Europass: find out what the platform exports today, and read it #244
Labels
No labels
accessibility
authentication
breaking change
bug
documentation
enhancement
interface
internationalisation
observability
security
tier
1
tier
2
tier
3
tier/4
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
Postulo/postulo#244
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Split out of #235, whose last bullet was a research task rather than a fix. #235 did the
three concrete things (levels left unset,
record_languagefrom the file's locale,translated group labels) and deliberately left this one alone, because half-building a
reader against a format nobody here has seen is worse than not having one.
What we actually know
reader.readsniffs on the first non-whitespace byte:<is XML,{is JSON, anythingelse is refused with a message naming the two formats.
read_xmlrefuses anything with noLearnerInfoelement;read_jsonacceptsSkillsPassport.LearnerInfoor a bareLearnerInfo.tests/data/are SkillsPassport. Neither came from europass.europa.euthis year.
%.What is plausible and unverified
The audit's claim is that today's Europass editor exports HR-Open Candidate XML, or a
PDF with the XML embedded, rather than SkillsPassport. Nobody has checked. If it is true,
"import your Europass CV" is a promise Postulo does not keep for anybody who made their CV
this year, and the refusal message tells them their own export is not a Europass file.
What to do first, before writing any code
Make a Europass CV on europass.europa.eu and download it in every format the Download
menu offers. Commit each as a fixture with the personal details replaced, the way
tests/data/europass.xmlalready is, and say in the file's comment what produced it andwhen — that comment is the thing that stops the next person guessing again.
Then, depending on what came back
Your career record, and close this.
importing.Record, which is whatthe
Recordshape exists for (#129). It cannot sniff on the first byte, since it is XMLtoo, so
read_xmlgrows a look at the root element's local name and dispatches; therefusal message then has to name three formats rather than two.
An embedded file lives in
/Names /EmbeddedFilesand reaching it means parsing PDFstructure, which Postulo has no dependency for today (WeasyPrint writes and never reads).
Adding one is a supply-chain decision, and it is an untrusted-input decision besides: the
uploaded file is a stranger's, so whatever is added has to be held to the same rules as
the rest of the importer kind — the size cap before parsing, no object-stream bomb, and
refuse_unreadableon what comes out of the attachment as well as on what went in,because the payload is a second file.
Also worth settling while looking
Whether the editor's PDF has any machine-readable payload at all any more. If it does not,
the upload form should say which file to choose rather than leaving somebody to find out by
being refused;
accept=".xml,.json,…"on the input already hints at it, and the sentenceabove it does not.