fix: catch ValueError for malformed timestamps in decode_signed_value - #3702
Open
abhi-0203 wants to merge 1 commit into
Open
fix: catch ValueError for malformed timestamps in decode_signed_value#3702abhi-0203 wants to merge 1 commit into
abhi-0203 wants to merge 1 commit into
Conversation
Both v1 and v2 decoders raised ValueError when the timestamp field was non-numeric after passing HMAC verification. Wrap int() calls in try/except ValueError and return None, consistent with the documented behavior of get_signed_cookie returning None for invalid cookies. Closes tornadoweb#3701
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Both
_decode_signed_value_v1and_decode_signed_value_v2intornado/web.pyraiseValueErrorwhen the timestamp field is non-numeric after passing HMAC signature verification. This causesget_signed_cookieto raise instead of returningNonefor malformed cookies.Changes
tornado/web.py: Wrapint()calls for timestamp parsing in both v1 and v2 decoders withtry/except ValueError, returningNoneon failure (consistent with all other malformed-cookie code paths in the same functions).tornado/test/web_test.py: Addtest_malformed_timestamp_v1andtest_malformed_timestamp_v2that construct signed cookies with non-decimal timestamps and verify they are rejected withNoneinstead of raising.Reproducer
Test results
All 12
SignedValueTesttests pass (including the 2 new ones).Closes #3701