`urllib.parse.parse_qsl` is accepting illegal characters
還沒有人認領這個 Issue。
- 主要語言
- Python
- 星號
- 77.2k
- 分支
- 36k
- PR 合併指標
- PR 指標待擷取
描述
Bug report
Bug description:
urllib.parse.parse_qsl parses query strings containing the ^ and ` characters, even though these are not valid query characters under RFC 3986.
Observed behaviour:
parse_qsl('foo=^', strict_parsing=True)
# [('foo', '^')]
parse_qsl('bar=`', strict_parsing=True)
# [('bar', '`')]
Expected behaviour:
According to RFC 3986, both ^ and ` must be percent-encoded if used in a URI. However, parse_qsl accepts them as-is without raising an error or warning. This could lead to applications treating invalid URLs as valid.
Detailed Code:
import sys
import platform
from urllib.parse import parse_qsl
def test_parse_qsl(query):
try:
result = parse_qsl(query, strict_parsing=True)
print(f"Query: {query!r} -> Parsed: {result}")
except ValueError as e:
print(f"Query: {query!r} -> Error: {e}")
# Test invalid query strings
test_parse_qsl("foo=^")
test_parse_qsl("bar=`")
# System information
os_name = platform.system()
os_release = platform.release()
python_impl = platform.python_implementation()
python_version = sys.version.split()[0]
python_compiler = platform.python_compiler()
print("\n--- System Information ---")
print(f"Python Implementation : {python_impl}")
print(f"Python Version : {python_version}")
print(f"Python Compiler : {python_compiler}")
print(f"Operating System : {os_name} {os_release}")
print(f"Machine : {platform.machine()}")
# Output:
# Query: 'foo=^' -> Parsed: [('foo', '^')]
# Query: 'bar=`' -> Parsed: [('bar', '`')]
# --- System Information ---
# Python Implementation : CPython
# Python Version : 3.13.1
# Python Compiler : GCC 14.2.0
# Operating System : Linux 4.14.174
# Machine : x86_64
References:
-
Section 2.2 Reserved Characters: https://datatracker.ietf.org/doc/html/rfc3986#section-2.2
-
Section 2.3 Unreserved Characters: https://datatracker.ietf.org/doc/html/rfc3986#section-2.3
CPython versions tested on:
3.13
Operating systems tested on:
Linux
Linked PRs
- gh-138291
貢獻指南
從這裡開始
- 先讀完整個 Issue,再讀專案的貢獻指南。
- 在 Issue 下留言說明你要接手 —— 這能避免兩個人做同樣的事。
- Fork 儲存庫,在一個分支上完成修改。
- 送出 Pull Request,並在描述裡引用這個 Issue 編號。
研究方向
從 urllib.parse.parse_qsl 入口點開始,將其目前行為與 RFC 3986 第 2.2 和 2.3 節進行比較。檢視現有的 urllib.parse 測試,然後驗證包含未編碼 ^ 和 ` 的查詢是否依規格處理,並確保回歸涵蓋範圍包含預期行為。
由索引模型根據 Issue 內容生成。
評估
- 技術堆疊
- python
- 領域
- networking
- Issue 類型
- 缺陷
- 難度
- 3/5
- 預估耗時
- 1-2 天
- 活躍度
- 停滯
- 描述清晰度
- 描述清楚
- 新手友好度
- 25/100