Add *strict* optional parameter and reject malformed inputs by default.
-.. function:: formataddr(pair, charset='utf-8')
+.. function:: formataddr(pair, charset='utf-8', *, strict=True)
The inverse of :meth:`parseaddr`, this takes a 2-tuple of the form ``(realname,
email_address)`` and returns the string value suitable for a :mailheader:`To` or
characters. Can be an instance of :class:`str` or a
:class:`~email.charset.Charset`. Defaults to ``utf-8``.
+ If *strict* is true (the default), raise :exc:`ValueError` for inputs that
+ contain CR or LF, which are not allowed in an email address. Set *strict*
+ to ``False`` to allow non-strict inputs.
+
.. versionchanged:: 3.3
Added the *charset* option.
+ .. versionchanged:: next
+ Added the *strict* parameter.
+
.. function:: getaddresses(fieldvalues, *, strict=True)
# Helpers
-def formataddr(pair, charset='utf-8'):
+def formataddr(pair, charset='utf-8', *, strict=True):
"""The inverse of parseaddr(), this takes a 2-tuple of the form
(realname, email_address) and returns the string value suitable
for an RFC 2822 From, To or Cc header.
realname in case realname is not ASCII safe. Can be an instance of str or
a Charset-like object which has a header_encode method. Default is
'utf-8'.
+
+ If strict is True (the default), raise ValueError for inputs that
+ contain CR or LF, which are not allowed in an email address.
"""
name, address = pair
+ if strict and ('\r' in address or '\n' in address
+ or (name and ('\r' in name or '\n' in name))):
+ raise ValueError(
+ "invalid arguments; address parts cannot contain CR or LF")
# The address MUST (per RFC) be ascii, so raise a UnicodeError if it isn't.
address.encode('ascii')
if name:
self.assertRaises(UnicodeError, utils.formataddr, (None, addr))
self.assertRaises(UnicodeError, utils.formataddr, ("Name", addr))
+ def test_crlf_in_parts_raises_error(self):
+ # formataddr() must reject CR and LF in either part so that the
+ # returned header value cannot be used to inject extra headers,
+ # matching email.headerregistry.Address.
+ for name, addr in [
+ ('Real\rName', 'person@dom.ain'),
+ ('Real\nName', 'person@dom.ain'),
+ ('Real Name', 'person@dom.ain\r\nBcc: victim@dom.ain'),
+ ('Real Name', 'person@dom.ain\nSubject: spoofed'),
+ ]:
+ with self.subTest(name=name, addr=addr):
+ self.assertRaises(ValueError, utils.formataddr, (name, addr))
+
+ def test_crlf_in_parts_allowed_when_not_strict(self):
+ # strict=False keeps the old behaviour and passes CR/LF through.
+ self.assertEqual(
+ utils.formataddr(('Real\rName', 'person@dom.ain'), strict=False),
+ 'Real\rName <person@dom.ain>')
+ self.assertEqual(
+ utils.formataddr(('Real Name', 'person@dom.ain\nfoo'), strict=False),
+ 'Real Name <person@dom.ain\nfoo>')
+
def test_name_with_dot(self):
x = 'John X. Doe <jxd@example.com>'
y = '"John X. Doe" <jxd@example.com>'
--- /dev/null
+:func:`email.utils.formataddr` now raises :exc:`ValueError` when the name or
+address contains a carriage return or line feed, matching
+:class:`email.headerregistry.Address`. This check can be disabled by passing
+``strict=False``.