test_http.py 10 KB

123456789101112131415161718192021222324252627282930313233343536373839404142434445464748495051525354555657585960616263646566676869707172737475767778798081828384858687888990919293949596979899100101102103104105106107108109110111112113114115116117118119120121122123124125126127128129130131132133134135136137138139140141142143144145146147148149150151152153154155156157158159160161162163164165166167168169170171172173174175176177178179180181182183184185186187188189190191192193194195196197198199200201202203204205206207208209210211212213214215216217218219220221222223224225226227228229230231232233234235236237238239240241242243244245246247248249250251252253254255256257258259260261262263264265266267268269270271272273
  1. import unittest
  2. from datetime import datetime
  3. from django.test import SimpleTestCase, ignore_warnings
  4. from django.utils.datastructures import MultiValueDict
  5. from django.utils.deprecation import RemovedInDjango30Warning
  6. from django.utils.http import (
  7. base36_to_int, cookie_date, http_date, int_to_base36, is_safe_url,
  8. is_same_domain, parse_etags, parse_http_date, quote_etag, urlencode,
  9. urlquote, urlquote_plus, urlsafe_base64_decode, urlsafe_base64_encode,
  10. urlunquote, urlunquote_plus,
  11. )
  12. class URLEncodeTests(unittest.TestCase):
  13. def test_tuples(self):
  14. self.assertEqual(urlencode((('a', 1), ('b', 2), ('c', 3))), 'a=1&b=2&c=3')
  15. def test_dict(self):
  16. result = urlencode({'a': 1, 'b': 2, 'c': 3})
  17. # Dictionaries are treated as unordered.
  18. self.assertIn(result, [
  19. 'a=1&b=2&c=3',
  20. 'a=1&c=3&b=2',
  21. 'b=2&a=1&c=3',
  22. 'b=2&c=3&a=1',
  23. 'c=3&a=1&b=2',
  24. 'c=3&b=2&a=1',
  25. ])
  26. def test_dict_containing_sequence_not_doseq(self):
  27. self.assertEqual(urlencode({'a': [1, 2]}, doseq=False), 'a=%5B%271%27%2C+%272%27%5D')
  28. def test_dict_containing_sequence_doseq(self):
  29. self.assertEqual(urlencode({'a': [1, 2]}, doseq=True), 'a=1&a=2')
  30. def test_dict_containing_empty_sequence_doseq(self):
  31. self.assertEqual(urlencode({'a': []}, doseq=True), '')
  32. def test_multivaluedict(self):
  33. result = urlencode(MultiValueDict({
  34. 'name': ['Adrian', 'Simon'],
  35. 'position': ['Developer'],
  36. }), doseq=True)
  37. # MultiValueDicts are similarly unordered.
  38. self.assertIn(result, [
  39. 'name=Adrian&name=Simon&position=Developer',
  40. 'position=Developer&name=Adrian&name=Simon',
  41. ])
  42. def test_dict_with_bytes_values(self):
  43. self.assertEqual(urlencode({'a': b'abc'}, doseq=True), 'a=abc')
  44. def test_dict_with_sequence_of_bytes(self):
  45. self.assertEqual(urlencode({'a': [b'spam', b'eggs', b'bacon']}, doseq=True), 'a=spam&a=eggs&a=bacon')
  46. def test_dict_with_bytearray(self):
  47. self.assertEqual(urlencode({'a': bytearray(range(2))}, doseq=True), 'a=0&a=1')
  48. self.assertEqual(urlencode({'a': bytearray(range(2))}, doseq=False), 'a=%5B%270%27%2C+%271%27%5D')
  49. def test_generator(self):
  50. def gen():
  51. yield from range(2)
  52. self.assertEqual(urlencode({'a': gen()}, doseq=True), 'a=0&a=1')
  53. self.assertEqual(urlencode({'a': gen()}, doseq=False), 'a=%5B%270%27%2C+%271%27%5D')
  54. class Base36IntTests(SimpleTestCase):
  55. def test_roundtrip(self):
  56. for n in [0, 1, 1000, 1000000]:
  57. self.assertEqual(n, base36_to_int(int_to_base36(n)))
  58. def test_negative_input(self):
  59. with self.assertRaisesMessage(ValueError, 'Negative base36 conversion input.'):
  60. int_to_base36(-1)
  61. def test_to_base36_errors(self):
  62. for n in ['1', 'foo', {1: 2}, (1, 2, 3), 3.141]:
  63. with self.assertRaises(TypeError):
  64. int_to_base36(n)
  65. def test_invalid_literal(self):
  66. for n in ['#', ' ']:
  67. with self.assertRaisesMessage(ValueError, "invalid literal for int() with base 36: '%s'" % n):
  68. base36_to_int(n)
  69. def test_input_too_large(self):
  70. with self.assertRaisesMessage(ValueError, 'Base36 input too large'):
  71. base36_to_int('1' * 14)
  72. def test_to_int_errors(self):
  73. for n in [123, {1: 2}, (1, 2, 3), 3.141]:
  74. with self.assertRaises(TypeError):
  75. base36_to_int(n)
  76. def test_values(self):
  77. for n, b36 in [(0, '0'), (1, '1'), (42, '16'), (818469960, 'django')]:
  78. self.assertEqual(int_to_base36(n), b36)
  79. self.assertEqual(base36_to_int(b36), n)
  80. class IsSafeURLTests(unittest.TestCase):
  81. def test_bad_urls(self):
  82. bad_urls = (
  83. 'http://example.com',
  84. 'http:///example.com',
  85. 'https://example.com',
  86. 'ftp://example.com',
  87. r'\\example.com',
  88. r'\\\example.com',
  89. r'/\\/example.com',
  90. r'\\\example.com',
  91. r'\\example.com',
  92. r'\\//example.com',
  93. r'/\/example.com',
  94. r'\/example.com',
  95. r'/\example.com',
  96. 'http:///example.com',
  97. r'http:/\//example.com',
  98. r'http:\/example.com',
  99. r'http:/\example.com',
  100. 'javascript:alert("XSS")',
  101. '\njavascript:alert(x)',
  102. '\x08//example.com',
  103. r'http://otherserver\@example.com',
  104. r'http:\\testserver\@example.com',
  105. r'http://testserver\me:pass@example.com',
  106. r'http://testserver\@example.com',
  107. r'http:\\testserver\confirm\me@example.com',
  108. 'http:999999999',
  109. 'ftp:9999999999',
  110. '\n',
  111. 'http://[2001:cdba:0000:0000:0000:0000:3257:9652/',
  112. 'http://2001:cdba:0000:0000:0000:0000:3257:9652]/',
  113. )
  114. for bad_url in bad_urls:
  115. with self.subTest(url=bad_url):
  116. self.assertIs(is_safe_url(bad_url, allowed_hosts={'testserver', 'testserver2'}), False)
  117. def test_good_urls(self):
  118. good_urls = (
  119. '/view/?param=http://example.com',
  120. '/view/?param=https://example.com',
  121. '/view?param=ftp://example.com',
  122. 'view/?param=//example.com',
  123. 'https://testserver/',
  124. 'HTTPS://testserver/',
  125. '//testserver/',
  126. 'http://testserver/confirm?email=me@example.com',
  127. '/url%20with%20spaces/',
  128. 'path/http:2222222222',
  129. )
  130. for good_url in good_urls:
  131. with self.subTest(url=good_url):
  132. self.assertIs(is_safe_url(good_url, allowed_hosts={'otherserver', 'testserver'}), True)
  133. def test_basic_auth(self):
  134. # Valid basic auth credentials are allowed.
  135. self.assertIs(is_safe_url(r'http://user:pass@testserver/', allowed_hosts={'user:pass@testserver'}), True)
  136. def test_no_allowed_hosts(self):
  137. # A path without host is allowed.
  138. self.assertIs(is_safe_url('/confirm/me@example.com'), True)
  139. # Basic auth without host is not allowed.
  140. self.assertIs(is_safe_url(r'http://testserver\@example.com'), False)
  141. def test_secure_param_https_urls(self):
  142. secure_urls = (
  143. 'https://example.com/p',
  144. 'HTTPS://example.com/p',
  145. '/view/?param=http://example.com',
  146. )
  147. for url in secure_urls:
  148. with self.subTest(url=url):
  149. self.assertIs(is_safe_url(url, allowed_hosts={'example.com'}, require_https=True), True)
  150. def test_secure_param_non_https_urls(self):
  151. insecure_urls = (
  152. 'http://example.com/p',
  153. 'ftp://example.com/p',
  154. '//example.com/p',
  155. )
  156. for url in insecure_urls:
  157. with self.subTest(url=url):
  158. self.assertIs(is_safe_url(url, allowed_hosts={'example.com'}, require_https=True), False)
  159. class URLSafeBase64Tests(unittest.TestCase):
  160. def test_roundtrip(self):
  161. bytestring = b'foo'
  162. encoded = urlsafe_base64_encode(bytestring)
  163. decoded = urlsafe_base64_decode(encoded)
  164. self.assertEqual(bytestring, decoded)
  165. class URLQuoteTests(unittest.TestCase):
  166. def test_quote(self):
  167. self.assertEqual(urlquote('Paris & Orl\xe9ans'), 'Paris%20%26%20Orl%C3%A9ans')
  168. self.assertEqual(urlquote('Paris & Orl\xe9ans', safe="&"), 'Paris%20&%20Orl%C3%A9ans')
  169. def test_unquote(self):
  170. self.assertEqual(urlunquote('Paris%20%26%20Orl%C3%A9ans'), 'Paris & Orl\xe9ans')
  171. self.assertEqual(urlunquote('Paris%20&%20Orl%C3%A9ans'), 'Paris & Orl\xe9ans')
  172. def test_quote_plus(self):
  173. self.assertEqual(urlquote_plus('Paris & Orl\xe9ans'), 'Paris+%26+Orl%C3%A9ans')
  174. self.assertEqual(urlquote_plus('Paris & Orl\xe9ans', safe="&"), 'Paris+&+Orl%C3%A9ans')
  175. def test_unquote_plus(self):
  176. self.assertEqual(urlunquote_plus('Paris+%26+Orl%C3%A9ans'), 'Paris & Orl\xe9ans')
  177. self.assertEqual(urlunquote_plus('Paris+&+Orl%C3%A9ans'), 'Paris & Orl\xe9ans')
  178. class IsSameDomainTests(unittest.TestCase):
  179. def test_good(self):
  180. for pair in (
  181. ('example.com', 'example.com'),
  182. ('example.com', '.example.com'),
  183. ('foo.example.com', '.example.com'),
  184. ('example.com:8888', 'example.com:8888'),
  185. ('example.com:8888', '.example.com:8888'),
  186. ('foo.example.com:8888', '.example.com:8888'),
  187. ):
  188. self.assertIs(is_same_domain(*pair), True)
  189. def test_bad(self):
  190. for pair in (
  191. ('example2.com', 'example.com'),
  192. ('foo.example.com', 'example.com'),
  193. ('example.com:9999', 'example.com:8888'),
  194. ):
  195. self.assertIs(is_same_domain(*pair), False)
  196. class ETagProcessingTests(unittest.TestCase):
  197. def test_parsing(self):
  198. self.assertEqual(
  199. parse_etags(r'"" , "etag", "e\\tag", W/"weak"'),
  200. ['""', '"etag"', r'"e\\tag"', 'W/"weak"']
  201. )
  202. self.assertEqual(parse_etags('*'), ['*'])
  203. # Ignore RFC 2616 ETags that are invalid according to RFC 7232.
  204. self.assertEqual(parse_etags(r'"etag", "e\"t\"ag"'), ['"etag"'])
  205. def test_quoting(self):
  206. self.assertEqual(quote_etag('etag'), '"etag"') # unquoted
  207. self.assertEqual(quote_etag('"etag"'), '"etag"') # quoted
  208. self.assertEqual(quote_etag('W/"etag"'), 'W/"etag"') # quoted, weak
  209. class HttpDateProcessingTests(unittest.TestCase):
  210. def test_http_date(self):
  211. t = 1167616461.0
  212. self.assertEqual(http_date(t), 'Mon, 01 Jan 2007 01:54:21 GMT')
  213. @ignore_warnings(category=RemovedInDjango30Warning)
  214. def test_cookie_date(self):
  215. t = 1167616461.0
  216. self.assertEqual(cookie_date(t), 'Mon, 01-Jan-2007 01:54:21 GMT')
  217. def test_parsing_rfc1123(self):
  218. parsed = parse_http_date('Sun, 06 Nov 1994 08:49:37 GMT')
  219. self.assertEqual(datetime.utcfromtimestamp(parsed), datetime(1994, 11, 6, 8, 49, 37))
  220. def test_parsing_rfc850(self):
  221. parsed = parse_http_date('Sunday, 06-Nov-94 08:49:37 GMT')
  222. self.assertEqual(datetime.utcfromtimestamp(parsed), datetime(1994, 11, 6, 8, 49, 37))
  223. def test_parsing_asctime(self):
  224. parsed = parse_http_date('Sun Nov 6 08:49:37 1994')
  225. self.assertEqual(datetime.utcfromtimestamp(parsed), datetime(1994, 11, 6, 8, 49, 37))