| FazBrowse GitHub Viewer | Trending | | Home |
| Tools: [Download Repo ZIP] [Original HTTPS Page] |
Sorry, something went wrong.
…e and tabs. (pythonGH-25595) * issue43882 - urllib.parse should sanitize urls containing ASCII newline and tabs. Co-authored-by: Gregory P. Smith <greg@krypto.org> Co-authored-by: Serhiy Storchaka <storchaka@gmail.com> (cherry picked from commit 76cd81d) Co-authored-by: Senthil Kumaran <senthil@uthcode.com>
|
@orsenthil: Status check is done, and it's a success ✅ . |
Sorry, something went wrong.
|
@orsenthil: Status check is done, and it's a success ✅ . |
Sorry, something went wrong.
|
@orsenthil: Status check is done, and it's a failure ❌ . |
Sorry, something went wrong.
This goes to show that messing with security-critical code is a nasty
business and often a mistake. Luckily, we have tests, but what
happened here is that I tweaked the code to separate out checks from
redirection. In so doing, I removed pulled the quoting code into the
checks, but took it out of the redirection part. So previously, we'd
quote a URL before redirecting it, now we didn't.
To fix this, I copied the fix from Python's standard lib that you can
see here:
python/cpython#25725
Instead of quoting it, we just make sure it doesn't have newlines. If
it does, we bail.
…newline and tabs. (pythonGH-25595) (pythonGH-25725) * bpo-43882 - urllib.parse should sanitize urls containing ASCII newline and tabs. (pythonGH-25595) Co-authored-by: Gregory P. Smith <greg@krypto.org> Co-authored-by: Serhiy Storchaka <storchaka@gmail.com> (cherry picked from commit 76cd81d) Co-authored-by: Senthil Kumaran <skumaran@gatech.edu> (backported to Python 2.7 by Michał Górny)
| Back | FazBrowse Home | New Git URL |
Co-authored-by: Gregory P. Smith greg@krypto.org
Co-authored-by: Serhiy Storchaka storchaka@gmail.com
(cherry picked from commit 76cd81d)
Co-authored-by: Senthil Kumaran senthil@uthcode.com
https://bugs.python.org/issue43882