1. 11 8月, 2023 5 次提交
  2. 09 8月, 2023 3 次提交
    • B
      http1connection: Make content-length parsing more strict · bf90f3a9
      Ben Darnell 提交于
      Content-length and chunk size parsing now strictly matches the RFCs.
      We previously used the python int() function which accepted leading
      plus signs and internal underscores, which are not allowed by the
      HTTP RFCs (it also accepts minus signs, but these are less problematic
      in this context since they'd result in errors elsewhere)
      
      It is important to fix this because when combined with certain proxies,
      the lax parsing could result in a request smuggling vulnerability (if
      both Tornado and the proxy accepted an invalid content-length but
      interpreted it differently). This is known to occur with old versions
      of haproxy, although the current version of haproxy is unaffected.
      bf90f3a9
    • B
      Merge pull request #3305 from bdarnell/redirect-test-windows · fe6c125b
      Ben Darnell 提交于
      web_test: Fix open redirect test on windows
      fe6c125b
    • B
      web_test: Fix open redirect test on windows · 418f63ad
      Ben Darnell 提交于
      Drive letters in windows absolute paths mess up this test,
      so remove them and use a path relative to the drive root instead.
      418f63ad
  3. 07 8月, 2023 1 次提交
  4. 04 8月, 2023 1 次提交
  5. 27 7月, 2023 10 次提交
  6. 26 7月, 2023 2 次提交
  7. 23 7月, 2023 5 次提交
  8. 20 7月, 2023 1 次提交
  9. 08 7月, 2023 10 次提交
  10. 22 6月, 2023 2 次提交