OWASP/Nest

Repositories static sitemap lastmod always uses current time instead of latest repository update

开放

#5,259 创建于 2026年7月20日

 (2 条评论) (0 个反应) (0 位负责人)Python (651 个派生)auto 404
good first issue

仓库指标

星标
 (412 个星标)
PR 合并指标
 (平均合并 2天 12小时) (30 天内合并 128 个 PR)

描述

Describe the bug

StaticSitemap.lastmod (backend/src/apps/sitemap/views/static.py) maps each static route to a model so it can compute lastmod from that model's most recent updated_at. The /repositories route is listed in BaseSitemap.STATIC_ROUTES but is missing from the path_to_model mapping, so it falls through to the datetime.now(UTC) fallback that is meant for unknown paths.

As a result, the /repositories entry in the static sitemap reports the current time as its lastmod on every regeneration, instead of the latest repository update like the other seven routes.

To Reproduce

Steps to reproduce the behavior:

  1. Generate the static sitemap.
  2. Compare the <lastmod> value for /repositories against /chapters, /projects, etc.
  3. /repositories shows the regeneration timestamp, while the other routes show their model's latest updated_at.

Expected behavior

/repositories should derive its lastmod from the most recently updated Repository (Repository.objects.aggregate(Max("updated_at"))), consistent with the other content routes. The datetime.now(UTC) fallback is only intended for paths that have no corresponding model (the existing test covers this with /unknown-path).

Additional context

The fix is to add "/repositories": Repository to the path_to_model dict (and import the model). A test asserting that every STATIC_ROUTES path maps to a model would prevent this from regressing.

Are you going to work on fixing this?

  • Yes
  • No

贡献者指南