summaryrefslogtreecommitdiff
path: root/django/template
diff options
context:
space:
mode:
Diffstat (limited to 'django/template')
-rw-r--r--django/template/loaders/app_directories.py9
-rw-r--r--django/template/loaders/filesystem.py11
2 files changed, 8 insertions, 12 deletions
diff --git a/django/template/loaders/app_directories.py b/django/template/loaders/app_directories.py
index b66adaed08..cab1edf8cc 100644
--- a/django/template/loaders/app_directories.py
+++ b/django/template/loaders/app_directories.py
@@ -8,6 +8,7 @@ import sys
from django.apps import apps
from django.conf import settings
+from django.core.exceptions import SuspiciousFileOperation
from django.template.base import TemplateDoesNotExist
from django.template.loader import BaseLoader
from django.utils._os import safe_join
@@ -47,11 +48,9 @@ class Loader(BaseLoader):
for template_dir in template_dirs:
try:
yield safe_join(template_dir, template_name)
- except UnicodeDecodeError:
- # The template dir name was a bytestring that wasn't valid UTF-8.
- raise
- except ValueError:
- # The joined path was located outside of template_dir.
+ except SuspiciousFileOperation:
+ # The joined path was located outside of this template_dir
+ # (it might be inside another one, so this isn't fatal).
pass
def load_template_source(self, template_name, template_dirs=None):
diff --git a/django/template/loaders/filesystem.py b/django/template/loaders/filesystem.py
index 52e41ef0b9..dc7de84abf 100644
--- a/django/template/loaders/filesystem.py
+++ b/django/template/loaders/filesystem.py
@@ -3,6 +3,7 @@ Wrapper for loading templates from the filesystem.
"""
from django.conf import settings
+from django.core.exceptions import SuspiciousFileOperation
from django.template.base import TemplateDoesNotExist
from django.template.loader import BaseLoader
from django.utils._os import safe_join
@@ -22,13 +23,9 @@ class Loader(BaseLoader):
for template_dir in template_dirs:
try:
yield safe_join(template_dir, template_name)
- except UnicodeDecodeError:
- # The template dir name was a bytestring that wasn't valid UTF-8.
- raise
- except ValueError:
- # The joined path was located outside of this particular
- # template_dir (it might be inside another one, so this isn't
- # fatal).
+ except SuspiciousFileOperation:
+ # The joined path was located outside of this template_dir
+ # (it might be inside another one, so this isn't fatal).
pass
def load_template_source(self, template_name, template_dirs=None):