diff options
author | Ćukasz Langa <lukasz@langa.pl> | 2022-07-01 18:50:36 +0200 |
---|---|---|
committer | GitHub <noreply@github.com> | 2022-07-01 18:50:36 +0200 |
commit | 239b2d9b4703ea5301dab698fe922de997973476 (patch) | |
tree | cc738d0173f39b73c8825c75257110880f64c234 | |
parent | 8a34afd55258c721e446d6de4a70353c39a24148 (diff) | |
download | cpython-git-239b2d9b4703ea5301dab698fe922de997973476.tar.gz |
[3.7] gh-81054: Document that SimpleHTTPRequestHandler follows symbolic links (GH-94416) (GH-94496)
(cherry picked from commit 80aaeabb8bd1e6b49598a7e23e0f8d99b3fcecaf)
Co-authored-by: Sam Ezeh <sam.z.ezeh@gmail.com>
-rw-r--r-- | Doc/library/http.server.rst | 13 |
1 files changed, 12 insertions, 1 deletions
diff --git a/Doc/library/http.server.rst b/Doc/library/http.server.rst index 7e317cd8bc..a93362d96f 100644 --- a/Doc/library/http.server.rst +++ b/Doc/library/http.server.rst @@ -19,7 +19,7 @@ This module defines classes for implementing HTTP servers (Web servers). .. warning:: :mod:`http.server` is not recommended for production. It only implements - basic security checks. + :ref:`basic security checks <http.server-security>`. One class, :class:`HTTPServer`, is a :class:`socketserver.TCPServer` subclass. It creates and listens at the HTTP socket, dispatching the requests to a @@ -470,3 +470,14 @@ the following command uses a specific directory:: the ``--cgi`` option:: python -m http.server --cgi 8000 + +.. _http.server-security: + +Security Considerations +----------------------- + +.. index:: pair: http.server; security + +:class:`SimpleHTTPRequestHandler` will follow symbolic links when handling +requests, this makes it possible for files outside of the specified directory +to be served. |