if created_by is not None: @@ -66,7 +61,7 @@ async def get_random_active_message(db: AsyncSession) -> Optional[str]: return None random_message = random.choice(active_messages) - return sanitize_html(random_message.message_text) + return random_message.message_text async def get_all_user_messages( @@ -107,11 +102,8 @@ async def update_user_message( if not message: return None - + if message_text is not None: - is_valid, error_message = validate_html_tags(message_text) - if not is_valid: - raise ValueError(error_message) message.message_text = message_text if is_active is not None: diff --git a/app/handlers/admin/user_messages.py b/app/handlers/admin/user_messages.py index ceacd20a..61533c4d 100644 --- a/app/handlers/admin/user_messages.py +++ b/app/handlers/admin/user_messages.py @@ -12,11 +12,6 @@ from app.database.crud.user_message import ( ) from app.database.models import User from app.keyboards.admin import get_admin_main_keyboard -from app.utils.validators import ( - get_html_help_text, - sanitize_html, - validate_html_tags, -) from app.utils.decorators import admin_required, error_handler from app.localization.texts import get_texts @@ -127,6 +122,8 @@ async def add_user_message_start( db_user: User, db: AsyncSession ): + from app.utils.validators import get_html_help_text + await callback.message.edit_text( f"📝 Добавление нового сообщения\n\n" f"Введите текст сообщения, которое будет показываться в главном меню.\n\n" @@ -164,6 +161,8 @@ async def process_new_message_text( ) return + from app.utils.validators import validate_html_tags, get_html_help_text + is_valid, error_msg = validate_html_tags(message_text) if not is_valid: await message.answer( @@ -313,22 +312,20 @@ async def view_user_message( return message = await get_user_message_by_id(db, message_id) - + if not message: await callback.answer("❌ Сообщение не найдено", show_alert=True) return - - safe_content = sanitize_html(message.message_text) - + status_text = "🟢 Активно" if message.is_active else "🔴 Неактивно" - + text = ( f"📋 Сообщение ID {message.id}\n\n" f"Статус: {status_text}\n" f"Создано: {message.created_at.strftime('%d.%m.%Y %H:%M')}\n" f"Обновлено: {message.updated_at.strftime('%d.%m.%Y %H:%M')}\n\n" f"Содержимое:\n" - f"
{safe_content}" + f"
{message.message_text}" ) await callback.message.edit_text( @@ -458,7 +455,7 @@ async def edit_user_message_start( await callback.message.edit_text( f"✏️ Редактирование сообщения ID {message.id}\n\n" f"Текущий текст:\n" - f"
{sanitize_html(message.message_text)}\n\n" + f"
{message.message_text}\n\n" f"Введите новый текст сообщения или отправьте /cancel для отмены:", parse_mode="HTML" ) @@ -492,23 +489,14 @@ async def process_edit_message_text( return new_text = message.text.strip() - + if len(new_text) > 4000: await message.answer( "❌ Сообщение слишком длинное. Максимум 4000 символов.\n" "Попробуйте еще раз или отправьте /cancel для отмены." ) return - - is_valid, error_msg = validate_html_tags(new_text) - if not is_valid: - await message.answer( - f"❌ Ошибка в HTML разметке: {error_msg}\n\n" - f"Исправьте ошибку и попробуйте еще раз, или отправьте /cancel для отмены.", - parse_mode=None - ) - return - + try: updated_message = await update_user_message( db=db, @@ -523,7 +511,7 @@ async def process_edit_message_text( f"ID: {updated_message.id}\n" f"Обновлено: {updated_message.updated_at.strftime('%d.%m.%Y %H:%M')}\n\n" f"Новый текст:\n" - f"
{sanitize_html(new_text)}", + f"
{new_text}", reply_markup=get_user_messages_keyboard(db_user.language), parse_mode="HTML" ) diff --git a/app/utils/validators.py b/app/utils/validators.py index 78245c36..c63b5f71 100644 --- a/app/utils/validators.py +++ b/app/utils/validators.py @@ -123,19 +123,23 @@ def validate_subscription_period(days: Union[str, int]) -> Optional[int]: def sanitize_html(text: str) -> str: if not text: return text - + text = html.escape(text) - - allowed_tags = ALLOWED_HTML_TAGS.union(SELF_CLOSING_TAGS) - - for tag in allowed_tags: + + for tag in ALLOWED_HTML_TAGS: text = re.sub( - f'<(/?{tag}\\b[^>]*)>', - lambda m: html.unescape(f"<{m.group(1)}>"), - text, + f'<{tag}(>|\\s[^&]*>)', + lambda m: m.group(0).replace('<', '<').replace('>', '>'), + text, flags=re.IGNORECASE ) - + text = re.sub( + f'</{tag}>', + f'{tag}>', + text, + flags=re.IGNORECASE + ) + return text diff --git a/app/webapi/routes/user_messages.py b/app/webapi/routes/user_messages.py index 847cd1c0..d6fba008 100644 --- a/app/webapi/routes/user_messages.py +++ b/app/webapi/routes/user_messages.py @@ -69,16 +69,13 @@ async def create_user_message_endpoint( db: AsyncSession = Depends(get_db_session), ) -> UserMessageResponse: created_by = getattr(token, "id", None) - try: - message = await create_user_message( - db, - message_text=payload.message_text, - created_by=created_by, - is_active=payload.is_active, - sort_order=payload.sort_order, - ) - except ValueError as error: - raise HTTPException(status.HTTP_400_BAD_REQUEST, str(error)) from error + message = await create_user_message( + db, + message_text=payload.message_text, + created_by=created_by, + is_active=payload.is_active, + sort_order=payload.sort_order, + ) return _serialize(message) @@ -91,10 +88,7 @@ async def update_user_message_endpoint( db: AsyncSession = Depends(get_db_session), ) -> UserMessageResponse: update_payload = payload.dict(exclude_unset=True) - try: - message = await update_user_message(db, message_id, **update_payload) - except ValueError as error: - raise HTTPException(status.HTTP_400_BAD_REQUEST, str(error)) from error + message = await update_user_message(db, message_id, **update_payload) if not message: raise HTTPException(status.HTTP_404_NOT_FOUND, "User message not found")