Repository navigation
email.utils.getaddresses() rejects email addresses with "," in name #106669
Description
Activity
- addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Jul 12, 2023 A regression test:
diff --git a/Lib/test/test_email/test_email.py b/Lib/test/test_email/test_email.py index 5238944d6b..30ade53a9a 100644 --- a/Lib/test/test_email/test_email.py +++ b/Lib/test/test_email/test_email.py @@ -3319,6 +3319,22 @@ def test_getaddresses(self): [('Al Person', 'aperson@dom.ain'), ('Bud Person', 'bperson@dom.ain')]) + def test_getaddresses_comma_in_name(self): + self.assertEqual( + utils.getaddresses( + [ + '"Bud, Person" <bperson@dom.ain>', + 'aperson@dom.ain (Al Person)', + '"Mariusz Felisiak" <to@example.com>', + ] + ), + [ + ('Bud Person', 'bperson@dom.ain'), + ('Al Person', 'aperson@dom.ain'), + ('Mariusz Felisiak', 'to@example.com'), + ], + ) + def test_getaddresses_parsing_errors(self): """Test for parsing errors from CVE-2023-27043""" eq = self.assertEqual
Reacted by Gregory P. Smith- added3.12only security fixesonly security fixes3.13only security fixesonly security fixes
on Jul 12, 2023 Thanks for finding this. It blew up the regression testing for the Roundup Issue Tracker during my release yesterday. Specifically for:
email.utils.getaddresses(['"Bork, Chef" chef@bork.bork.bork'])
[('', '')]Any idea if there will be a beta-5 to fix this? If not I could use some ideas on how to
handle/decorate the three tests that are failing when run on 3.12.Thanks.
Reacted by Gregory P. SmithIf you add a test skip decorator, I'd do it specifically for 3.12beta4. Something like this:
@unittest.skipIf(sys.version_info == (3, 12, 0, 'beta', 4), "https://github.com/python/cpython/issues/106669") def test_oops(self): ...
It does not look like there is an easy acceptable workaround for the bug as the source of the problem appears to be the comma counting logic added near the end of
email.utils.getaddresses().It's up to @Yhg1s to decide if this warrants a beta5 or not. I've prepared a rollback of the change that caused it.
Reacted by John P. RouillardThis also breaks b4 very similarly to Django; mentioning here for reference
https://bugzilla.redhat.com/show_bug.cgi?id=2226159
def test_header_wrapping(sampledir, hval, verify, tr): hname = 'To' if '@' in hval else "X-Header" wrapped = b4.LoreMessage.wrap_header((hname, hval), transform=tr) > assert wrapped.decode() == f'{hname}: {verify}' E assert 'To: ' == 'To: foo@exam...@example.com>' E + To: E - To: foo@example.com, Foo Bar <bar@example.com>, E - =?utf-8?q?F=C3=B4o_Baz?= <baz@example.com>, "Quux, Foo" <quux@example.com> tests/test___init__.py:171: AssertionErrorThe rollbacks were merged and will appear in 3.12.0rc1.
- moved this from Todo to Done in Release and Deferred blockers 🚫
on Jul 26, 2023 - added a commit that references this issue
on Jul 27, 2023 - added 5 commits that reference this issue
on Aug 4, 2023 - added a commit that references this issue
on Aug 15, 2023
Metadata
Metadata
Assignees
Labels
Projects
- StatusShow more project fieldsDone
Bug report
email.utils.getaddresses()returns('', '')for email addresses with,in a real name, e.g.Regression in 18dfbd0.
Your environment
Linked PRs