#12423 Fix web.http not parsing multiple files in multipart form-data#12424
Merged
adiroiban merged 1 commit intotwisted:trunkfrom Feb 5, 2025
Merged
Conversation
CodSpeed Performance ReportMerging #12424 will not alter performanceComparing Summary
|
20f6fbb to
f7e1830
Compare
adiroiban
requested changes
Feb 4, 2025
Member
adiroiban
left a comment
There was a problem hiding this comment.
Many thanks for the PR.
It looks very good.
Only a few minor comments regarding the release notes and the test.
Thanks again!
f7e1830 to
d42720a
Compare
According to rfc7578:
To match widely deployed implementations, multiple files MUST be sent
by supplying each file in a separate part but all with the same
"name" parameter.
d42720a to
230dc05
Compare
adiroiban
approved these changes
Feb 5, 2025
Member
adiroiban
left a comment
There was a problem hiding this comment.
Thanks. It looks good.
Note that this functionality of Twisted raises a lot of security concerns
See #4688 (comment)
Also, the actual file names are not recorderd ... there is a separate ticket for that #12358
Thanks again for this PR
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Scope and purpose
Fixes #12423
Fixes a regression in twisted.web.http due to replacement of cgi.parse_multipart in commit 4579398 resulted in multipart/form-data requests with multiple files and same name parameter would be parsed to contain only a single file.