Repository navigation
maximum length not enforced in cgi.parse() #42628
Description
Activity
I have a simple form in HTML to upload a file:
<form action="http://foo/cgi-bin/test.py"
enctype="multipart/form-data" method="post">
<p>
Please specify a file:<br>
<input type="file" name="file_1" size="40">
</p>
<p>
<input type="submit" value="Send">
</p>
</form>I use this to post to a CGI python script that looks
like this:import cgi import cgitb; cgitb.enable() cgi.maxlen = 50
print "Content-type: text/plain"
printq = cgi.parse() print q
I was expecting that cgi.pm would then throw an
exception if I send a file > 50 bytes long to it. If
I construct a FieldStorage object, it certainly
does:form = cgi.FieldStorage() print form
The issue is that in parse_multipart() in cgi.pm, if
a part of a multi-part message does not have the
Content-Length header, you read lines until you
get to the next boundary "--...", but don't honour
maxlen whilst doing so. I'd consider this to be a bug
and would even be happy to have a go at fixing
it as my first contribution to Python, should others
concur with me... :-)- addedstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directory
on Nov 27, 2005 - addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Mar 30, 2009 Andrew could you please provide a patch.
No reply to msg109880.
- addedstaleStale PR or inactive for long period of time.Stale PR or inactive for long period of time.
on Aug 31, 2010 - addedstaleStale PR or inactive for long period of time.Stale PR or inactive for long period of time.
on Aug 31, 2010 Let's close this old issue, the cgi module is deprecated in 3.11 and set for removal in 3.13.
See PEP 594 – Removing dead batteries from the standard library, #91217 and #32410.
There's a fork at https://pypi.org/project/legacy-cgi/.
Let's close this old issue, the cgi module is deprecated in 3.11 and set for removal in 3.13.
See PEP 594 – Removing dead batteries from the standard library, #91217 and #32410.
There's a fork at https://pypi.org/project/legacy-cgi/.
Cc. @adr26
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields: