Dereferencing a value before checking for None

Dereferencing a value before checking for None

Description

A request parameter retrieved with .get() may be None when it is absent. Calling a method on that value or calculating its length without checking it raises an exception.

Potential impact

  • Omitting a required parameter may cause service errors or denial of service.
  • Debug settings may expose internal information when the error occurs.

Remediation

  • Check the .get() result with is not None, or provide a suitable default before using it.
  • Declare required request values in the framework's validation layer.

Examples

These excerpts belong inside a request-handling function.

Before

python
filename = request.POST.get("filename")
return filename.count(".")

After

python
filename = request.POST.get("filename")
if filename is not None:
    return filename.count(".")
return 0

Explanation:

  • Before: A value from request.POST.get() may be None when missing. Using it for method calls, attribute access or length calculations without a check raises an exception.
  • After: Checks the .get() result before using it. A suitable default is another option.

References