python / python/cpython

Improper Input Validation in urlparse

未关闭
#91,026 5 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看

还没有人认领这个 Issue。

3.9 (EOL) stdlib type-security
主要语言
Python
星标
77.2k
派生
36k
PR 合并指标
PR 指标待抓取

描述

BPO 46870
Nosy @orsenthil, @P0cas, @lafolle

Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

Show more details

GitHub fields:

assignee = None
closed_at = None
created_at = <Date 2022-02-27.01:12:03.440>
labels = ['type-security', '3.9']
title = 'Improper Input Validation in urlparse'
updated_at = <Date 2022-03-02.13:38:56.216>
user = 'https://github.com/P0cas'

bugs.python.org fields:

activity = <Date 2022-03-02.13:38:56.216>
actor = 'P0cas'
assignee = 'none'
closed = False
closed_date = None
closer = None
components = []
creation = <Date 2022-02-27.01:12:03.440>
creator = 'P0cas'
dependencies = []
files = []
hgrepos = []
issue_num = 46870
keywords = []
message_count = 4.0
messages = ['414132', '414133', '414171', '414345']
nosy_count = 3.0
nosy_names = ['orsenthil', 'P0cas', 'karanchaudhary']
pr_nums = []
priority = 'normal'
resolution = None
stage = None
status = 'open'
superseder = None
type = 'security'
url = 'https://bugs.python.org/issue46870'
versions = ['Python 3.9']

贡献指南

打开贡献指南

从这里开始

  1. 先读完整个 Issue,再读项目的贡献指南。
  2. 在 Issue 下留言说明你要接手 —— 这能避免两个人做同样的事。
  3. Fork 仓库,在一个分支上完成修改。
  4. 提交 Pull Request,并在描述里引用这个 Issue 编号。

调研方向

首先定位 urlparse 及其现有测试,然后从 BPO issue 46870 及其迁移的消息中恢复缺失的复现用例和预期行为。当不正确的输入按指定方式得到一致处理,并且回归测试覆盖验证了该行为时,此 issue 即完成。

由索引模型根据 Issue 内容生成。

评估

技术栈
python
领域
networking, security
Issue 类型
缺陷
难度
4/5
预计耗时
3-5 天
活跃度
停滞
描述清晰度
需要澄清
新手友好度
25/100

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。