| Commit message (Collapse) | Author | Age | Files | Lines | |
|---|---|---|---|---|---|
| * | bpo-26657: Fix Windows directory traversal vulnerability with http.server ↵ | Victor Stinner | 2017-07-26 | 1 | -3/+3 |
| | | | | | | | | | | (#782) (#2860) Based on patch by Philipp Hagemeister. This fixes a regression caused by revision f4377699fd47. (cherry picked from commit d274b3f1f1e2d8811733fb952c9f18d7da3a376a) (cherry picked from commit 6f6bc1da8aaae52664e7747e328d26eb59c0e74f) | ||||
| * | [3.3] bpo-22928: Disabled HTTP header injections in http.client. (#2817) | Serhiy Storchaka | 2017-07-26 | 1 | -0/+37 |
| | | | | | | Original patch by Demian Brecht.. (cherry picked from commit a112a8ae47813f75aa8ad27ee8c42a7c2e937d13) | ||||
| * | merge 3.2 (#22931) | Benjamin Peterson | 2015-05-23 | 1 | -3/+4 |
| |\ | |||||
| | * | allow square brackets in cookie values (closes #22931) | Benjamin Peterson | 2015-05-23 | 1 | -3/+4 |
| | | | |||||
| | * | Lax cookie parsing in http.cookies could be a security issue when combined | Antoine Pitrou | 2014-09-16 | 1 | -1/+2 |
| | | | | | | | | | | | | | with non-standard cookie handling in some Web browsers. Reported by Sergey Bobrov. | ||||
| | * | Issue #16037: HTTPMessage.readheaders() raises an HTTPException when more than | Georg Brandl | 2014-09-30 | 1 | -0/+4 |
| | | | | | | | | | 100 headers are read. Adapted from patch by Jyrki Pulliainen. | ||||
| * | | Lax cookie parsing in http.cookies could be a security issue when combined | Antoine Pitrou | 2014-09-16 | 1 | -1/+2 |
| | | | | | | | | | | | | | with non-standard cookie handling in some Web browsers. Reported by Sergey Bobrov. | ||||
| * | | Issue #21323: Fix http.server to again handle scripts in CGI subdirectories, | Ned Deily | 2014-07-13 | 1 | -5/+5 |
| |\ \ | |/ | | | | | broken by the fix for security issue #19435. Patch by Zach Byrne. | ||||
| | * | Issue #21323: Fix http.server to again handle scripts in CGI subdirectories, | Ned Deily | 2014-07-13 | 1 | -5/+5 |
| | | | | | | | | | broken by the fix for security issue #19435. Patch by Zach Byrne. | ||||
| * | | merge 3.2 (#21766) | Benjamin Peterson | 2014-06-15 | 1 | -1/+1 |
| |\ \ | |/ | |||||
| | * | url unquote the path before checking if it refers to a CGI script (closes ↵ | Benjamin Peterson | 2014-06-15 | 1 | -1/+1 |
| | | | | | | | | | #21766) | ||||
| * | | Issue #20331: Fixed possible FD leaks in various modules: | Serhiy Storchaka | 2014-01-25 | 1 | -9/+15 |
| | | | | | | | | | http.server, imghdr, mailcap, mimetypes, xml.etree. | ||||
| * | | fix handling of 100-continue status code (closes #18574) | Benjamin Peterson | 2014-01-19 | 1 | -1/+1 |
| | | | |||||
| * | | Issue #19936: Added executable bits or shebang lines to Python scripts which | Serhiy Storchaka | 2014-01-16 | 1 | -3/+0 |
| | | | | | | | | | | | | | | | requires them. Disable executable bits and shebang lines in test and benchmark files in order to prevent using a random system python, and in source files of modules which don't provide command line interface. Fixed shebang line to use python3 executable in the unittestgui script. | ||||
| * | | update url to spec (closes #20018) | Benjamin Peterson | 2013-12-18 | 1 | -1/+1 |
| | | | |||||
| * | | Issue #20007: HTTPResponse.read(0) no more prematurely closes connection. | Serhiy Storchaka | 2013-12-17 | 1 | -1/+1 |
| | | | | | | | | | Original patch by Simon Sapin. | ||||
| * | | merge 3.2 (#19435) | Benjamin Peterson | 2013-10-30 | 1 | -5/+4 |
| |\ \ | |/ | |||||
| | * | merge 3.1 (#19435) | Benjamin Peterson | 2013-10-30 | 1 | -5/+4 |
| | |\ | |||||
| | | * | use the collapsed path in the run_cgi method (closes #19435) | Benjamin Peterson | 2013-10-30 | 1 | -5/+4 |
| | | | | |||||
| * | | | Issue #16037: HTTPMessage.readheaders() raises an HTTPException when more than | Georg Brandl | 2013-10-27 | 1 | -0/+4 |
| | | | | | | | | | | | | | 100 headers are read. Adapted from patch by Jyrki Pulliainen. | ||||
| * | | | Minor code improvement. Review comment by Eric V. Smith | Senthil Kumaran | 2013-09-30 | 1 | -1/+1 |
| | | | | |||||
| * | | | Fix http.server's request handling case on trailing '/'. | Senthil Kumaran | 2013-09-13 | 1 | -0/+4 |
| | | | | | | | | | | | | | Patch contributed by Vajrasky Kok. Addresses Issue #17324 | ||||
| * | | | #16611: BaseCookie now parses 'secure' and 'httponly' flags. | R David Murray | 2013-08-25 | 1 | -10/+19 |
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Previously it generated them if they were given a value, but completely ignored them if they were present in the string passed in to be parsed. Now if the flag appears on a cookie, the corresponding Morsel key will reference a True value. Other pre-existing behavior is retained in this maintenance patch: if the source contains something like 'secure=foo', morsel['secure'] will return 'foo'. Since such a value doesn't round trip and never did (and would be a surprising occurrence) a subsequent non-bug-fix patch may change this behavior. Inspired by a patch from Julien Phalip, who reviewed this one. | ||||
| * | | | Issue #16658: add missing return to HTTPConnection.send(). | Andrew Svetlov | 2013-04-12 | 1 | -1/+1 |
| | | | | | | | | | | | | | Patch by Jeff Knupp | ||||
| * | | | #17678: Fix DeprecationWarning in the http/cookiejar.py by changing the usage | Senthil Kumaran | 2013-04-09 | 1 | -1/+1 |
| | | | | | | | | | | | | | | | | | | | of get_origin_req_host() to origin_req_host. Patch by Wei-Cheng Pan | ||||
| * | | | Reverting the changeset 5d76a4746d9d made for Issue #12921 | Senthil Kumaran | 2013-03-05 | 1 | -1/+1 |
| |\ \ \ | |/ / | |||||
| | * | | Reverting the changeset 5126e62c60af made for Issue #12921 | Senthil Kumaran | 2013-03-05 | 1 | -1/+1 |
| | | | | |||||
| * | | | Fix Issue #12921: BaseHTTPServer's send_error should send the correct error | Senthil Kumaran | 2013-03-05 | 1 | -1/+1 |
| |\ \ \ | |/ / | | | | | | | | | | response message when send_error includes a message in addition to error status. Patch contributed by Karl. | ||||
| | * | | Fix Issue #12921: BaseHTTPServer's send_error should send the correct error | Senthil Kumaran | 2013-03-05 | 1 | -1/+1 |
| | | | | | | | | | | | | | | | | response message when send_error includes a message in addition to error status. Patch contributed by Karl. | ||||
| * | | | Issue #16723: httplib.HTTPResponse no longer marked closed when the connection | Serhiy Storchaka | 2013-02-06 | 1 | -17/+21 |
| |\ \ \ | |/ / | | | | | | | is automatically closed. | ||||
| | * | | Issue #16723: httplib.HTTPResponse no longer marked closed when the connection | Serhiy Storchaka | 2013-02-06 | 1 | -15/+19 |
| | | | | | | | | | | | | | is automatically closed. | ||||
| | * | | Simplify code in HTTPResponse.read() | Antoine Pitrou | 2013-02-02 | 1 | -4/+1 |
| | | | | |||||
| * | | | Issue #15633: httplib.HTTPResponse is now mark closed when the server sends ↵ | Antoine Pitrou | 2013-02-02 | 1 | -5/+10 |
| |\ \ \ | |/ / | | | | | | | less than the advertised Content-Length. | ||||
| | * | | Issue #15633: httplib.HTTPResponse is now mark closed when the server sends ↵ | Antoine Pitrou | 2013-02-02 | 1 | -1/+9 |
| | | | | | | | | | | | | | less than the advertised Content-Length. | ||||
| * | | | Issue #16298: In HTTPResponse.read(), close the socket when there is no ↵ | Antoine Pitrou | 2012-12-15 | 1 | -0/+3 |
| |\ \ \ | |/ / | | | | | | | | | | | | | Content-Length and the incoming stream is finished. Patch by Eran Rundstein. | ||||
| | * | | Issue #16298: In HTTPResponse.read(), close the socket when there is no ↵ | Antoine Pitrou | 2012-12-15 | 1 | -0/+4 |
| | | | | | | | | | | | | | | | | | | | Content-Length and the incoming stream is finished. Patch by Eran Rundstein. | ||||
| * | | | #15980: merge with 3.2. | Ezio Melotti | 2012-09-21 | 1 | -2/+2 |
| |\ \ \ | |/ / | |||||
| | * | | #15980: properly escape newlines in docstrings. Patch by Serhiy Storchaka. | Ezio Melotti | 2012-09-21 | 1 | -2/+2 |
| | | | | |||||
| * | | | Issue #15409: Replace use of deprecated urllib.request.Request methods in ↵ | Meador Inge | 2012-07-21 | 1 | -4/+4 |
| | | | | | | | | | | | | | | | | | | | http.cookijar Patch by Flávio Ribeiro. | ||||
| * | | | Issue 14989: http.server --cgi option can enable the CGI http server. | Senthil Kumaran | 2012-06-03 | 1 | -7/+15 |
| | | | | |||||
| * | | | merge - Fix for issue14426 - buildbots here I come | Senthil Kumaran | 2012-05-20 | 1 | -1/+1 |
| |\ \ \ | |/ / | |||||
| | * | | Fix for issue14426 - buildbots here I come | Senthil Kumaran | 2012-05-20 | 1 | -1/+1 |
| | | | | |||||
| * | | | Issue #14426: Correct the Date format in Expires attribute of Set-Cookie. ↵ | Senthil Kumaran | 2012-05-20 | 1 | -1/+1 |
| |\ \ \ | |/ / | | | | | | | Patch by Federico Reghenzani and Müte Invert | ||||
| | * | | Issue #14426: Correct the Date format in Expires attribute of Set-Cookie. ↵ | Senthil Kumaran | 2012-05-20 | 1 | -1/+1 |
| | | | | | | | | | | | | | Patch by Federico Reghenzani and Müte Invert | ||||
| * | | | merge - Fix Issue14721: Send Content-length: 0 for empty body () in the ↵ | Senthil Kumaran | 2012-05-19 | 1 | -1/+1 |
| |\ \ \ | |/ / | | | | | | | http.client requests | ||||
| | * | | Fix Issue14721: Send Content-length: 0 for empty body () in the http.client ↵ | Senthil Kumaran | 2012-05-19 | 1 | -1/+1 |
| | | | | | | | | | | | | | requests | ||||
| * | | | #14809: Add HTTP status codes from RFC 6585 to http.server and http.client | Hynek Schlawack | 2012-05-16 | 2 | -1/+17 |
| | | | | | | | | | | | | | Patch by EungJun Yi. | ||||
| * | | | issue6085 - update docs in default branch | Senthil Kumaran | 2012-04-29 | 1 | -1/+1 |
| |\ \ \ | |/ / | |||||
| | * | | Fix issue6085 - Remove the delay caused by fqdn lookup while logging in ↵ | Senthil Kumaran | 2012-04-29 | 1 | -2/+2 |
| | | | | | | | | | | | | | BaseHTTPRequestHandler | ||||
| * | | | Fix Issue6085 - SimpleHTTPServer address_string to return client ip instead ↵ | Senthil Kumaran | 2012-04-29 | 1 | -11/+2 |
| | | | | | | | | | | | | | of client hostname | ||||
