tornadoweb / tornadoweb/tornado
Use stricter/platform-independent IP parsing for X-Forwarded-For
Nobody has claimed this yet.
- Dominant language
- Python
- Stars
- 22.2k
- Forks
- 5.6k
- Avg merge
- 3h 42m
- Merged PRs (30d)
- 16
Description
netutil.is_valid_ip uses getaddrinfo in AI_NUMERICHOST mode to parse IP addresses. This method accepts some surprising formats (e.g. "x.y" is parsed as x.(y >> 16).((y>>8)&0xff).(y&0xff), at least on mac and linux). It would be good to limit this to a more formal specification (e.g. the one in http://tools.ietf.org/html/rfc3986#section-3.2.2, which is cited in http://tools.ietf.org/html/draft-ietf-appsawg-http-forwarded-10#section-6.1).
Contributor guide
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
Research direction
Start at netutil.is_valid_ip and compare its getaddrinfo behavior in AI_NUMERICHOST mode with RFC 3986 section 3.2.2 and the Forwarded-header guidance cited in the issue. Done means X-Forwarded-For validation rejects surprising formats such as "x.y" and behaves consistently across macOS and Linux.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- python
- Domain
- networking
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Mostly clear
- Newbie friendliness
- 35/100