-
-
Notifications
You must be signed in to change notification settings - Fork 2.1k
Fix cookie unquoting regression #11173
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
Codecov ReportAll modified and coverable lines are covered by tests ✅
✅ All tests successful. No failed tests found. Additional details and impacted files@@ Coverage Diff @@
## master #11173 +/- ##
=======================================
Coverage 98.85% 98.86%
=======================================
Files 131 131
Lines 42966 43010 +44
Branches 2314 2316 +2
=======================================
+ Hits 42476 42520 +44
Misses 340 340
Partials 150 150
Flags with carried forward coverage won't be shown. Click here to find out more. ☔ View full report in Codecov by Sentry. |
CodSpeed Performance ReportMerging #11173 will not alter performanceComparing Summary
|
Backport to 3.12: 💚 backport PR created✅ Backport PR branch: Backported as #11179 🤖 @patchback |
(cherry picked from commit 85b0df4)
Backport to 3.13: 💚 backport PR created✅ Backport PR branch: Backported as #11180 🤖 @patchback |
(cherry picked from commit 85b0df4)
What do these changes do?
This PR fixes a regression I introduced when vendoring SimpleCookie - I accidentally copied the wrong
_unquote
function. The correct implementation from Python'shttp.cookies
module is now vendored, which properly handles:\012
for newline,\011
for tab)\"
) and backslashes (\\
)Comprehensive tests have been added to ensure the vendored function behaves identically to SimpleCookie's implementation.
Are there changes in behavior for the user?
Cookie parsing will now correctly handle cookies with octal escape sequences in their values, restoring compatibility with servers that send such cookies. This fixes a regression where these cookies were not being decoded properly.
Is it a substantial burden for the maintainers to support this?
No. This is a straightforward vendoring of a stable function from Python's standard library that has remained unchanged for years. The implementation is well-tested and matches Python's cookie handling behavior exactly. The comprehensive test suite ensures any future changes will be caught.
Related issue number
Checklist
CONTRIBUTORS.txt
CHANGES/
foldername it
<issue_or_pr_num>.<type>.rst
(e.g.588.bugfix.rst
)if you don't have an issue number, change it to the pull request
number after creating the PR
.bugfix
: A bug fix for something the maintainers deemed animproper undesired behavior that got corrected to match
pre-agreed expectations.
.feature
: A new behavior, public APIs. That sort of stuff..deprecation
: A declaration of future API removals and breakingchanges in behavior.
.breaking
: When something public is removed in a breaking way.Could be deprecated in an earlier release.
.doc
: Notable updates to the documentation structure or buildprocess.
.packaging
: Notes for downstreams about unobvious side effectsand tooling. Changes in the test invocation considerations and
runtime assumptions.
.contrib
: Stuff that affects the contributor experience. e.g.Running tests, building the docs, setting up the development
environment.
.misc
: Changes that are hard to assign to any of the abovecategories.
Make sure to use full sentences with correct case and punctuation,
for example:
Use the past tense or the present tense a non-imperative mood,
referring to what's changed compared to the last released version
of this project.