<feed xmlns='http://www.w3.org/2005/Atom'>
<title>delta/cpython-git.git/Lib/urllib, branch enum-private-310</title>
<subtitle>github.com: python/cpython.git
</subtitle>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/'/>
<entry>
<title>Update URLs in comments and metadata to use HTTPS (GH-27458) (GH-27478)</title>
<updated>2021-07-30T14:25:28+00:00</updated>
<author>
<name>Miss Islington (bot)</name>
<email>31488909+miss-islington@users.noreply.github.com</email>
</author>
<published>2021-07-30T14:25:28+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=f7f1c26423b1208ef22cbe0f60f36e26a51cebf6'/>
<id>f7f1c26423b1208ef22cbe0f60f36e26a51cebf6</id>
<content type='text'>
(cherry picked from commit be42c06bb01206209430f3ac08b72643dc7cad1c)

Co-authored-by: Noah Kantrowitz &lt;noah@coderanger.net&gt;</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
(cherry picked from commit be42c06bb01206209430f3ac08b72643dc7cad1c)

Co-authored-by: Noah Kantrowitz &lt;noah@coderanger.net&gt;</pre>
</div>
</content>
</entry>
<entry>
<title>bpo-43882 Remove the newline, and tab early. From query and fragments. (GH-25936)</title>
<updated>2021-05-05T23:04:38+00:00</updated>
<author>
<name>Miss Islington (bot)</name>
<email>31488909+miss-islington@users.noreply.github.com</email>
</author>
<published>2021-05-05T23:04:38+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=24f1d1a8a2c4aa58a606b4b6d5fa4305a3b91705'/>
<id>24f1d1a8a2c4aa58a606b4b6d5fa4305a3b91705</id>
<content type='text'>
(cherry picked from commit 985ac016373403e8ad41f8d563c4355ffa8d49ff)</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
(cherry picked from commit 985ac016373403e8ad41f8d563c4355ffa8d49ff)</pre>
</div>
</content>
</entry>
<entry>
<title>bpo-43979: Remove unnecessary operation from urllib.parse.parse_qsl (GH-25756)</title>
<updated>2021-04-30T19:01:55+00:00</updated>
<author>
<name>Dong-hee Na</name>
<email>donghee.na@python.org</email>
</author>
<published>2021-04-30T19:01:55+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=6143fcdf8bfe54c24e3081bcee423f4d51f35c4e'/>
<id>6143fcdf8bfe54c24e3081bcee423f4d51f35c4e</id>
<content type='text'>
Automerge-Triggered-By: GH:gpshead</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Automerge-Triggered-By: GH:gpshead</pre>
</div>
</content>
</entry>
<entry>
<title>bpo-43882 - urllib.parse should sanitize urls containing ASCII newline and tabs. (GH-25595)</title>
<updated>2021-04-29T17:16:50+00:00</updated>
<author>
<name>Senthil Kumaran</name>
<email>senthil@uthcode.com</email>
</author>
<published>2021-04-29T17:16:50+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=76cd81d60310d65d01f9d7b48a8985d8ab89c8b4'/>
<id>76cd81d60310d65d01f9d7b48a8985d8ab89c8b4</id>
<content type='text'>
* issue43882 - urllib.parse should sanitize urls containing ASCII newline and tabs.

Co-authored-by: Gregory P. Smith &lt;greg@krypto.org&gt;
Co-authored-by: Serhiy Storchaka &lt;storchaka@gmail.com&gt;</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* issue43882 - urllib.parse should sanitize urls containing ASCII newline and tabs.

Co-authored-by: Gregory P. Smith &lt;greg@krypto.org&gt;
Co-authored-by: Serhiy Storchaka &lt;storchaka@gmail.com&gt;</pre>
</div>
</content>
</entry>
<entry>
<title>bpo-42967: coerce bytes separator to string in urllib.parse_qs(l) (#24818)</title>
<updated>2021-04-11T13:26:09+00:00</updated>
<author>
<name>Ken Jin</name>
<email>28750310+Fidget-Spinner@users.noreply.github.com</email>
</author>
<published>2021-04-11T13:26:09+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=b38601d49675d90e1ee6faa47f7adaeca992d02d'/>
<id>b38601d49675d90e1ee6faa47f7adaeca992d02d</id>
<content type='text'>
* coerce bytes separator to string

* Add news

* Update Misc/NEWS.d/next/Library/2021-03-11-00-31-41.bpo-42967.2PeQRw.rst</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
* coerce bytes separator to string

* Add news

* Update Misc/NEWS.d/next/Library/2021-03-11-00-31-41.bpo-42967.2PeQRw.rst</pre>
</div>
</content>
</entry>
<entry>
<title>bpo-43075: Fix ReDoS in urllib AbstractBasicAuthHandler (GH-24391)</title>
<updated>2021-04-07T11:27:41+00:00</updated>
<author>
<name>Yeting Li</name>
<email>liyt@ios.ac.cn</email>
</author>
<published>2021-04-07T11:27:41+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=7215d1ae25525c92b026166f9d5cac85fb1defe1'/>
<id>7215d1ae25525c92b026166f9d5cac85fb1defe1</id>
<content type='text'>
Fix Regular Expression Denial of Service (ReDoS) vulnerability in
urllib.request.AbstractBasicAuthHandler. The ReDoS-vulnerable regex
has quadratic worst-case complexity and it allows cause a denial of
service when identifying crafted invalid RFCs. This ReDoS issue is on
the client side and needs remote attackers to control the HTTP server.</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Fix Regular Expression Denial of Service (ReDoS) vulnerability in
urllib.request.AbstractBasicAuthHandler. The ReDoS-vulnerable regex
has quadratic worst-case complexity and it allows cause a denial of
service when identifying crafted invalid RFCs. This ReDoS issue is on
the client side and needs remote attackers to control the HTTP server.</pre>
</div>
</content>
</entry>
<entry>
<title>bpo-42967: Fix urllib.parse docs and make logic clearer (GH-24536)</title>
<updated>2021-02-15T17:00:20+00:00</updated>
<author>
<name>Ken Jin</name>
<email>28750310+Fidget-Spinner@users.noreply.github.com</email>
</author>
<published>2021-02-15T17:00:20+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=a2f0654b0a5b4c4f726155620002cc1f5f2d206a'/>
<id>a2f0654b0a5b4c4f726155620002cc1f5f2d206a</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>bpo-42967: only use '&amp;' as a query string separator (#24297)</title>
<updated>2021-02-14T22:41:57+00:00</updated>
<author>
<name>Adam Goldschmidt</name>
<email>adamgold7@gmail.com</email>
</author>
<published>2021-02-14T22:41:57+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=fcbe0cb04d35189401c0c880ebfb4311e952d776'/>
<id>fcbe0cb04d35189401c0c880ebfb4311e952d776</id>
<content type='text'>
bpo-42967: [security] Address a web cache-poisoning issue reported in urllib.parse.parse_qsl().

urllib.parse will only us "&amp;" as query string separator by default instead of both ";" and "&amp;" as allowed in earlier versions. An optional argument seperator with default value "&amp;" is added to specify the separator.


Co-authored-by: Éric Araujo &lt;merwok@netwok.org&gt;
Co-authored-by: blurb-it[bot] &lt;43283697+blurb-it[bot]@users.noreply.github.com&gt;
Co-authored-by: Ken Jin &lt;28750310+Fidget-Spinner@users.noreply.github.com&gt;
Co-authored-by: Éric Araujo &lt;merwok@netwok.org&gt;</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
bpo-42967: [security] Address a web cache-poisoning issue reported in urllib.parse.parse_qsl().

urllib.parse will only us "&amp;" as query string separator by default instead of both ";" and "&amp;" as allowed in earlier versions. An optional argument seperator with default value "&amp;" is added to specify the separator.


Co-authored-by: Éric Araujo &lt;merwok@netwok.org&gt;
Co-authored-by: blurb-it[bot] &lt;43283697+blurb-it[bot]@users.noreply.github.com&gt;
Co-authored-by: Ken Jin &lt;28750310+Fidget-Spinner@users.noreply.github.com&gt;
Co-authored-by: Éric Araujo &lt;merwok@netwok.org&gt;</pre>
</div>
</content>
</entry>
<entry>
<title>Allow / character in username,password fields in _PROXY envvars. (#23973)</title>
<updated>2020-12-29T12:18:42+00:00</updated>
<author>
<name>Senthil Kumaran</name>
<email>senthil@uthcode.com</email>
</author>
<published>2020-12-29T12:18:42+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=030a713183084594659aefd77b76fe30178e23c8'/>
<id>030a713183084594659aefd77b76fe30178e23c8</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>bpo-40968: Send http/1.1 ALPN extension (#20959)</title>
<updated>2020-11-13T15:37:52+00:00</updated>
<author>
<name>Christian Heimes</name>
<email>christian@python.org</email>
</author>
<published>2020-11-13T15:37:52+00:00</published>
<link rel='alternate' type='text/html' href='http://91.123.203.49/cgit/delta/cpython-git.git/commit/?id=f97406be4c0a02c1501c7ab8bc8ef3850eddb962'/>
<id>f97406be4c0a02c1501c7ab8bc8ef3850eddb962</id>
<content type='text'>
Signed-off-by: Christian Heimes &lt;christian@python.org&gt;</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
Signed-off-by: Christian Heimes &lt;christian@python.org&gt;</pre>
</div>
</content>
</entry>
</feed>
