Uh oh!
There was an error while loading.Please reload this page.
- Notifications
You must be signed in to change notification settings - Fork34k
gh-142412: Add warning about urlsplit's netloc parsing and open redirects#144448
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to ourterms of service andprivacy statement. We’ll occasionally send you account related emails.
Already on GitHub?Sign in to your account
Conversation
… redirectsAdd a warning to the URL parsing security section explaining thaturlsplit/urlparse only parse the netloc when preceded by //. Thisbehavior can lead to open redirect vulnerabilities if applicationsrely solely on checking the netloc to validate redirect URLs.Co-Authored-By: Claude Opus 4.5 <noreply@anthropic.com>
picnixz left a comment
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others.Learn more.
The placing of this note is incorrect and likely auto-generated. In addition, the warning is useless as we're already in a "beware of [...]" section. I would prefer addressing this after we addressed the fate of urlparse in general (and its placement) as a follow-up of#144148.
So for now, I'm closing it.
| sense? Is that a sensible ``path``? Is there anything strange about that | ||
| ``hostname``? etc. | ||
| .. warning:: |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others.Learn more.
It does not make sense to have a warning note here. In addition, its placing interrupts the flow of the current text and is quite off-topic here.
A Python core developer has requested some changes be made to your pull request before we can consider merging it. If you could please address their requests along with any other requests in other reviews from core developers that would be appreciated. Once you have made the requested changes, please leave a comment on this pull request containing the phrase |
Uh oh!
There was an error while loading.Please reload this page.
Summary
urlsplit/urlparseonly parse thenetlocwhen preceded by/////example.com/pathresult in an emptynetlocand apathof/example.com/pathnetlocto validate redirect URLsTest plan
make checkpassed in Doc/ directory🤖 Generated withClaude Code
netlocnot being suitable for open redirect checking #142412📚 Documentation preview 📚:https://cpython-previews--144448.org.readthedocs.build/