Repository navigation
Wrong attachement filename when mail mime header was too long #83221
Description
Activity
manfred-kaiser commented
on Dec 13, 2019 manfred-kaisermannequinMannequinAuthorMore actionsI'm working on a mailfilter in python and used the method "get_filename" of the "EmailMessage" class.
In some cases a wrong filename was returned. The reason was, that the Content-Disposition Header had a line break and the following intention was interpreted as part of the filename.
After fixing this bug, I was able to get the right filename.
I had to change "linesep_splitter" in "email.policy" to match the intention.
Old Value:
linesep_splitter = re.compile(r'\n|\r')
New Value:
linesep_splitter = re.compile(r'\n\s+|\r\s+')
- added3.7 (EOL)end of lifeend of life3.8 (EOL)end of lifeend of lifetype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Dec 13, 2019 - changed the title
[-]Wrong filename in when mime header was too long[/-][+]Wrong filename in mail when mime header was too long[/+]on Dec 13, 2019 - changed the title
[-]Wrong filename in when mime header was too long[/-][+]Wrong filename in mail when mime header was too long[/+]on Dec 13, 2019 - changed the title
[-]Wrong filename in mail when mime header was too long[/-][+]Wrong attachement filename when mail mime header was too long[/+]on Dec 13, 2019 - changed the title
[-]Wrong filename in mail when mime header was too long[/-][+]Wrong attachement filename when mail mime header was too long[/+]on Dec 13, 2019 Thanks for the report. Can you provide an example that reproduces the problem?
Per the RFC, lines may be broken before whitespace in certain places in certain headers, but that does not make the whitespace go away. Only the crlf sequence is removed when unfolding the header, per the RFC, so your proposed fix is incorrect. I suspect your example header is invalid, and the question will then become is there some sort of Postel-style error recovery we can and want to do in the function that parses the content-disposition header.
manfred-kaiser commented
on Dec 13, 2019 manfred-kaisermannequinMannequinAuthorMore actionsThe original filename is "Schulbesuchsbestättigung.pdf", but when I use the method "get_filename" I got "Schulbesuchsbestättigung. pdf"
I removed some headers from the mail for privacy reasons
13 remaining items
Thanks David! I applied the fixes as per your comments, can you please take another look?
One more tweak to the test and we'll be good to go.
Sure, fixed as per your comments in the PR.
I don't see the change to the test in the PR. Did you miss a push or is github doing something wonky with the review? (I haven't used github review in a while and I had forgetten how hard it is to use...)
I double checked, there should be 4 commits in the PR and last 2 have the changes that you asked for in the test case and NEWS entry.
Your previous comment will point at the old diff, you might have to look at the full diff here: https://github.com/python/cpython/pull/17620/files or if you want, this is the diff for the 2 commits with the changes you requested: https://github.com/python/cpython/pull/17620/files/bf2cb76009d72869d9df6550b473b5818ceab311..016ceb3ef00b3b940993d35d539ce63d68437d4f
Strange that this hasn't been fixed when a fix was submitted literally years ago.
It looks like it was and the issue just wasn't closed.
@bitdancer It does not appear to have been fixed. I just ran into it with python 3.10.4:
$ cat /tmp/testbug.py #!/usr/bin/env python3 import email message = email.message_from_string("""\ MIME-Version: 1.0 Content-Type: text/plain; name="This File Name Is Folded.pdf" Content-Disposition: attachment; filename="This File Name Is Folded.pdf" Content-Transfer-Encoding: 8bit Foo """) print(message.get_filename()) $ python3 /tmp/testbug.py This File Name Is Folded.pdf $ python3 -V 3.10.4That's a different bug, and it is in the legacy API. The new API handles it correctly:
rdmurray@pydev:~/cpython/master[master]>cat temp.py #!/usr/bin/env python3 import email, email.policy message = email.message_from_string("""\ MIME-Version: 1.0 Content-Type: text/plain; name="This File Name Is Folded.pdf" Content-Disposition: attachment; filename="This File Name Is Folded.pdf" Content-Transfer-Encoding: 8bit Foo """, policy=email.policy.default) print(message.get_filename()) rdmurray@pydev:~/cpython/master[master]>./python temp.py This File Name Is Folded.pdf rdmurray@pydev:~/cpython/master[master]>./python -V Python 3.12.0a0 rdmurray@pydev:~/cpython/master[master]>I don't think this is worth trying to fix in the legacy api; the reason it happens there is probably a result of some deeply embedded assumptions in that code and may not be easy to fix. (What would be worth fixing is making the new API truly be the default policy, but I don't currently have time to shepherd that process).
Reacted by Jonathan Kamens
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields: