Open the importer kind to third parties, once the file refusals belong to the kind #105
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Depends on
#99 Europass becomes an internal plugin
Postulo/postulo
Reference
Postulo/postulo#105
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why this is separate
#99 makes Europass an internal plugin and stops there, deliberately — the third-party surface
was the larger half of that issue and none of it is needed to get Europass out of
resume/views.pyand into the registry.This is the rest: telling anybody else they may write one.
What is left to do
Not much, if #99 lands as narrowed:
ImporterPluginprotocol, so_load_third_party'sisinstancecheck has somethingto check against. Built-ins skip that check; third parties do not.
docs/PLUGINS.mdwith the contract:can_handle(data, filename),read(data) -> Record, and the identity fields from #97.postulo-helloworldalready ships asource and a notifier, and a third example may be more use as a separate repository.
The prerequisite, which #99 should already have handled
An importer is handed a file somebody uploaded, which is not the threat a source faces —
a source gets a URL and HTML that Postulo fetched itself.
europass.pyrefuses a DOCTYPEbefore parsing, "because a DOCTYPE is where entity expansion lives, and the point is to
refuse it rather than to hand it to a parser and hope", and caps the file at
MAX_BYTES.Those refusals belong to the kind, enforced before a plugin sees a byte. A third-party
importer that forgot the DOCTYPE check would be an XXE hole in an application holding
people's CVs, and "every plugin author remembers" is not a control.
Check this is true before advertising the group. #99 is asked to move them; if it did
not, this issue does it first and nothing else.
Worth having at all?
Yes, and the argument is the one the plugin system was built on. Europass is not the last CV
format: JSON Resume, HR-XML, a LinkedIn export, a PDF somebody wants parsed. Each is
somebody else's itch, and
registry.pyputs it as "the person who cares about a particularjob board... should not have to wait for this project to accept a patch".
Classification
Enhancement. Depends on #99. On 0.4.0 rather than 0.3.0 to keep the release simple, which is
the point of narrowing #99 in the first place.