marshmallow-code / marshmallow-code/marshmallow

URL TLD IP Address Allowed

Open
#1,423 1 comment 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
Python
Stars
7.2k
Forks
738
Avg merge
1d 23h
Merged PRs (30d)
7

Description

`require_tld` does not reject IP addresses in URL fields. The docs say it should "reject non-FQDN hostnames".

https://marshmallow.readthedocs.io/en/stable/api_reference.html?highlight=url#marshmallow.fields.Url

```python
from marshmallow import Schema, fields

class Test(Schema):
foo = fields.URL(require_tld=True) # default

Test().load({'foo': 'http://192.168.1.1/'})
# {'foo': 'http://192.168.1.1/'}
```

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by locating fields.URL and the require_tld validation path, using the example URL in the issue as the reproduction case. Add a regression test showing that an IP address is rejected when require_tld is true, and verify the existing URL validation tests still pass.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
backend
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Clearly specified
Newbie friendliness
45/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.