python / python/cpython

`urllib.parse.parse_qsl` is accepting illegal characters

オープン
#138,284 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る

まだ誰も着手していません。

stdlib type-bug
主要言語
Python
スター
77.2k
フォーク
35.9k
PR マージ指標
PR 指標を取得中

説明

Bug report

Bug description:

urllib.parse.parse_qsl parses query strings containing the ^ and ` characters, even though these are not valid query characters under RFC 3986.

Observed behaviour:

parse_qsl('foo=^', strict_parsing=True)
# [('foo', '^')]

parse_qsl('bar=`', strict_parsing=True)
# [('bar', '`')]

Expected behaviour:
According to RFC 3986, both ^ and ` must be percent-encoded if used in a URI. However, parse_qsl accepts them as-is without raising an error or warning. This could lead to applications treating invalid URLs as valid.

Detailed Code:

import sys
import platform
from urllib.parse import parse_qsl


def test_parse_qsl(query):
    try:
        result = parse_qsl(query, strict_parsing=True)
        print(f"Query: {query!r} -> Parsed: {result}")
    except ValueError as e:
        print(f"Query: {query!r} -> Error: {e}")


# Test invalid query strings
test_parse_qsl("foo=^")
test_parse_qsl("bar=`")

# System information
os_name = platform.system()
os_release = platform.release()
python_impl = platform.python_implementation() 
python_version = sys.version.split()[0]
python_compiler = platform.python_compiler() 

print("\n--- System Information ---")
print(f"Python Implementation : {python_impl}")
print(f"Python Version : {python_version}")
print(f"Python Compiler       : {python_compiler}")
print(f"Operating System : {os_name} {os_release}")
print(f"Machine         : {platform.machine()}")

# Output:
# Query: 'foo=^' -> Parsed: [('foo', '^')]
# Query: 'bar=`' -> Parsed: [('bar', '`')]

# --- System Information ---
# Python Implementation : CPython
# Python Version : 3.13.1
# Python Compiler       : GCC 14.2.0
# Operating System : Linux 4.14.174
# Machine         : x86_64

References:

  1. Section 2.2 Reserved Characters: https://datatracker.ietf.org/doc/html/rfc3986#section-2.2

  2. Section 2.3 Unreserved Characters: https://datatracker.ietf.org/doc/html/rfc3986#section-2.3

CPython versions tested on:

3.13

Operating systems tested on:

Linux

Linked PRs
  • gh-138291

コントリビューションガイド

コントリビューションガイドを開く

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

調査の方向性

urllib.parse.parse_qsl のエントリポイントから開始し、現在の動作を RFC 3986 のセクション 2.2 および 2.3 と比較します。既存の urllib.parse のテストを確認し、エンコードされていない ^ と ` を含むクエリが仕様どおりに処理されること、およびリグレッションカバレッジで期待される動作がカバーされることを検証します。

索引モデルが issue の本文から書いたものです。

評価

技術スタック
python
領域
networking
issue の種類
バグ
難易度
3/5
見積もり時間
1〜2日
活発さ
停滞
明瞭さ
明確に書かれている
初心者へのやさしさ
25/100

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。