Skip to content

Add the ignorechars parameter in the Base64 decoder #144001

Description

@serhiy-storchaka

Feature or enhancement

Earlier standards for Base64 (RFC 1421, RFC 1521) on which the base64 and binascii modules are based, specified that any non-alphabet characters should be ignored, and this is the default behavior of these modules. More modern standard (RFC 4648) considers this a vulnerability, and specify that they should be rejected until the upper lever document states otherwise. Thus, strict_mode/validate parameters were added. But they are "all-or-nothing" -- either all non-alphabet characters are rejected, or other errors are ignored. In some cases we need to ignore only the part of errors -- for example, ignore newlines and whitespaces, but not other invalid characters, or ignore padding errors.

a85decode() has parameter ignorechars which could also be used to control Base64 decoding.

Linked PRs

Activity

  1. added
    type-featureA feature request or enhancement
    stdlibStandard Library Python modules in the Lib/ directory
    3.15bugs and security fixes
    on Jan 18, 2026
  2. added a commit that references this issue on Jan 18, 2026
  3. moneebullah25 commented on Jan 18, 2026

    @moneebullah25
    Contributor

    Hi @serhiy-storchaka

    I've implemented this feature in PR #144009.

    This PR adds ignorechars parameter to binascii.a2b_base64() and base64.b64decode() with O(1) lookup table, tests, and NEWS entry.

    If this aligns with you have in your mind, feel free to merge or let me know what to cherry-pick from it. Otherwise If you'd prefer a different approach or it needs significant changes, please let me know or feel free to create your own implementation, if not I am happy to close mine in that case.

  4. added 2 commits that reference this issue on Jan 18, 2026
  5. added a commit that references this issue on Jan 19, 2026
  6. serhiy-storchaka commented on Jan 19, 2026

    @serhiy-storchaka
    MemberAuthor

    Sorry, @moneebullah25, but I already had my code before opening this issue. I only needed to solve a pair of corner cases.

  7. added 2 commits that reference this issue on Jan 19, 2026
  8. added a commit that references this issue on Jan 26, 2026
  9. gpshead commented on Jan 26, 2026

    @gpshead
    Member

    a followup PR is likely needed per #144024 (comment)

  10. added 2 commits that reference this issue on Jan 28, 2026
  11. serhiy-storchaka commented on Jan 28, 2026

    @serhiy-storchaka
    MemberAuthor

    PR #144306 extend the function of ignorechars and allows to support the following optional features (RFC 4648, section 3.3):

    Furthermore, such specifications MAY ignore the pad
    character, "=", treating it as non-alphabet data, if it is present
    before the end of the encoded data. If more than the allowed number
    of pad characters is found at the end of the string (e.g., a base 64
    string terminated with "==="), the excess pad characters MAY also be
    ignored.

    Now, if ignorechars contains the pad character '=', the pad characters presented before the end of the encoded data and the excess pad characters will be ignored.

  12. added a commit that references this issue on Jan 29, 2026
  13. serhiy-storchaka commented on Jan 29, 2026

    @serhiy-storchaka
    MemberAuthor

    And since ignorechars is a new parameter, no need to restore the deprecated behavior and emit corresponding warnings when both altchars and ignorechars are specified. #144324 makes it matching the future more secure behavior. It also makes the code simpler.

  14. added a commit that references this issue on Feb 2, 2026
  15. added a commit that references this issue on Feb 3, 2026
  16. added a commit that references this issue on Feb 5, 2026
  17. added 3 commits that reference this issue on Feb 15, 2026
  18. added a commit that references this issue on Apr 25, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

3.15bugs and security fixesstdlibStandard Library Python modules in the Lib/ directorytype-featureA feature request or enhancement

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions