From 817cb25055904fbb06d7749e01f5a0c5b43e8ceb Mon Sep 17 00:00:00 2001 From: Sharadhi V Date: Mon, 5 Oct 2026 17:09:27 +0530 Subject: [PATCH] Reject path-like locale names in Locale.load --- src/pendulum/locales/locale.py | 4 ++++ tests/test_helpers.py | 6 ++++++ 2 files changed, 10 insertions(+) diff --git a/src/pendulum/locales/locale.py b/src/pendulum/locales/locale.py index 951ba8be6..2b70a4734 100644 --- a/src/pendulum/locales/locale.py +++ b/src/pendulum/locales/locale.py @@ -32,6 +32,10 @@ def load(cls, locale: str | Locale) -> Locale: if locale in cls._cache: return cls._cache[locale] + # A locale is a package name, not a path + if not re.fullmatch("[a-z]+(_[a-z0-9]+)*", locale): + raise ValueError(f"Locale [{locale}] does not exist.") + # Checking locale existence actual_locale = locale locale_path = cast(Path, resources.files(__package__).joinpath(actual_locale)) diff --git a/tests/test_helpers.py b/tests/test_helpers.py index a96604954..4bab1f402 100644 --- a/tests/test_helpers.py +++ b/tests/test_helpers.py @@ -160,6 +160,12 @@ def test_set_locale_malformed_locale(locale: str) -> None: pendulum.set_locale("en") +@pytest.mark.parametrize("locale", ["..", "../tz", "en/../en"]) +def test_set_locale_path_is_invalid(locale: str) -> None: + with pytest.raises(ValueError): + pendulum.set_locale(locale) + + def test_week_starts_at() -> None: pendulum.week_starts_at(pendulum.SATURDAY)