Detect foreign content in HTMLParser for context-dependent parsing of CDATA sections
Personne n'a encore pris cette issue.
- Langage dominant
- Python
- Étoiles
- 77.2k
- Forks
- 35.9k
- Métriques de merge des PR
- Métriques de PR en attente
Description
Feature or enhancement
HTMLParser recognizes a CDATA section <![CDATA[...]]> in any context. According to the HTML5 specification, it should only be recognized in foreign content -- the content of svg and math elements. Otherwise <![CDATA[ starts a bogus comment which ends at the first >, not at ]]>. Using the wrong ending condition can make the parser see a different structure of the document than browsers, which can have security consequences. This is the last unresolved item of gh-135661. The fix in #135665 was not satisfying, it just passed the ball to the user's side: the user is supposed to maintain the tracking mechanism outside of HTMLParser and call the new private method _set_support_cdata().
I propose to automatically detect foreign content in HTMLParser itself, by following start and end tags, approximating the tree construction dispatcher and the rules for parsing tokens in foreign content.
>>> parser.feed('<![CDATA[a > b]]>') # bogus comment: comment '[CDATA[a '
>>> parser.feed('<svg><![CDATA[a > b]]>') # CDATA section: unknown decl 'CDATA[a > b'
This also fixes RAWTEXT and RCDATA elements in foreign content: <svg><title>a<b>c</b></title> contains a b element, but HTMLParser currently parses the title content as text.
The new constructor parameter support_cdata controls this: None (default) -- automatic detection; True -- a CDATA section is recognized in any context, foreign content is not detected (the previous default behavior); False -- a CDATA section is never recognized. Calling _set_support_cdata() disables the automatic detection, so existing code which maintains its own tracking machinery works as before.
Has this already been discussed elsewhere?
The last item of gh-135661, discussed also in #135665. Related: gh-137877, gh-140878.
Links to previous discussion of this feature:
Linked PRs
- gh-153028
Guide de contribution
Ouvrir le guide de contribution
Par où commencer
- Lisez l'issue en entier, puis le guide de contribution du projet.
- Signalez en commentaire que vous la prenez — cela évite que deux personnes fassent le même travail.
- Forkez le dépôt et travaillez sur une branche.
- Ouvrez une pull request qui référence le numéro de l'issue.
Piste de recherche
Commencez par HTMLParser, son constructeur, feed() et _set_support_cdata(), puis comparez le comportement proposé aux règles HTML5 liées concernant la construction de l’arbre et le contenu foreign. Le travail est considéré comme terminé lorsque support_cdata utilise par défaut la détection automatique du contexte, tandis que le comportement de True, False et _set_support_cdata() correspond aux cas de compatibilité indiqués, y compris les exemples de CDATA et de RAWTEXT/RCDATA.
Rédigé par le modèle d'indexation à partir du texte de l'issue.
Évaluation
- Stack technique
- python
- Domaine
- web-dev
- Type d'issue
- Fonctionnalité
- Difficulté
- 5/5
- Temps estimé
- Plus d'une semaine
- Activité
- À l'abandon
- Clarté
- Plutôt claire
- Accessibilité débutants
- 25/100