chore: Restrict "json" type deserialization (#6269)

- Rm untyped loads/dumps
- Restrict to an allow list

---------

Co-authored-by: Sydney Runkle <sydneymarierunkle@gmail.com>
This commit is contained in:
William FH
2025-10-20 10:18:36 -07:00
committed by GitHub
co-authored by Sydney Runkle
parent d298b489b4
commit c5744f583b
8 changed files with 143 additions and 172 deletions
+18 -3
View File
@@ -1,4 +1,5 @@
import dataclasses
import json
import pathlib
import re
import sys
@@ -19,6 +20,7 @@ from pydantic.v1 import BaseModel as BaseModelV1
from pydantic.v1 import SecretStr as SecretStrV1
from langgraph.checkpoint.serde.jsonplus import (
InvalidModuleError,
JsonPlusSerializer,
_msgpack_ext_hook_to_json,
)
@@ -160,10 +162,9 @@ def test_serde_jsonplus() -> None:
"Text\ud83d\udcac",
"收花🙄·到",
]
serde = JsonPlusSerializer(pickle_fallback=True)
assert serde.loads_typed(serde.dumps_typed(surrogates)) == [
v.encode("utf-8", "ignore").decode() for v in surrogates
]
assert serde.loads_typed(serde.dumps_typed(surrogates)) == surrogates
def test_serde_jsonplus_json_mode() -> None:
@@ -290,6 +291,20 @@ def test_serde_jsonplus_bytes() -> None:
assert serde.loads_typed(dumped) == some_bytes
def test_deserde_invalid_module() -> None:
serde = JsonPlusSerializer()
load = {
"lc": 2,
"type": "constructor",
"id": ["pprint", "pprint"],
"kwargs": {"object": "HELLO"},
}
with pytest.raises(InvalidModuleError):
serde._revive_lc2(load)
serde = JsonPlusSerializer(allowed_json_modules=[("pprint", "pprint")])
serde.loads_typed(("json", json.dumps(load).encode("utf-8")))
def test_serde_jsonplus_bytearray() -> None:
serde = JsonPlusSerializer()