You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
35 lines
1.5 KiB
35 lines
1.5 KiB
|
|
# HG changeset patch |
|
# User Benjamin Peterson <benjamin@python.org> |
|
# Date 1402796189 25200 |
|
# Node ID b4bab078876811c7d95231d08aa6fa7142fdda66 |
|
# Parent bb8b0c7fefd0c5ed99b3f336178a4f9554a1d0ef |
|
url unquote the path before checking if it refers to a CGI script (closes #21766) |
|
|
|
diff --git a/Lib/CGIHTTPServer.py b/Lib/CGIHTTPServer.py |
|
--- a/Lib/CGIHTTPServer.py |
|
+++ b/Lib/CGIHTTPServer.py |
|
@@ -84,7 +84,7 @@ class CGIHTTPRequestHandler(SimpleHTTPSe |
|
path begins with one of the strings in self.cgi_directories |
|
(and the next character is a '/' or the end of the string). |
|
""" |
|
- collapsed_path = _url_collapse_path(self.path) |
|
+ collapsed_path = _url_collapse_path(urllib.unquote(self.path)) |
|
dir_sep = collapsed_path.find('/', 1) |
|
head, tail = collapsed_path[:dir_sep], collapsed_path[dir_sep+1:] |
|
if head in self.cgi_directories: |
|
diff --git a/Lib/test/test_httpservers.py b/Lib/test/test_httpservers.py |
|
--- a/Lib/test/test_httpservers.py |
|
+++ b/Lib/test/test_httpservers.py |
|
@@ -510,6 +510,11 @@ class CGIHTTPServerTestCase(BaseTestCase |
|
(res.read(), res.getheader('Content-type'), res.status)) |
|
self.assertEqual(os.environ['SERVER_SOFTWARE'], signature) |
|
|
|
+ def test_urlquote_decoding_in_cgi_check(self): |
|
+ res = self.request('/cgi-bin%2ffile1.py') |
|
+ self.assertEqual((b'Hello World\n', 'text/html', 200), |
|
+ (res.read(), res.getheader('Content-type'), res.status)) |
|
+ |
|
|
|
class SimpleHTTPRequestHandlerTestCase(unittest.TestCase): |
|
""" Test url parsing """
|
|
|