#28123: django.utils.html.smart_urlquote() is incorrectly parsing the query
string
--------------------------------+--------------------------------------
Reporter: Denis Pechenev | Owner: nobody
Type: Uncategorized | Status: new
Component: Uncategorized | Version: 1.10
Severity: Normal | Resolution:
Keywords: smart_urlquote | Triage Stage: Unreviewed
Has patch: 0 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 0 | UI/UX: 0
--------------------------------+--------------------------------------
Description changed by Denis Pechenev:
Old description:
> Query string like
> 'search_text=%D0%B4%D0%B6%D0%B8%D0%BD%D1%81%D0%BE%D0%B2%D1%8B%D0%B5+%D0%BA%D1%83%D1%80%D1%82%D0%BA%D0%B8'
> is already encoded. But smart_urlquote() encodes it again because of
> incorrect parsing in parse_qsl(). Value should be encoded with ASCII
> before parsing.
>
> So there should be something like:
>
> {{{
> query_parts = [(unquote(force_str(q[0])), unquote(force_str(q[1])))
> for q in parse_qsl(query.encode('ascii'),
> keep_blank_values=True)]
> }}}
New description:
Query string like
'search_text=%D0%B4%D0%B6%D0%B8%D0%BD%D1%81%D0%BE%D0%B2%D1%8B%D0%B5+%D0%BA%D1%83%D1%80%D1%82%D0%BA%D0%B8'
is already encoded. But smart_urlquote() encodes it again because of
incorrect parsing in parse_qsl(). Value should be encoded with ASCII
before parsing.
So there should be something like:
{{{
query_parts = [(unquote(force_str(q[0])), unquote(force_str(q[1])))
for q in parse_qsl(query.encode('ascii'),
keep_blank_values=True)]
}}}
https://github.com/django/django/blob/master/django/utils/html.py#L216
--
--
Ticket URL: <https://code.djangoproject.com/ticket/28123#comment:1>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
--
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To post to this group, send email to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/django-updates/067.5f21ba78eff6933bd1a7ad3fdc71edc1%40djangoproject.com.
For more options, visit https://groups.google.com/d/optout.