Description
A request parameter retrieved with .get() may be None when it is absent. Calling a method on that value or calculating its length without checking it raises an exception.
Potential impact
- Omitting a required parameter may cause service errors or denial of service.
- Debug settings may expose internal information when the error occurs.
Remediation
- Check the
.get()result withis not None, or provide a suitable default before using it. - Declare required request values in the framework's validation layer.
Examples
These excerpts belong inside a request-handling function.
Before
python
filename = request.POST.get("filename")
return filename.count(".")
After
python
filename = request.POST.get("filename")
if filename is not None:
return filename.count(".")
return 0
Explanation:
- Before: A value from
request.POST.get()may beNonewhen missing. Using it for method calls, attribute access or length calculations without a check raises an exception. - After: Checks the
.get()result before using it. A suitable default is another option.