Repository navigation
urllib.parse.urlparse doesn't check port #88037
Description
Activity
It is possible to get valid ParseResult from the urlparse function even for a non-numeric port value. Only by requesting the port it fails[1].
Would it be an improvement if _checknetloc[2] validates the value of port properly?// code snippet Python 3.8.5 (default, Jan 27 2021, 15:41:15) [GCC 9.3.0] on linux Type "help", "copyright", "credits" or "license" for more information. >>> from urllib.parse import urlparse >>> uri = 'xx://foo:bar' >>> uri_parts = urlparse(uri) >>> uri_parts.netloc 'foo:bar' >>> uri_parts.port Traceback (most recent call last): File "<stdin>", line 1, in <module> File "/usr/lib/python3.8/urllib/parse.py", line 174, in port raise ValueError(message) from None ValueError: Port could not be cast to integer value as 'bar' // code snippet
[1]
Line 172 in e1903e1
port = int(port, 10)
[2]Line 416 in e1903e1
def _checknetloc(netloc): I guess moving port validation logic to parsing time is done as part of #16780
Treating this as bug in itself might be a better idea than waiting for a ipv6 scope introduction, which had few caveats.
Would it be an improvement if _checknetloc[2] validates the value of port properly?
Yes, we could check if it is an int. That should be sufficient.
Thank you for your swift response and your willingness to add port validation to _checknetloc.
I think the validation itself should compound both exceptional branches implemented in port[3]
- port is an int
- port is in the range
[3]
Lines 173 to 178 in e1903e1
except ValueError: message = f'Port could not be cast to integer value as {port!r}' raise ValueError(message) from None if not ( 0 <= port <= 65535): raise ValueError("Port out of range 0-65535") return port - addedstdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directory
on Nov 23, 2023 - addedtype-bugAn unexpected behavior, bug, or errorAn unexpected behavior, bug, or error
on Oct 10, 2026
Metadata
Metadata
Assignees
Labels
Projects
- StatusShow more project fieldsTodo
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields:
Linked PRs