-
-
Notifications
You must be signed in to change notification settings - Fork 2.1k
Fix cookie header parser ignoring reserved names #11178
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Codecov ReportAll modified and coverable lines are covered by tests ✅
✅ All tests successful. No failed tests found. Additional details and impacted files@@ Coverage Diff @@
## master #11178 +/- ##
========================================
Coverage 98.86% 98.86%
========================================
Files 131 131
Lines 43010 43220 +210
Branches 2316 2320 +4
========================================
+ Hits 42520 42730 +210
Misses 340 340
Partials 150 150
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. |
CodSpeed Performance ReportMerging #11178 will not alter performanceComparing Summary
|
now matches requests.session behavior. before SimpleCookie().load would always treat as attributes |
Backport to 3.12: 💚 backport PR created✅ Backport PR branch: Backported as #11181 🤖 @patchback |
Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com> (cherry picked from commit 915338c)
Backport to 3.13: 💚 backport PR created✅ Backport PR branch: Backported as #11182 🤖 @patchback |
Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com> (cherry picked from commit 915338c)
… reserved names (#11181) Co-authored-by: J. Nick Koston <[email protected]> Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
… reserved names (#11182) Co-authored-by: J. Nick Koston <[email protected]> Co-authored-by: pre-commit-ci[bot] <66853113+pre-commit-ci[bot]@users.noreply.github.com>
What do these changes do?
This PR fixes the Cookie header parser to correctly handle reserved attribute names (like
path
,domain
,secure
) as regular cookies, per RFC 6265 Section 5.4.Previously, Cookie headers like
session=abc123; path=/api; secure=true
would only parsesession=abc123
, incorrectly ignoringpath
andsecure
. Now all three are correctly parsed as cookies.The fix:
parse_cookie_header()
function specifically for RFC 6265 compliant Cookie header parsingparse_cookie_headers()
toparse_set_cookie_headers()
for clarityAre there changes in behavior for the user?
Yes, Cookie headers containing reserved attribute names will now be parsed differently:
Before:
After:
This is the correct behavior per RFC 6265 and matches what web browsers do.
Is it a substantial burden for the maintainers to support this?
No. This change:
Related issue number
This has likely been an issue since the beginning, as we previously used Python's
SimpleCookie
which has the same incorrect behavior. Now that we have our own parser (from PR #11112), we can fix this RFC compliance issue.Checklist
CONTRIBUTORS.txt
CHANGES/
foldername it
<issue_or_pr_num>.<type>.rst
(e.g.588.bugfix.rst
)if you don't have an issue number, change it to the pull request
number after creating the PR
.bugfix
: A bug fix for something the maintainers deemed animproper undesired behavior that got corrected to match
pre-agreed expectations.
.feature
: A new behavior, public APIs. That sort of stuff..deprecation
: A declaration of future API removals and breakingchanges in behavior.
.breaking
: When something public is removed in a breaking way.Could be deprecated in an earlier release.
.doc
: Notable updates to the documentation structure or buildprocess.
.packaging
: Notes for downstreams about unobvious side effectsand tooling. Changes in the test invocation considerations and
runtime assumptions.
.contrib
: Stuff that affects the contributor experience. e.g.Running tests, building the docs, setting up the development
environment.
.misc
: Changes that are hard to assign to any of the abovecategories.
Make sure to use full sentences with correct case and punctuation,
for example:
Use the past tense or the present tense a non-imperative mood,
referring to what's changed compared to the last released version
of this project.