summaryrefslogtreecommitdiffstats
path: root/Lib/http
Commit message (Collapse)AuthorAgeFilesLines
* merge 3.4 (#22931)Benjamin Peterson2015-05-231-3/+4
|\
| * merge 3.3 (#22931)Benjamin Peterson2015-05-231-3/+4
| |\
| | * merge 3.2 (#22931)Benjamin Peterson2015-05-231-3/+4
| | |\
| | | * allow square brackets in cookie values (closes #22931)Benjamin Peterson2015-05-231-3/+4
| | | |
| | | * Lax cookie parsing in http.cookies could be a security issue when combinedAntoine Pitrou2014-09-161-1/+2
| | | | | | | | | | | | | | | | | | | | | | | | with non-standard cookie handling in some Web browsers. Reported by Sergey Bobrov.
| | | * Issue #16037: HTTPMessage.readheaders() raises an HTTPException when more thanGeorg Brandl2014-09-301-0/+4
| | | | | | | | | | | | | | | | 100 headers are read. Adapted from patch by Jyrki Pulliainen.
* | | | Issue #23865: close() methods in multiple modules now are idempotent and moreSerhiy Storchaka2015-04-101-9/+15
|\ \ \ \ | |/ / / | | | | | | | | | | | | robust at shutdown. If needs to release multiple resources, they are released even if errors are occured.
| * | | Issue #23865: close() methods in multiple modules now are idempotent and moreSerhiy Storchaka2015-04-101-9/+15
| | | | | | | | | | | | | | | | | | | | robust at shutdown. If needs to release multiple resources, they are released even if errors are occured.
* | | | #3566: Clean up handling of remote server disconnects.R David Murray2015-04-051-7/+20
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | This changeset does two things: introduces a new RemoteDisconnected exception (that subclasses ConnectionResetError and BadStatusLine) so that a remote server disconnection can be detected by client code (and provides a better error message for debugging purposes), and ensures that the client socket is closed if a ConnectionError happens, so that the automatic re-connection code can work if the application handles the error and continues on. Tests are added that confirm that a connection is re-used or not re-used as appropriate to the various combinations of protocol version and headers. Patch by Martin Panter, reviewed by Demian Brecht. (Tweaked only slightly by me.)
* | | | Issue #22831: Use "with" to avoid possible fd leaks.Serhiy Storchaka2015-04-041-1/+0
| | | |
* | | | #2211: properly document the Morsel behavior changes.R David Murray2015-03-291-1/+8
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Also deprecate the undocumented set argument instead of removing it already in 3.5. Initial patch by Demian Brecht.
* | | | Merge: #23539: Set Content-Length to 0 for PUT, POST, and PATCH if body is None.R David Murray2015-03-221-13/+24
|\ \ \ \ | |/ / /
| * | | #23539: Set Content-Length to 0 for PUT, POST, and PATCH if body is None.R David Murray2015-03-221-13/+24
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Some http servers will reject PUT, POST, and PATCH requests if they do not have a Content-Length header. Patch by James Rutherford, with additional cleaning up of the 'request' documentation by me.
* | | | Restored backward compatibility of pickling http.cookies.Morsel. It wasSerhiy Storchaka2015-03-181-0/+12
| | | | | | | | | | | | | | | | broken after converting instance attributes to properies in issue #2211.
* | | | Issue #2211: Updated the implementation of the http.cookies.Morsel class.Serhiy Storchaka2015-03-181-86/+94
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | Setting attributes key, value and coded_value directly now is deprecated. update() and setdefault() now transform and check keys. Comparing for equality now takes into account attributes key, value and coded_value. copy() now returns a Morsel, not a dict. repr() now contains all attributes. Optimized checking keys and quoting values. Added new tests. Original patch by Demian Brecht.
* | | | Issue #23138: Fixed parsing cookies with absent keys or values in cookiejar.Serhiy Storchaka2015-03-131-15/+31
|\ \ \ \ | |/ / / | | | | | | | | Patch by Demian Brecht.
| * | | Issue #23138: Fixed parsing cookies with absent keys or values in cookiejar.Serhiy Storchaka2015-03-131-15/+31
| | | | | | | | | | | | | | | | Patch by Demian Brecht.
* | | | Issue #22928: Disabled HTTP header injections in http.client.Serhiy Storchaka2015-03-121-0/+37
|\ \ \ \ | |/ / / | | | | | | | | Original patch by Demian Brecht.
| * | | Issue #22928: Disabled HTTP header injections in http.client.Serhiy Storchaka2015-03-121-0/+37
| | | | | | | | | | | | | | | | Original patch by Demian Brecht.
* | | | Issue #21793: BaseHTTPRequestHandler again logs response code as numeric,Serhiy Storchaka2015-03-071-1/+2
| | | | | | | | | | | | | | | | not as stringified enum. Patch by Demian Brecht.
* | | | Issue #23442: Rename two member names to stay backward compatibleBerker Peksag2015-02-201-4/+4
| | | | | | | | | | | | | | | | | | | | | | | | with the constants in http.client. Initial patch by Demian Brecht.
* | | | Issue #23439: Add missing entries to http.client.__all__.Berker Peksag2015-02-201-1/+3
|\ \ \ \ | |/ / / | | | | | | | | | | | | | | | | | | | | Also, document the LineTooLong exception since it can be raised by the members of public API (e.g. http.client.HTTPResponse). Patch by Martin Panter.
| * | | Issue #23439: Add missing entries to http.client.__all__.Berker Peksag2015-02-201-1/+3
| | | | | | | | | | | | | | | | | | | | | | | | | | | | Also, document the LineTooLong exception since it can be raised by the members of public API (e.g. http.client.HTTPResponse). Patch by Martin Panter.
* | | | merge 3.4 (#23410)Benjamin Peterson2015-02-181-10/+10
|\ \ \ \ | |/ / /
| * | | document the requestline and close_connection attributes, use real booleans, ↵Benjamin Peterson2015-02-181-10/+10
| | | | | | | | | | | | | | | | | | | | | | | | and add tests (closes #23410) Patch by Martin Panter.
* | | | Issue #23418: Add missing entries to http.server.__all__.Berker Peksag2015-02-131-1/+4
|\ \ \ \ | |/ / / | | | | | | | | Patch by Martin Panter.
| * | | Issue #23418: Add missing entries to http.server.__all__.Berker Peksag2015-02-131-1/+4
| | | | | | | | | | | | | | | | Patch by Martin Panter.
* | | | Issue #13128: Print response headers for CONNECT requests when debuglevel > 0.Berker Peksag2015-02-031-0/+3
| | | | | | | | | | | | | | | | Patch by Demian Brecht.
* | | | http.client: disable Nagle's algorithm (closes #23302)Benjamin Peterson2015-01-231-21/+4
| | | | | | | | | | | | | | | | Patch by Demian Brecht.
* | | | Issue #20898: Add a "HTTP status codes" section to avoid duplication in HTTP ↵Berker Peksag2015-01-201-30/+0
| | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | | docs. This commit also removes a couple of non-standard status codes. They were added as part of edf669b13482, so there is no backwards compatibility issue. Patch by Demian Brecht.
* | | | merge 3.4 (#22986)Benjamin Peterson2015-01-171-2/+2
|\ \ \ \ | |/ / /
| * | | capitialize "HttpOnly" and "Secure" as they appear in the standard and other ↵Benjamin Peterson2015-01-171-2/+2
| | | | | | | | | | | | | | | | | | | | | | | | impls (closes #23250) Patch by Jon Dufresne.
* | | | merge 3.4 (#23221)Benjamin Peterson2015-01-131-1/+1
|\ \ \ \ | |/ / /
| * | | fix instances of consecutive articles (closes #23221)Benjamin Peterson2015-01-131-1/+1
| | | | | | | | | | | | | | | | Patch by Karan Goel.
* | | | merge 3.4 (#23112)Benjamin Peterson2014-12-261-2/+6
|\ \ \ \ | |/ / /
| * | | fix behavior of trailing slash redirection when a query string is involved ↵Benjamin Peterson2014-12-261-2/+6
| | | | | | | | | | | | | | | | (closes #23112)
* | | | Issue #21793: Added http.HTTPStatus enums (i.e. HTTPStatus.OK,Serhiy Storchaka2014-12-233-215/+225
| | | | | | | | | | | | | | | | HTTPStatus.NOT_FOUND). Patch by Demian Brecht.
* | | | Issue #22095: Fixed HTTPConnection.set_tunnel with default port. The portSerhiy Storchaka2014-12-121-5/+3
|\ \ \ \ | |/ / / | | | | | | | | value in the host header was set to "None". Patch by Demian Brecht.
| * | | Issue #22095: Fixed HTTPConnection.set_tunnel with default port. The portSerhiy Storchaka2014-12-121-5/+3
| | | | | | | | | | | | | | | | value in the host header was set to "None". Patch by Demian Brecht.
* | | | merge 3.4 (#22959)Benjamin Peterson2014-12-071-2/+2
|\ \ \ \ | |/ / /
| * | | HTTPSConnection: prefer the context's check_hostname attribute over the ↵Benjamin Peterson2014-12-071-2/+2
| | | | | | | | | | | | | | | | constructor parameter (#22959)
* | | | Issue #21032. Fixed socket leak if HTTPConnection.getresponse() fails.Serhiy Storchaka2014-12-011-10/+14
|\ \ \ \ | |/ / / | | | | | | | | Original patch by Martin Panter.
| * | | Issue #21032. Fixed socket leak if HTTPConnection.getresponse() fails.Serhiy Storchaka2014-12-011-10/+14
| | | | | | | | | | | | | | | | Original patch by Martin Panter.
* | | | merge 3.4 (#22921)Benjamin Peterson2014-11-231-2/+1
|\ \ \ \ | |/ / /
| * | | don't require OpenSSL SNI to pass hostname to ssl functions (#22921)Benjamin Peterson2014-11-231-2/+1
| | | | | | | | | | | | | | | | Patch by Donald Stufft.
* | | | Issue #22796: HTTP cookie parsing is now stricter, in order to protect ↵Antoine Pitrou2014-11-211-15/+41
| | | | | | | | | | | | | | | | against potential injection attacks.
* | | | merge 3.4 (#22417)Benjamin Peterson2014-11-031-1/+1
|\ \ \ \ | |/ / /
| * | | PEP 476: enable HTTPS certificate verification by default (#22417)Benjamin Peterson2014-11-031-1/+1
| | | | | | | | | | | | | | | | Patch by Alex Gaynor with some modifications by me.
* | | | Issue #22775: Fixed unpickling of http.cookies.SimpleCookie with protocol 2Serhiy Storchaka2014-11-021-2/+6
|\ \ \ \ | |/ / / | | | | | | | | and above. Patch by Tim Graham.
| * | | Issue #22775: Fixed unpickling of http.cookies.SimpleCookie with protocol 2Serhiy Storchaka2014-11-021-2/+6
| | | | | | | | | | | | | | | | and above. Patch by Tim Graham.