Conversation
Python's email.utils.parseaddr returns ('', '') for addresses with a
stray trailing '>' since the CVE-2023-27043 mitigation (cpython 3.9.20,
3.10.15, 3.11.10, 3.12.6, 3.13.0). The malformed inputs in
test_unicode_sender and test_unicode_sender_tuple silently produced an
empty From: header on those interpreters, so the assertions on
'From: =?utf-8?b?w4TDnMOWIOKGkiDinJM=?= <from@example.com>' failed.
Fix the inputs so they are well-formed addresses; the assertions
already expected a clean '<from@example.com>'.
Closes pallets-eco#233.
Member
|
AI junk |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
tests/test_message.py::test_unicode_senderandtests/test_message.py::test_unicode_sender_tuplewere passing a sender with astray trailing
>("from@example.com>"). Python'semail.utils.parseaddrreturns
('', '')for malformed inputs since the CVE-2023-27043 mitigationlanded in cpython 3.9.20, 3.10.15, 3.11.10, 3.12.6 and 3.13.0, so
sanitize_addressproduces an empty string and theFrom:header is silentlydropped on every supported Python interpreter. Both tests have failed since
those releases shipped.
Fix the inputs so they are well-formed addresses. The assertions already
expected a clean
<from@example.com>, so no other change is needed.Fixes #233.
What I ran locally
Reproduce BEFORE/AFTER yourself (copy-paste)
Edge cases
("ÄÜÖ → ✓", "from@example.com")From: =?utf-8?b?w4TDnMOWIOKGkiDinJM=?= <from@example.com>test_unicode_sender_tuple"ÄÜÖ → ✓ <from@example.com>"From: =?utf-8?b?w4TDnMOWIOKGkiDinJM=?= <from@example.com>test_unicode_sender<…>brackets('ÄÜÖ → ✓', 'from@example.com')test_unicode_headers(unchanged, still passing)Risk / blast radius
Tests only — no runtime code path touched. The two assertions in the file
already encoded the well-formed expected output, so this aligns the inputs
with what the tests had always claimed to verify.
PR drafted with assistance from Claude Code (Anthropic). The change was
reviewed manually against flask-mail's source. The reproducer block above is
the one I used during development; reviewers can paste it verbatim.