Issue #12541: Be lenient with quotes around Realm field of HTTP Basic Authentation in urllib2.
G: changed Misc/NEWS
This commit is contained in:
parent
539f239e88
commit
34f3fcc269
|
@ -1218,6 +1218,21 @@ class HandlerTests(unittest.TestCase):
|
||||||
def test_basic_auth_with_single_quoted_realm(self):
|
def test_basic_auth_with_single_quoted_realm(self):
|
||||||
self.test_basic_auth(quote_char="'")
|
self.test_basic_auth(quote_char="'")
|
||||||
|
|
||||||
|
def test_basic_auth_with_unquoted_realm(self):
|
||||||
|
opener = OpenerDirector()
|
||||||
|
password_manager = MockPasswordManager()
|
||||||
|
auth_handler = urllib.request.HTTPBasicAuthHandler(password_manager)
|
||||||
|
realm = "ACME Widget Store"
|
||||||
|
http_handler = MockHTTPHandler(
|
||||||
|
401, 'WWW-Authenticate: Basic realm=%s\r\n\r\n' % realm)
|
||||||
|
opener.add_handler(auth_handler)
|
||||||
|
opener.add_handler(http_handler)
|
||||||
|
self._test_basic_auth(opener, auth_handler, "Authorization",
|
||||||
|
realm, http_handler, password_manager,
|
||||||
|
"http://acme.example.com/protected",
|
||||||
|
"http://acme.example.com/protected",
|
||||||
|
)
|
||||||
|
|
||||||
def test_proxy_basic_auth(self):
|
def test_proxy_basic_auth(self):
|
||||||
opener = OpenerDirector()
|
opener = OpenerDirector()
|
||||||
ph = urllib.request.ProxyHandler(dict(http="proxy.example.com:3128"))
|
ph = urllib.request.ProxyHandler(dict(http="proxy.example.com:3128"))
|
||||||
|
|
|
@ -794,7 +794,7 @@ class AbstractBasicAuthHandler:
|
||||||
# allow for double- and single-quoted realm values
|
# allow for double- and single-quoted realm values
|
||||||
# (single quotes are a violation of the RFC, but appear in the wild)
|
# (single quotes are a violation of the RFC, but appear in the wild)
|
||||||
rx = re.compile('(?:.*,)*[ \t]*([^ \t]+)[ \t]+'
|
rx = re.compile('(?:.*,)*[ \t]*([^ \t]+)[ \t]+'
|
||||||
'realm=(["\'])(.*?)\\2', re.I)
|
'realm=(["\']?)([^"\']*)\\2', re.I)
|
||||||
|
|
||||||
# XXX could pre-emptively send auth info already accepted (RFC 2617,
|
# XXX could pre-emptively send auth info already accepted (RFC 2617,
|
||||||
# end of section 2, and section 1.2 immediately after "credentials"
|
# end of section 2, and section 1.2 immediately after "credentials"
|
||||||
|
|
|
@ -63,6 +63,9 @@ Core and Builtins
|
||||||
Library
|
Library
|
||||||
-------
|
-------
|
||||||
|
|
||||||
|
- Issue #12541: Be lenient with quotes around Realm field of HTTP Basic
|
||||||
|
Authentation in urllib2.
|
||||||
|
|
||||||
- Issue #14662: Prevent shutil failures on OS X when destination does not
|
- Issue #14662: Prevent shutil failures on OS X when destination does not
|
||||||
support chflag operations. Patch by Hynek Schlawack.
|
support chflag operations. Patch by Hynek Schlawack.
|
||||||
|
|
||||||
|
|
Loading…
Reference in New Issue