python / python/cpython

`urllib.parse.parse_qsl` is accepting illegal characters

Offen
#138,284 2 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen

Dieses Issue hat noch niemand übernommen.

stdlib type-bug
Vorherrschende Sprache
Python
Sterne
77.2k
Forks
35.9k
PR-Merge-Kennzahlen
PR-Kennzahlen ausstehend

Beschreibung

Bug report

Bug description:

urllib.parse.parse_qsl parses query strings containing the ^ and ` characters, even though these are not valid query characters under RFC 3986.

Observed behaviour:

parse_qsl('foo=^', strict_parsing=True)
# [('foo', '^')]

parse_qsl('bar=`', strict_parsing=True)
# [('bar', '`')]

Expected behaviour:
According to RFC 3986, both ^ and ` must be percent-encoded if used in a URI. However, parse_qsl accepts them as-is without raising an error or warning. This could lead to applications treating invalid URLs as valid.

Detailed Code:

import sys
import platform
from urllib.parse import parse_qsl


def test_parse_qsl(query):
    try:
        result = parse_qsl(query, strict_parsing=True)
        print(f"Query: {query!r} -> Parsed: {result}")
    except ValueError as e:
        print(f"Query: {query!r} -> Error: {e}")


# Test invalid query strings
test_parse_qsl("foo=^")
test_parse_qsl("bar=`")

# System information
os_name = platform.system()
os_release = platform.release()
python_impl = platform.python_implementation() 
python_version = sys.version.split()[0]
python_compiler = platform.python_compiler() 

print("\n--- System Information ---")
print(f"Python Implementation : {python_impl}")
print(f"Python Version : {python_version}")
print(f"Python Compiler       : {python_compiler}")
print(f"Operating System : {os_name} {os_release}")
print(f"Machine         : {platform.machine()}")

# Output:
# Query: 'foo=^' -> Parsed: [('foo', '^')]
# Query: 'bar=`' -> Parsed: [('bar', '`')]

# --- System Information ---
# Python Implementation : CPython
# Python Version : 3.13.1
# Python Compiler       : GCC 14.2.0
# Operating System : Linux 4.14.174
# Machine         : x86_64

References:

  1. Section 2.2 Reserved Characters: https://datatracker.ietf.org/doc/html/rfc3986#section-2.2

  2. Section 2.3 Unreserved Characters: https://datatracker.ietf.org/doc/html/rfc3986#section-2.3

CPython versions tested on:

3.13

Operating systems tested on:

Linux

Linked PRs
  • gh-138291

Beitragsleitfaden

Beitragsleitfaden öffnen

Erste Schritte

  1. Lies das ganze Issue und danach den Beitragsleitfaden des Projekts.
  2. Schreib ins Issue, dass du es übernimmst — das erspart doppelte Arbeit.
  3. Forke das Repository und arbeite in einem Branch.
  4. Öffne einen Pull Request, der die Issue-Nummer nennt.

Rechercherichtung

Beginne beim Einstiegspunkt urllib.parse.parse_qsl und vergleiche sein aktuelles Verhalten mit den Abschnitten 2.2 und 2.3 von RFC 3986. Überprüfe die vorhandenen Tests für urllib.parse und stelle anschließend sicher, dass Abfragen mit nicht kodierten ^ und ` wie spezifiziert verarbeitet werden und dass die Regressionstestabdeckung das erwartete Verhalten erfasst.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Tech-Stack
python
Bereich
networking
Issue-Typ
Bug
Schwierigkeit
3/5
Geschätzter Aufwand
1-2 Tage
Aktivitätsstatus
Veraltet
Klarheit
Klar beschrieben
Anfängerfreundlichkeit
25/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.