Skip to content

AI junk - #251

Closed
jbbqqf wants to merge 1 commit into
pallets-eco:mainfrom
jbbqqf:fix/233-unicode-sender-test-inputs
Closed

jbbqqf wants to merge 1 commit into
pallets-eco:mainfrom
jbbqqf:fix/233-unicode-sender-test-inputs

Conversation

@jbbqqf

@jbbqqf jbbqqf commented May 22, 2026

Copy link
Copy Markdown

Summary

tests/test_message.py::test_unicode_sender and
tests/test_message.py::test_unicode_sender_tuple were passing a sender with a
stray trailing > ("from@example.com>"). Python's email.utils.parseaddr
returns ('', '') for malformed inputs since the CVE-2023-27043 mitigation
landed in cpython 3.9.20, 3.10.15, 3.11.10, 3.12.6 and 3.13.0, so
sanitize_address produces an empty string and the From: header is silently
dropped on every supported Python interpreter. Both tests have failed since
those releases shipped.

Fix the inputs so they are well-formed addresses. The assertions already
expected a clean <from@example.com>, so no other change is needed.

Fixes #233.

What I ran locally

$ pytest tests/test_message.py -k 'test_unicode_sender' -v
tests/test_message.py::test_unicode_sender_tuple PASSED
tests/test_message.py::test_unicode_sender PASSED

$ pytest
51 passed in 0.09s

Reproduce BEFORE/AFTER yourself (copy-paste)

# --- one-time setup ---
git clone https://github.com/pallets-eco/flask-mail.git /tmp/fm-233 && cd /tmp/fm-233
python3.11 -m venv .venv && source .venv/bin/activate
pip install -e . pytest >/dev/null

# --- BEFORE: origin/main ---
git checkout origin/main
pytest tests/test_message.py -k 'test_unicode_sender' -v
# Expected: 2 failed (empty 'From:' header in msg.as_string())

# --- AFTER: this branch ---
git fetch https://github.com/jbbqqf/flask-mail.git fix/233-unicode-sender-test-inputs
git checkout FETCH_HEAD
pytest tests/test_message.py -k 'test_unicode_sender' -v
# Expected: 2 passed

Edge cases

# Scenario Input Expected Verified by
1 tuple sender, well-formed address ("ÄÜÖ → ✓", "from@example.com") From: =?utf-8?b?w4TDnMOWIOKGkiDinJM=?= <from@example.com> test_unicode_sender_tuple
2 string sender, well-formed address "ÄÜÖ → ✓ <from@example.com>" From: =?utf-8?b?w4TDnMOWIOKGkiDinJM=?= <from@example.com> test_unicode_sender
3 string sender already containing <…> brackets parseaddr returns ('ÄÜÖ → ✓', 'from@example.com') name encoded, address ascii test_unicode_headers (unchanged, still passing)

Risk / blast radius

Tests only — no runtime code path touched. The two assertions in the file
already encoded the well-formed expected output, so this aligns the inputs
with what the tests had always claimed to verify.


PR drafted with assistance from Claude Code (Anthropic). The change was
reviewed manually against flask-mail's source. The reproducer block above is
the one I used during development; reviewers can paste it verbatim.

Python's email.utils.parseaddr returns ('', '') for addresses with a
stray trailing '>' since the CVE-2023-27043 mitigation (cpython 3.9.20,
3.10.15, 3.11.10, 3.12.6, 3.13.0). The malformed inputs in
test_unicode_sender and test_unicode_sender_tuple silently produced an
empty From: header on those interpreters, so the assertions on
'From: =?utf-8?b?w4TDnMOWIOKGkiDinJM=?= <from@example.com>' failed.

Fix the inputs so they are well-formed addresses; the assertions
already expected a clean '<from@example.com>'.

Closes pallets-eco#233.
@davidism davidism closed this May 22, 2026
@davidism

Copy link
Copy Markdown
Member

AI junk

@davidism davidism changed the title tests: drop trailing > from unicode sender addresses (#233) AI junk May 22, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

Tests broken by fix for CVE-2023-27043

2 participants