Skip to content

Commit 76410af

Browse files
committed
Reject a comma in a URL scheme
The scheme check used "+-." as a character range, so a comma was accepted. The error text only allows letters, digits, "+", "-", and ".".
1 parent 978f2e6 commit 76410af

3 files changed

Lines changed: 8 additions & 1 deletion

File tree

‎CHANGELOG.md‎

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22

33
## Next
44

5+
* A URL scheme no longer accepts a comma. `+-.` in the scheme check was a character range, so `,` sat between `+` and `.`. ([#199](https://github.com/python-hyper/hyperlink/issues/199))
56
* CPython 3.9 added to test matrix
67

78
## 21.0.0

‎src/hyperlink/_url.py‎

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -154,7 +154,8 @@ def __nonzero__(self):
154154
r"(\?(?P<query>[^#]*))?"
155155
r"(#(?P<fragment>.*))?$"
156156
)
157-
_SCHEME_RE = re.compile(r"^[a-zA-Z0-9+-.]*$")
157+
# Hyphen is last so it is a literal. "+-." would be the range from "+" to ".".
158+
_SCHEME_RE = re.compile(r"^[a-zA-Z0-9.+-]*$")
158159
_AUTHORITY_RE = re.compile(
159160
r"^(?:(?P<userinfo>[^@/?#]*)@)?"
160161
r"(?P<host>"

‎src/hyperlink/test/test_url.py‎

Lines changed: 5 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1261,6 +1261,11 @@ def test_wrong_constructor(self):
12611261
with self.assertRaises(ValueError):
12621262
# explicitly bad scheme not allowed
12631263
URL("HTTP_____more_like_imHoTTeP")
1264+
with self.assertRaises(ValueError):
1265+
# "+-." is not a range, so a comma is not a scheme character
1266+
URL(scheme="ht,tp")
1267+
with self.assertRaises(ValueError):
1268+
URL.from_text("ht,tp://example.com")
12641269

12651270
def test_encoded_userinfo(self):
12661271
# type: () -> None

0 commit comments

Comments
 (0)