#32725: Release notes for 2.2.21 are incomplete, or the code is too strict
--------------------------------+--------------------------------------
Reporter: Ned Batchelder | Owner: nobody
Type: Uncategorized | Status: new
Component: Uncategorized | Version: 2.2
Severity: Normal | Resolution:
Keywords: | Triage Stage: Unreviewed
Has patch: 0 | Needs documentation: 0
Needs tests: 0 | Patch needs improvement: 0
Easy pickings: 0 | UI/UX: 0
--------------------------------+--------------------------------------
Description changed by Ned Batchelder:
Old description:
> It seems to me that the release note for 2.2.21 is incomplete. It says,
> "Specifically, empty file names and paths with dot segments will be
> rejected."
>
> But it's stricter than that: any path component causes the path to be
> rejected:
>
> ```
> if name != os.path.basename(name):
> raise SuspiciousFileOperation("File name '%s' includes path
> elements" % name)
> ```
>
> Is this level of strictness necessary?
New description:
It seems to me that the release note for 2.2.21 is incomplete. It says,
"Specifically, empty file names and paths with dot segments will be
rejected."
But it's stricter than that: any path component causes the path to be
rejected:
{{{
if name != os.path.basename(name):
raise SuspiciousFileOperation("File name '%s' includes path
elements" % name)
}}}
Is this level of strictness necessary?
--
--
Ticket URL: <https://code.djangoproject.com/ticket/32725#comment:2>
Django <https://code.djangoproject.com/>
The Web framework for perfectionists with deadlines.
--
You received this message because you are subscribed to the Google Groups
"Django updates" group.
To unsubscribe from this group and stop receiving emails from it, send an email
to [email protected].
To view this discussion on the web visit
https://groups.google.com/d/msgid/django-updates/064.b4413dab26f714697e0012bcf5fc9c22%40djangoproject.com.