You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
36 lines
1.5 KiB
36 lines
1.5 KiB
4 years ago
|
|
||
|
# HG changeset patch
|
||
|
# User Benjamin Peterson <benjamin@python.org>
|
||
|
# Date 1402796189 25200
|
||
|
# Node ID b4bab078876811c7d95231d08aa6fa7142fdda66
|
||
|
# Parent bb8b0c7fefd0c5ed99b3f336178a4f9554a1d0ef
|
||
|
url unquote the path before checking if it refers to a CGI script (closes #21766)
|
||
|
|
||
|
diff --git a/Lib/CGIHTTPServer.py b/Lib/CGIHTTPServer.py
|
||
|
--- a/Lib/CGIHTTPServer.py
|
||
|
+++ b/Lib/CGIHTTPServer.py
|
||
|
@@ -84,7 +84,7 @@ class CGIHTTPRequestHandler(SimpleHTTPSe
|
||
|
path begins with one of the strings in self.cgi_directories
|
||
|
(and the next character is a '/' or the end of the string).
|
||
|
"""
|
||
|
- collapsed_path = _url_collapse_path(self.path)
|
||
|
+ collapsed_path = _url_collapse_path(urllib.unquote(self.path))
|
||
|
dir_sep = collapsed_path.find('/', 1)
|
||
|
head, tail = collapsed_path[:dir_sep], collapsed_path[dir_sep+1:]
|
||
|
if head in self.cgi_directories:
|
||
|
diff --git a/Lib/test/test_httpservers.py b/Lib/test/test_httpservers.py
|
||
|
--- a/Lib/test/test_httpservers.py
|
||
|
+++ b/Lib/test/test_httpservers.py
|
||
|
@@ -510,6 +510,11 @@ class CGIHTTPServerTestCase(BaseTestCase
|
||
|
(res.read(), res.getheader('Content-type'), res.status))
|
||
|
self.assertEqual(os.environ['SERVER_SOFTWARE'], signature)
|
||
|
|
||
|
+ def test_urlquote_decoding_in_cgi_check(self):
|
||
|
+ res = self.request('/cgi-bin%2ffile1.py')
|
||
|
+ self.assertEqual((b'Hello World\n', 'text/html', 200),
|
||
|
+ (res.read(), res.getheader('Content-type'), res.status))
|
||
|
+
|
||
|
|
||
|
class SimpleHTTPRequestHandlerTestCase(unittest.TestCase):
|
||
|
""" Test url parsing """
|