]> git.ipfire.org Git - thirdparty/Python/cpython.git/commitdiff
[3.15] gh-47005: fix do_open() to let regular headers override unredirected … (GH...
authorMiss Islington (bot) <31488909+miss-islington@users.noreply.github.com>
Thu, 9 Jul 2026 04:15:30 +0000 (06:15 +0200)
committerGitHub <noreply@github.com>
Thu, 9 Jul 2026 04:15:30 +0000 (04:15 +0000)
gh-47005: fix do_open() to let regular headers override unredirected … (GH-146506)

AbstractHTTPHandler.do_open() was building the request header dict by
starting with unredirected_hdrs and only inserting regular headers that
were not already present, giving unredirected headers priority.  This
contradicts get_header() and header_items(), both of which give regular
headers the higher priority.

Fix by unconditionally updating with req.headers so that a header set
via add_header() always overrides one set via add_unredirected_header().

---------
(cherry picked from commit 6d386684ad69f42cb57c72fe0e0ffcec82ec7e12)

Co-authored-by: CHINMAY <89741289+Das-Chinmay@users.noreply.github.com>
Co-authored-by: Senthil Kumaran <senthil@python.org>
Lib/test/test_urllib2.py
Lib/urllib/request.py
Misc/NEWS.d/next/Library/2026-03-26-00-00-00.gh-issue-47005.xxc89c.rst [new file with mode: 0644]

index 3a77b9e5ab792890df753d414eab07e87a796577..d2fd111f6d9de0209503f8e0be3d3f378d99266b 100644 (file)
@@ -980,6 +980,35 @@ class HandlerTests(unittest.TestCase):
             self.assertEqual(req.unredirected_hdrs["Host"], "baz")
             self.assertEqual(req.unredirected_hdrs["Spam"], "foo")
 
+    def test_http_header_priority(self):
+        # gh-47005: regular headers set via add_header() must override
+        # unredirected headers with the same name in do_open(), consistent
+        # with get_header() and header_items().
+        cases = [
+            ("Content-Type", "application/json", "application/x-www-form-urlencoded"),
+            ("Content-Length", "99", "0"),
+            ("Host", "override.example.com", "internal.example.com"),
+            ("Authorization", "Bearer user-token", "Basic stale="),
+            ("Cookie", "a=1", "b=2"),
+            ("User-Agent", "MyApp/1.0", "Python-urllib/test"),
+        ]
+        h = urllib.request.AbstractHTTPHandler()
+        h.parent = MockOpener()
+
+        for key, regular, unredirected in cases:
+            req = Request("http://example.com/", headers={key: regular})
+            req.timeout = None
+            req.add_unredirected_header(key, unredirected)
+
+            http = MockHTTPClass()
+            h.do_open(http, req)
+
+            sent_headers = dict(http.req_headers)
+            self.assertEqual(sent_headers[key], regular)
+            # key is capitalized by add_header() and add_unredirected_header() calls
+            self.assertEqual(req.get_header(key.capitalize()), regular)
+            self.assertEqual(dict(req.header_items())[key.capitalize()], regular)
+
     def test_http_body_file(self):
         # A regular file - chunked encoding is used unless Content Length is
         # already set.
index f5f17f223a458532cbc2d63aec815f0ab227aba1..660301fef61258837e3c14a67f35898e16f51662 100644 (file)
@@ -1293,8 +1293,7 @@ class AbstractHTTPHandler(BaseHandler):
         h.set_debuglevel(self._debuglevel)
 
         headers = dict(req.unredirected_hdrs)
-        headers.update({k: v for k, v in req.headers.items()
-                        if k not in headers})
+        headers.update(req.headers)
 
         # TODO(jhylton): Should this be redesigned to handle
         # persistent connections?
diff --git a/Misc/NEWS.d/next/Library/2026-03-26-00-00-00.gh-issue-47005.xxc89c.rst b/Misc/NEWS.d/next/Library/2026-03-26-00-00-00.gh-issue-47005.xxc89c.rst
new file mode 100644 (file)
index 0000000..646367f
--- /dev/null
@@ -0,0 +1,4 @@
+Fix :meth:`!urllib.request.AbstractHTTPHandler.do_open` to give regular
+headers set via :meth:`~urllib.request.Request.add_header` priority over
+unredirected headers, consistent with :meth:`~urllib.request.Request.get_header`
+and :meth:`~urllib.request.Request.header_items`.