Commit bab41433 authored by Raymond Hettinger's avatar Raymond Hettinger

SF patch #1116583: NameError in cookielib domain check

parent ab630507
......@@ -1134,11 +1134,10 @@ class DefaultCookiePolicy(CookiePolicy):
# having to load lots of MSIE cookie files unless necessary.
req_host, erhn = eff_request_host(request)
if not req_host.startswith("."):
dotted_req_host = "."+req_host
req_host = "."+req_host
if not erhn.startswith("."):
dotted_erhn = "."+erhn
if not (dotted_req_host.endswith(domain) or
dotted_erhn.endswith(domain)):
erhn = "."+erhn
if not (req_host.endswith(domain) or erhn.endswith(domain)):
#debug(" request domain %s does not match cookie domain %s",
# req_host, domain)
return False
......
......@@ -399,6 +399,7 @@ Luke Mewburn
Mike Meyer
Steven Miale
Trent Mick
Chad Miller
Roman Milner
Dom Mitchell
Doug Moen
......
......@@ -51,6 +51,8 @@ Extension Modules
Library
-------
- Fixed bug in a NameError bug in cookielib. Patch #1116583.
- Applied a security fix to SimpleXMLRPCserver (PSF-2005-001). This
disables recursive traversal through instance attributes, which can
be exploited in various ways.
......
Markdown is supported
0%
or
You are about to add 0 people to the discussion. Proceed with caution.
Finish editing this message first!
Please register or to comment