Martin Panter added the comment:

The str.find() call was kind of what I had in mind. But I don’t feel qualified 
to say whether the fix is good in general. I would have to find out about at 
the Cookie header format, and understand what the security implications are to 
do with lax parsing.

----------

_______________________________________
Python tracker <rep...@bugs.python.org>
<http://bugs.python.org/issue25228>
_______________________________________
_______________________________________________
Python-bugs-list mailing list
Unsubscribe: 
https://mail.python.org/mailman/options/python-bugs-list/archive%40mail-archive.com

Reply via email to