From 2a42a0bff36129fc9aec06b20e67747cfcc85230 Mon Sep 17 00:00:00 2001 From: Senthil Kumaran Date: Wed, 17 Sep 2014 13:17:58 +0800 Subject: Issue #22421 - Secure pydoc server run. Bind it to localhost instead of all interfaces. --- Lib/pydoc.py | 4 ++-- Lib/test/test_pydoc.py | 2 ++ 2 files changed, 4 insertions(+), 2 deletions(-) diff --git a/Lib/pydoc.py b/Lib/pydoc.py index 9dce079..c9d8436 100755 --- a/Lib/pydoc.py +++ b/Lib/pydoc.py @@ -2168,8 +2168,8 @@ def _start_server(urlhandler, port): class DocServer(http.server.HTTPServer): def __init__(self, port, callback): - self.host = (sys.platform == 'mac') and '127.0.0.1' or 'localhost' - self.address = ('', port) + self.host = 'localhost' + self.address = (self.host, port) self.callback = callback self.base.__init__(self, self.address, self.handler) self.quit = False diff --git a/Lib/test/test_pydoc.py b/Lib/test/test_pydoc.py index 43f4163..ce46d60 100644 --- a/Lib/test/test_pydoc.py +++ b/Lib/test/test_pydoc.py @@ -557,6 +557,8 @@ class PydocServerTest(unittest.TestCase): return text serverthread = pydoc._start_server(my_url_handler, port=0) + self.assertIn('localhost', serverthread.docserver.address) + starttime = time.time() timeout = 1 #seconds -- cgit v0.12