<feed xmlns='http://www.w3.org/2005/Atom'>
<title>delta/cpython.git/Lib/DocXMLRPCServer.py, branch v2.5b2</title>
<subtitle>
</subtitle>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/cpython.git/'/>
<entry>
<title>[Bug #1473048]</title>
<updated>2006-05-31T14:08:48+00:00</updated>
<author>
<name>Andrew M. Kuchling</name>
<email>amk@amk.ca</email>
</author>
<published>2006-05-31T14:08:48+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/cpython.git/commit/?id=5142c4dc0d5dba3a8c09391e9e752e27f3fd0c48'/>
<id>5142c4dc0d5dba3a8c09391e9e752e27f3fd0c48</id>
<content type='text'>
SimpleXMLRPCServer and DocXMLRPCServer don't look at
the path of the HTTP request at all; you can POST or
GET from / or /RPC2 or /blahblahblah with the same results.
Security scanners that look for /cgi-bin/phf will therefore report
lots of vulnerabilities.

Fix: add a .rpc_paths attribute to the SimpleXMLRPCServer class,
and report a 404 error if the path isn't on the allowed list.

Possibly-controversial aspect of this change: the default makes only
'/' and '/RPC2' legal.  Maybe this will break people's applications
(though I doubt it).  We could just set the default to an empty tuple,
which would exactly match the current behaviour.
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
SimpleXMLRPCServer and DocXMLRPCServer don't look at
the path of the HTTP request at all; you can POST or
GET from / or /RPC2 or /blahblahblah with the same results.
Security scanners that look for /cgi-bin/phf will therefore report
lots of vulnerabilities.

Fix: add a .rpc_paths attribute to the SimpleXMLRPCServer class,
and report a 404 error if the path isn't on the allowed list.

Possibly-controversial aspect of this change: the default makes only
'/' and '/RPC2' legal.  Maybe this will break people's applications
(though I doubt it).  We could just set the default to an empty tuple,
which would exactly match the current behaviour.
</pre>
</div>
</content>
</entry>
<entry>
<title>Reduce the usage of the types module.</title>
<updated>2005-02-07T14:16:21+00:00</updated>
<author>
<name>Raymond Hettinger</name>
<email>python@rcn.com</email>
</author>
<published>2005-02-07T14:16:21+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/cpython.git/commit/?id=bcff7654c51e9f5ee54197c4ec360089512c5dc8'/>
<id>bcff7654c51e9f5ee54197c4ec360089512c5dc8</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Use multi-line import</title>
<updated>2004-08-31T11:38:12+00:00</updated>
<author>
<name>Andrew M. Kuchling</name>
<email>amk@amk.ca</email>
</author>
<published>2004-08-31T11:38:12+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/cpython.git/commit/?id=9a7f30e71529dce95d41c28587cab6efc3af91ad'/>
<id>9a7f30e71529dce95d41c28587cab6efc3af91ad</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Patch #727805: Remove extra line ending from CGI responses.</title>
<updated>2003-05-01T05:05:09+00:00</updated>
<author>
<name>Martin v. Löwis</name>
<email>martin@v.loewis.de</email>
</author>
<published>2003-05-01T05:05:09+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/cpython.git/commit/?id=d06b57e1d39325bfa01403c1b6e5c1dced8d907e'/>
<id>d06b57e1d39325bfa01403c1b6e5c1dced8d907e</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Whitespace normalization.</title>
<updated>2003-04-24T16:02:54+00:00</updated>
<author>
<name>Tim Peters</name>
<email>tim.peters@gmail.com</email>
</author>
<published>2003-04-24T16:02:54+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/cpython.git/commit/?id=38425ed060dd425bc6383c46c0a07b4ac57015a3'/>
<id>38425ed060dd425bc6383c46c0a07b4ac57015a3</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
<entry>
<title>Patch #536883: SimpleXMLRPCServer auto-docing subclass.</title>
<updated>2003-04-18T21:04:39+00:00</updated>
<author>
<name>Martin v. Löwis</name>
<email>martin@v.loewis.de</email>
</author>
<published>2003-04-18T21:04:39+00:00</published>
<link rel='alternate' type='text/html' href='http://git.baserock.org/cgit/delta/cpython.git/commit/?id=566e0e84205b040bb1a89f52056edb842fc36f8c'/>
<id>566e0e84205b040bb1a89f52056edb842fc36f8c</id>
<content type='text'>
</content>
<content type='xhtml'>
<div xmlns='http://www.w3.org/1999/xhtml'>
<pre>
</pre>
</div>
</content>
</entry>
</feed>
