]> git.ipfire.org Git - thirdparty/Python/cpython.git/commit
gh-121650: Encode newlines in headers, and verify headers are sound (GH-122233)
authorPetr Viktorin <encukou@gmail.com>
Tue, 30 Jul 2024 22:19:48 +0000 (00:19 +0200)
committerGitHub <noreply@github.com>
Tue, 30 Jul 2024 22:19:48 +0000 (00:19 +0200)
commit097633981879b3c9de9a1dd120d3aa585ecc2384
treebd7d04f28e53f8df28dd57213e09619cc1666b9d
parent5912487938ac4b517209082ab9e6d2d3d0fb4f4d
gh-121650: Encode newlines in headers, and verify headers are sound (GH-122233)

## Encode header parts that contain newlines

Per RFC 2047:

> [...] these encoding schemes allow the
> encoding of arbitrary octet values, mail readers that implement this
> decoding should also ensure that display of the decoded data on the
> recipient's terminal will not cause unwanted side-effects

It seems that the "quoted-word" scheme is a valid way to include
a newline character in a header value, just like we already allow
undecodable bytes or control characters.
They do need to be properly quoted when serialized to text, though.

## Verify that email headers are well-formed

This should fail for custom fold() implementations that aren't careful
about newlines.

Co-authored-by: Bas Bloemsaat <bas@bloemsaat.org>
Co-authored-by: Serhiy Storchaka <storchaka@gmail.com>
Doc/library/email.errors.rst
Doc/library/email.policy.rst
Doc/whatsnew/3.13.rst
Lib/email/_header_value_parser.py
Lib/email/_policybase.py
Lib/email/errors.py
Lib/email/generator.py
Lib/test/test_email/test_generator.py
Lib/test/test_email/test_policy.py
Misc/NEWS.d/next/Library/2024-07-27-16-10-41.gh-issue-121650.nf6oc9.rst [new file with mode: 0644]