simonw / simonw/tools

http_check.py allows opening local files via file://localhost/... URLs

Open Beginner friendly
#316 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
HTML
Stars
1.9k
Forks
191
Avg merge
36m
Merged PRs (30d)
12

Description

http_check.py is intended to check HTTP/HTTPS headers (Gzip, ETag, Last-Modified). However, it does not validate the URL scheme, and urllib.request.urlopen handles file: URLs by default.

While file:///etc/passwd is rejected due to a missing netloc, passing file://localhost/... bypasses the check and causes the script to open and read local files.

Example input: python3 python/http_check.py "file://localhost/etc/passwd"
Expected behavior: The script should only accept http:// and https:// URLs and reject other schemes.

Contributor guide

No contributing guide indexed for this repository

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with python/http_check.py and inspect how URLs are parsed before urllib.request.urlopen is called. Run the reported file://localhost/etc/passwd example and verify that non-HTTP(S) schemes are rejected while HTTP and HTTPS header checks continue to work.

Written by the indexing model from the issue text.

Assessment

Tech stack
python
Domain
cli, security
Issue type
Bug
Difficulty
2/5
Estimated time
1-3 hours
Activity status
Active
Clarity
Clearly specified
Newbie friendliness
82/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.