Skip to content
Projeler
Gruplar
Parçacıklar
Yardım
Yükleniyor...
Oturum aç / Kaydol
Gezinmeyi değiştir
C
cpython
Proje
Proje
Ayrıntılar
Etkinlik
Cycle Analytics
Depo (repository)
Depo (repository)
Dosyalar
Kayıtlar (commit)
Dallar (branch)
Etiketler
Katkıda bulunanlar
Grafik
Karşılaştır
Grafikler
Konular (issue)
0
Konular (issue)
0
Liste
Pano
Etiketler
Kilometre Taşları
Birleştirme (merge) Talepleri
0
Birleştirme (merge) Talepleri
0
CI / CD
CI / CD
İş akışları (pipeline)
İşler
Zamanlamalar
Grafikler
Paketler
Paketler
Wiki
Wiki
Parçacıklar
Parçacıklar
Üyeler
Üyeler
Collapse sidebar
Close sidebar
Etkinlik
Grafik
Grafikler
Yeni bir konu (issue) oluştur
İşler
Kayıtlar (commit)
Konu (issue) Panoları
Kenar çubuğunu aç
Batuhan Osman TASKAYA
cpython
Commits
079381d2
Kaydet (Commit)
079381d2
authored
Mar 29, 2011
tarafından
Guido van Rossum
Dosyalara gözat
Seçenekler
Dosyalara Gözat
İndir
Sade Fark
Merge issue 11662 from 2.5.
üst
af1fee06
92ecb873
Hide whitespace changes
Inline
Side-by-side
Showing
5 changed files
with
60 additions
and
13 deletions
+60
-13
test_urllib.py
Lib/test/test_urllib.py
+14
-0
test_urllib2.py
Lib/test/test_urllib2.py
+21
-0
urllib.py
Lib/urllib.py
+12
-0
urllib2.py
Lib/urllib2.py
+11
-0
NEWS
Misc/NEWS
+2
-13
No files found.
Lib/test/test_urllib.py
Dosyayı görüntüle @
079381d2
...
@@ -162,6 +162,20 @@ Content-Type: text/html; charset=iso-8859-1
...
@@ -162,6 +162,20 @@ Content-Type: text/html; charset=iso-8859-1
finally
:
finally
:
self
.
unfakehttp
()
self
.
unfakehttp
()
def
test_invalid_redirect
(
self
):
# urlopen() should raise IOError for many error codes.
self
.
fakehttp
(
"""HTTP/1.1 302 Found
Date: Wed, 02 Jan 2008 03:03:54 GMT
Server: Apache/1.3.33 (Debian GNU/Linux) mod_ssl/2.8.22 OpenSSL/0.9.7e
Location: file:README
Connection: close
Content-Type: text/html; charset=iso-8859-1
"""
)
try
:
self
.
assertRaises
(
IOError
,
urllib
.
urlopen
,
"http://python.org/"
)
finally
:
self
.
unfakehttp
()
def
test_empty_socket
(
self
):
def
test_empty_socket
(
self
):
# urlopen() raises IOError if the underlying socket does not send any
# urlopen() raises IOError if the underlying socket does not send any
# data. (#1680230)
# data. (#1680230)
...
...
Lib/test/test_urllib2.py
Dosyayı görüntüle @
079381d2
...
@@ -942,6 +942,27 @@ class HandlerTests(unittest.TestCase):
...
@@ -942,6 +942,27 @@ class HandlerTests(unittest.TestCase):
self
.
assertEqual
(
count
,
self
.
assertEqual
(
count
,
urllib2
.
HTTPRedirectHandler
.
max_redirections
)
urllib2
.
HTTPRedirectHandler
.
max_redirections
)
def
test_invalid_redirect
(
self
):
from_url
=
"http://example.com/a.html"
valid_schemes
=
[
'http'
,
'https'
,
'ftp'
]
invalid_schemes
=
[
'file'
,
'imap'
,
'ldap'
]
schemeless_url
=
"example.com/b.html"
h
=
urllib2
.
HTTPRedirectHandler
()
o
=
h
.
parent
=
MockOpener
()
req
=
Request
(
from_url
)
for
scheme
in
invalid_schemes
:
invalid_url
=
scheme
+
'://'
+
schemeless_url
self
.
assertRaises
(
urllib2
.
HTTPError
,
h
.
http_error_302
,
req
,
MockFile
(),
302
,
"Security Loophole"
,
MockHeaders
({
"location"
:
invalid_url
}))
for
scheme
in
valid_schemes
:
valid_url
=
scheme
+
'://'
+
schemeless_url
h
.
http_error_302
(
req
,
MockFile
(),
302
,
"That's fine"
,
MockHeaders
({
"location"
:
valid_url
}))
self
.
assertEqual
(
o
.
req
.
get_full_url
(),
valid_url
)
def
test_cookie_redirect
(
self
):
def
test_cookie_redirect
(
self
):
# cookies shouldn't leak into redirected requests
# cookies shouldn't leak into redirected requests
from
cookielib
import
CookieJar
from
cookielib
import
CookieJar
...
...
Lib/urllib.py
Dosyayı görüntüle @
079381d2
...
@@ -652,6 +652,18 @@ class FancyURLopener(URLopener):
...
@@ -652,6 +652,18 @@ class FancyURLopener(URLopener):
fp
.
close
()
fp
.
close
()
# In case the server sent a relative URL, join with original:
# In case the server sent a relative URL, join with original:
newurl
=
basejoin
(
self
.
type
+
":"
+
url
,
newurl
)
newurl
=
basejoin
(
self
.
type
+
":"
+
url
,
newurl
)
# For security reasons we do not allow redirects to protocols
# other than HTTP, HTTPS or FTP.
newurl_lower
=
newurl
.
lower
()
if
not
(
newurl_lower
.
startswith
(
'http://'
)
or
newurl_lower
.
startswith
(
'https://'
)
or
newurl_lower
.
startswith
(
'ftp://'
)):
raise
IOError
(
'redirect error'
,
errcode
,
errmsg
+
" - Redirection to url '
%
s' is not allowed"
%
newurl
,
headers
)
return
self
.
open
(
newurl
)
return
self
.
open
(
newurl
)
def
http_error_301
(
self
,
url
,
fp
,
errcode
,
errmsg
,
headers
,
data
=
None
):
def
http_error_301
(
self
,
url
,
fp
,
errcode
,
errmsg
,
headers
,
data
=
None
):
...
...
Lib/urllib2.py
Dosyayı görüntüle @
079381d2
...
@@ -578,6 +578,17 @@ class HTTPRedirectHandler(BaseHandler):
...
@@ -578,6 +578,17 @@ class HTTPRedirectHandler(BaseHandler):
newurl
=
urlparse
.
urljoin
(
req
.
get_full_url
(),
newurl
)
newurl
=
urlparse
.
urljoin
(
req
.
get_full_url
(),
newurl
)
# For security reasons we do not allow redirects to protocols
# other than HTTP, HTTPS or FTP.
newurl_lower
=
newurl
.
lower
()
if
not
(
newurl_lower
.
startswith
(
'http://'
)
or
newurl_lower
.
startswith
(
'https://'
)
or
newurl_lower
.
startswith
(
'ftp://'
)):
raise
HTTPError
(
newurl
,
code
,
msg
+
" - Redirection to url '
%
s' is not allowed"
%
newurl
,
headers
,
fp
)
# XXX Probably want to forget about the state of the current
# XXX Probably want to forget about the state of the current
# request, although that might interact poorly with other
# request, although that might interact poorly with other
# handlers that also use handler-specific request attributes
# handlers that also use handler-specific request attributes
...
...
Misc/NEWS
Dosyayı görüntüle @
079381d2
...
@@ -19,19 +19,8 @@ Core and Builtins
...
@@ -19,19 +19,8 @@ Core and Builtins
Library
Library
-------
-------
- Issue #9129: smtpd.py is vulnerable to DoS attacks deriving from missing
- Issue #11662: Make urllib and urllib2 ignore redirections if the
error handling when accepting a new connection.
scheme is not HTTP, HTTPS or FTP (CVE-2011-1521).
What's New in Python 2.6.6?
===========================
*Release date: 2010-08-24*
Core and Builtins
-----------------
Library
-------
What's New in Python 2.6.6 rc 2?
What's New in Python 2.6.6 rc 2?
...
...
Write
Preview
Markdown
is supported
0%
Try again
or
attach a new file
Attach a file
Cancel
You are about to add
0
people
to the discussion. Proceed with caution.
Finish editing this message first!
Cancel
Please
register
or
sign in
to comment