-
-
Notifications
You must be signed in to change notification settings - Fork 32.5k
bpo-35121: prefix dot in domain for proper subdomain validation #10258
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Merged
Merged
Changes from 1 commit
Commits
Show all changes
7 commits
Select commit
Hold shift + click to select a range
d67d18e
Prefix domain with dot for proper subdomain validation in domain_retu…
tirkarthi 2816aa8
Add NEWS entry
tirkarthi dfdc776
Prefix dot only for suffix check and add test
tirkarthi ecae447
Reword news entry and added extra test
tirkarthi b2ab4a3
Refactor if clause and fix news entry
tirkarthi b8e2df1
Ensure return_ok_domain does proper validation
tirkarthi 9d1eed3
Move NEWS to security
tirkarthi File filter
Filter by extension
Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Next
Next commit
Prefix domain with dot for proper subdomain validation in domain_retu…
…rn_ok
- Loading branch information
commit d67d18e83ba60567f99135c73fd1229026436443
There are no files selected for viewing
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This will affect calls of
self.is_blocked(domain)
andself.is_not_allowed(domain)
below.There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks @serhiy-storchaka . My bad that I looked into fixing the issue and not about the underlying callers that use the dot-prefixed domain. Yes, adding the extra dot makes the comparison to fail where A has an extra dot at start due to my patch at https://github.com/python/cpython/blob/f30060dcd07cd53879226816512ea80bff0d0a78/Lib/http/cookiejar.py#L601 .
Sample program where the domain should be blocked
With patch this returns true but should be false since the domain is blocked and the prefix dot makes the comparison
.xxxfoo.co.jp == xxxfoo.co.jp
. One fix would be to use dot prefixed domain only for the checks athttps://github.com/python/cpython/blob/f30060dcd07cd53879226816512ea80bff0d0a78/Lib/http/cookiejar.py#L1178
I think this needs to be fixed but I am also afraid I might accidentally break something here since the function itself received no changes since 2004.