-
-
Notifications
You must be signed in to change notification settings - Fork 2.1k
Fix cookie unquoting regression #11173
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #11173 +/- ##
==========================================
+ Coverage 98.30% 98.86% +0.55%
==========================================
Files 132 131 -1
Lines 43245 43010 -235
Branches 2374 2316 -58
==========================================
+ Hits 42511 42520 +9
+ Misses 558 340 -218
+ Partials 176 150 -26
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. |
CodSpeed Performance ReportMerging #11173 will not alter performanceComparing Summary
|
Backport to 3.12: 💚 backport PR created✅ Backport PR branch: Backported as #11179 🤖 @patchback |
(cherry picked from commit 85b0df4)
Backport to 3.13: 💚 backport PR created✅ Backport PR branch: Backported as #11180 🤖 @patchback |
(cherry picked from commit 85b0df4)
…11179) Co-authored-by: J. Nick Koston <[email protected]>
…11180) Co-authored-by: J. Nick Koston <[email protected]>
What do these changes do?
This PR fixes a regression I introduced when vendoring SimpleCookie - I accidentally copied the wrong
_unquote
function. The correct implementation from Python'shttp.cookies
module is now vendored, which properly handles:\012
for newline,\011
for tab)\"
) and backslashes (\\
)Comprehensive tests have been added to ensure the vendored function behaves identically to SimpleCookie's implementation.
Are there changes in behavior for the user?
Cookie parsing will now correctly handle cookies with octal escape sequences in their values, restoring compatibility with servers that send such cookies. This fixes a regression where these cookies were not being decoded properly.
Is it a substantial burden for the maintainers to support this?
No. This is a straightforward vendoring of a stable function from Python's standard library that has remained unchanged for years. The implementation is well-tested and matches Python's cookie handling behavior exactly. The comprehensive test suite ensures any future changes will be caught.
Related issue number
Checklist
CONTRIBUTORS.txt
CHANGES/
foldername it
<issue_or_pr_num>.<type>.rst
(e.g.588.bugfix.rst
)if you don't have an issue number, change it to the pull request
number after creating the PR
.bugfix
: A bug fix for something the maintainers deemed animproper undesired behavior that got corrected to match
pre-agreed expectations.
.feature
: A new behavior, public APIs. That sort of stuff..deprecation
: A declaration of future API removals and breakingchanges in behavior.
.breaking
: When something public is removed in a breaking way.Could be deprecated in an earlier release.
.doc
: Notable updates to the documentation structure or buildprocess.
.packaging
: Notes for downstreams about unobvious side effectsand tooling. Changes in the test invocation considerations and
runtime assumptions.
.contrib
: Stuff that affects the contributor experience. e.g.Running tests, building the docs, setting up the development
environment.
.misc
: Changes that are hard to assign to any of the abovecategories.
Make sure to use full sentences with correct case and punctuation,
for example:
Use the past tense or the present tense a non-imperative mood,
referring to what's changed compared to the last released version
of this project.