Skip to content

email.utils.getaddresses() rejects email addresses with "," in name #106669

Description

@felixxm

Bug report

email.utils.getaddresses() returns ('', '') for email addresses with , in a real name, e.g.

>>> from email.utils import getaddresses
>>> getaddresses(('"Sürname, Firstname" <to@example.com>',))
[('', '')]

Regression in 18dfbd0.

Your environment

  • CPython versions tested on: 3.12.0b4
  • Operating system and architecture: x86_64 GNU/Linux

Linked PRs

Activity

  1. felixxm commented on Jul 12, 2023

    @felixxm
    ContributorAuthor

    A regression test:

    diff --git a/Lib/test/test_email/test_email.py b/Lib/test/test_email/test_email.py
    index 5238944d6b..30ade53a9a 100644
    --- a/Lib/test/test_email/test_email.py
    +++ b/Lib/test/test_email/test_email.py
    @@ -3319,6 +3319,22 @@ def test_getaddresses(self):
                [('Al Person', 'aperson@dom.ain'),
                 ('Bud Person', 'bperson@dom.ain')])
     
    +    def test_getaddresses_comma_in_name(self):
    +        self.assertEqual(
    +            utils.getaddresses(
    +                [
    +                    '"Bud, Person" <bperson@dom.ain>',
    +                    'aperson@dom.ain (Al Person)',
    +                    '"Mariusz Felisiak" <to@example.com>',
    +                ]
    +            ),
    +            [
    +                ('Bud Person', 'bperson@dom.ain'),
    +                ('Al Person', 'aperson@dom.ain'),
    +                ('Mariusz Felisiak', 'to@example.com'),
    +            ],
    +        )
    +
         def test_getaddresses_parsing_errors(self):
             """Test for parsing errors from CVE-2023-27043"""
             eq = self.assertEqual
  2. rouilj commented on Jul 13, 2023

    @rouilj

    Thanks for finding this. It blew up the regression testing for the Roundup Issue Tracker during my release yesterday. Specifically for:

    email.utils.getaddresses(['"Bork, Chef" chef@bork.bork.bork'])
    [('', '')]

    Any idea if there will be a beta-5 to fix this? If not I could use some ideas on how to
    handle/decorate the three tests that are failing when run on 3.12.

    Thanks.

  3. added a commit that references this issue on Jul 14, 2023
  4. gpshead commented on Jul 14, 2023

    @gpshead
    Member

    If you add a test skip decorator, I'd do it specifically for 3.12beta4. Something like this:

    @unittest.skipIf(sys.version_info == (3, 12, 0, 'beta', 4), "https://github.com/python/cpython/issues/106669")
    def test_oops(self): ...

    It does not look like there is an easy acceptable workaround for the bug as the source of the problem appears to be the comma counting logic added near the end of email.utils.getaddresses().

    It's up to @Yhg1s to decide if this warrants a beta5 or not. I've prepared a rollback of the change that caused it.

  5. added 3 commits that reference this issue on Jul 21, 2023
  6. michel-slm commented on Jul 26, 2023

    @michel-slm

    This also breaks b4 very similarly to Django; mentioning here for reference

    https://bugzilla.redhat.com/show_bug.cgi?id=2226159

        def test_header_wrapping(sampledir, hval, verify, tr):
            hname = 'To' if '@' in hval else "X-Header"
            wrapped = b4.LoreMessage.wrap_header((hname, hval), transform=tr)
    >       assert wrapped.decode() == f'{hname}: {verify}'
    E       assert 'To: ' == 'To: foo@exam...@example.com>'
    E         + To: 
    E         - To: foo@example.com, Foo Bar <bar@example.com>, 
    E         -  =?utf-8?q?F=C3=B4o_Baz?= <baz@example.com>, "Quux, Foo" <quux@example.com>
    tests/test___init__.py:171: AssertionError
    
  7. gpshead commented on Jul 26, 2023

    @gpshead
    Member

    The rollbacks were merged and will appear in 3.12.0rc1.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

Projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions