summaryrefslogtreecommitdiff
diff options
context:
space:
mode:
authorClaude Paroz <claude@2xlibre.net>2016-03-04 15:41:52 +0100
committerClaude Paroz <claude@2xlibre.net>2016-03-04 21:16:51 +0100
commit28bed24f552aa01e5b69902493f5ee2e06514522 (patch)
tree34bbd75ffdb9b8d2ba5f1f9753ec9944f35a9928
parentf294b3833bb4f6af51ea3a49598e44787990f6a7 (diff)
[1.8.x] Fixed #26308 -- Prevented crash with binary URLs in is_safe_url()
This fixes a regression introduced by c5544d28923. Thanks John Eskew for the reporti and Tim Graham for the review. Backport of ada7a4aef from master.
-rw-r--r--django/utils/http.py2
-rw-r--r--docs/releases/1.8.11.txt10
-rw-r--r--tests/utils_tests/test_http.py12
3 files changed, 17 insertions, 7 deletions
diff --git a/django/utils/http.py b/django/utils/http.py
index 94800e9749..68f77fba5e 100644
--- a/django/utils/http.py
+++ b/django/utils/http.py
@@ -277,6 +277,8 @@ def is_safe_url(url, host=None):
url = url.strip()
if not url:
return False
+ if six.PY2:
+ url = force_text(url, errors='replace')
# Chrome treats \ completely as / in paths but it could be part of some
# basic auth credentials so we need to check both URLs.
return _is_safe_url(url, host) and _is_safe_url(url.replace('\\', '/'), host)
diff --git a/docs/releases/1.8.11.txt b/docs/releases/1.8.11.txt
index 9837371f7b..b01807129b 100644
--- a/docs/releases/1.8.11.txt
+++ b/docs/releases/1.8.11.txt
@@ -2,11 +2,7 @@
Django 1.8.11 release notes
===========================
-*Under development*
+*March 4, 2016*
-Django 1.8.11 fixes several bugs in 1.8.10.
-
-Bugfixes
-========
-
-* ...
+Django 1.8.11 fixes a regression on Python 2 in the 1.8.10 security release
+where ``utils.http.is_safe_url()`` crashes on bytestring URLs (:ticket:`26308`).
diff --git a/tests/utils_tests/test_http.py b/tests/utils_tests/test_http.py
index e04a3abaf9..106f149515 100644
--- a/tests/utils_tests/test_http.py
+++ b/tests/utils_tests/test_http.py
@@ -1,3 +1,4 @@
+# -*- encoding: utf-8 -*-
from __future__ import unicode_literals
import sys
@@ -134,6 +135,17 @@ class TestUtilsHttp(unittest.TestCase):
'http://testserver/confirm?email=me@example.com',
'/url%20with%20spaces/'):
self.assertTrue(http.is_safe_url(good_url, host='testserver'), "%s should be allowed" % good_url)
+
+ if six.PY2:
+ # Check binary URLs, regression tests for #26308
+ self.assertTrue(
+ http.is_safe_url(b'https://testserver/', host='testserver'),
+ "binary URLs should be allowed on Python 2"
+ )
+ self.assertFalse(http.is_safe_url(b'\x08//example.com', host='testserver'))
+ self.assertTrue(http.is_safe_url('àview/'.encode('utf-8'), host='testserver'))
+ self.assertTrue(http.is_safe_url('àview'.encode('latin-1'), host='testserver'))
+
# Valid basic auth credentials are allowed.
self.assertTrue(http.is_safe_url(r'http://user:pass@testserver/', host='user:pass@testserver'))
# A path without host is allowed.