Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add regression test for #5621 #5632

Closed
wants to merge 359 commits into from
Closed

Conversation

thehesiod
Copy link
Contributor

@thehesiod thehesiod commented Apr 19, 2021

What do these changes do?

Adds regression test for issue #5621

Are there changes in behavior for the user?

Related issue number

#5621

Checklist

  • I think the code is well written
  • [] Unit tests for the changes exist
  • Documentation reflects the changes
  • If you provide code modification, please add yourself to CONTRIBUTORS.txt
    • The format is <Name> <Surname>.
    • Please keep alphabetical order, the file is sorted by names.
  • Add a new news fragment into the CHANGES folder
    • name it <issue_id>.<type> for example (588.bugfix)
    • if you don't have an issue_id change it to the pr id after creating the pr
    • ensure type is one of the following:
      • .feature: Signifying a new feature.
      • .bugfix: Signifying a bug fix.
      • .doc: Signifying a documentation improvement.
      • .removal: Signifying a deprecation or removal of public API.
      • .misc: A ticket has been closed, but it is not of interest to users.
    • Make sure to use full sentences with correct case and punctuation, for example: "Fix issue with non-ascii contents in doctest text files."

View rendered .github/ISSUE_TEMPLATE.md
View rendered .github/ISSUE_TEMPLATE/feature_request.md
View rendered .github/PULL_REQUEST_TEMPLATE.md

asvetlov and others added 30 commits January 13, 2020 15:33
…o-libs#4481) (aio-libs#4512)

(cherry picked from commit 63a0d10)

Co-authored-by: Purusah <16886633+Purusah@users.noreply.github.com>

Co-authored-by: Purusah <16886633+Purusah@users.noreply.github.com>
Co-authored-by: hh-h <hh-h@users.noreply.github.com>.
(cherry picked from commit ec493d6)

Co-authored-by: Andrew Svetlov <andrew.svetlov@gmail.com>
…le (aio-libs#4517) (aio-libs#4518)

(cherry picked from commit e6f04ce)

Co-authored-by: Andrew Svetlov <andrew.svetlov@gmail.com>
…#4529) (aio-libs#4533)

(cherry picked from commit 72176b2)

Co-authored-by: hh-h <hh-h@users.noreply.github.com>

Co-authored-by: hh-h <hh-h@users.noreply.github.com>
)

Otherwise, some tasks might be cancelled before cleanup hooks run. Fixes aio-libs#3593
(cherry picked from commit c32101d)

Co-authored-by: multun <multun@users.noreply.github.com>

Co-authored-by: multun <multun@users.noreply.github.com>
…libs#4534)

(cherry picked from commit 9c10806)

Co-authored-by: Коренберг Марк <socketpair@gmail.com>

Co-authored-by: Коренберг Марк <socketpair@gmail.com>
….close (aio-libs#4540) (aio-libs#4550)

(cherry picked from commit 7e8a94e)

Co-authored-by: Marat Sharafutdinov <decaz89@gmail.com>

Co-authored-by: Marat Sharafutdinov <decaz89@gmail.com>
dependabot bot and others added 27 commits November 6, 2020 09:07
Bumps [attrs](https://github.com/python-attrs/attrs) from 20.2.0 to 20.3.0.
- [Release notes](https://github.com/python-attrs/attrs/releases)
- [Changelog](https://github.com/python-attrs/attrs/blob/master/CHANGELOG.rst)
- [Commits](python-attrs/attrs@20.2.0...20.3.0)

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [sphinxcontrib-spelling](https://github.com/sphinx-contrib/spelling) from 7.0.1 to 7.1.0.
<details>
<summary>Commits</summary>
<ul>
<li><a href="https://github.com/sphinx-contrib/spelling/commit/76127431a996ee6f69fc43f359404a9ca488c9dd"><code>7612743</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/sphinx-contrib/spelling/issues/118">#118</a> from dhellmann/release-note-warning-option</li>
<li><a href="https://github.com/sphinx-contrib/spelling/commit/1704c575e1592a9647122f938185f6e2437e6190"><code>1704c57</code></a> add release note for <code>spelling_warning</code> option</li>
<li><a href="https://github.com/sphinx-contrib/spelling/commit/aa5971d71095e027cf1ef9aa85c08787a1ee6803"><code>aa5971d</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/sphinx-contrib/spelling/issues/117">#117</a> from dhellmann/django-integration-github-action</li>
<li><a href="https://github.com/sphinx-contrib/spelling/commit/09e409f466611291fda37a4ce2392a5e6859a495"><code>09e409f</code></a> add integration test to github actions</li>
<li><a href="https://github.com/sphinx-contrib/spelling/commit/111866ff1af85311a9606500759d818b7c10786d"><code>111866f</code></a> add spelling_warning configuration option (<a href="https://github-redirect.dependabot.com/sphinx-contrib/spelling/issues/116">#116</a>)</li>
<li><a href="https://github.com/sphinx-contrib/spelling/commit/a7780b4467b337938a16cf5c901c0474880994f4"><code>a7780b4</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/sphinx-contrib/spelling/issues/115">#115</a> from dhellmann/limit-release-action</li>
<li><a href="https://github.com/sphinx-contrib/spelling/commit/d49f8981c0278b64ade788011d51456f7267cfdb"><code>d49f898</code></a> do not run the build-n-publish job on forks of the repo</li>
<li><a href="https://github.com/sphinx-contrib/spelling/commit/cbec5dc9d44fdd5bb6f1840f45b427ea6a276b42"><code>cbec5dc</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/sphinx-contrib/spelling/issues/114">#114</a> from dhellmann/release-check-depth</li>
<li><a href="https://github.com/sphinx-contrib/spelling/commit/525c75317f3bb11449093cc7d90d081025320997"><code>525c753</code></a> clone the whole repo when building release</li>
<li><a href="https://github.com/sphinx-contrib/spelling/commit/27fb6a40ac1575c5ceb575e086f3f7a85f7dc757"><code>27fb6a4</code></a> Merge pull request <a href="https://github-redirect.dependabot.com/sphinx-contrib/spelling/issues/113">#113</a> from dhellmann/fix-pypi-publish</li>
<li>Additional commits viewable in <a href="https://github.com/sphinx-contrib/spelling/compare/7.0.1...7.1.0">compare view</a></li>
</ul>
</details>
<br />


[![Dependabot compatibility score](https://dependabot-badges.githubapp.com/badges/compatibility_score?dependency-name=sphinxcontrib-spelling&package-manager=pip&previous-version=7.0.1&new-version=7.1.0)](https://docs.github.com/en/github/managing-security-vulnerabilities/configuring-github-dependabot-security-updates)

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting `@dependabot rebase`.

[//]: # (dependabot-automerge-start)
[//]: # (dependabot-automerge-end)
Bumps [sphinx](https://github.com/sphinx-doc/sphinx) from 3.3.0 to 3.3.1.
- [Release notes](https://github.com/sphinx-doc/sphinx/releases)
- [Changelog](https://github.com/sphinx-doc/sphinx/blob/3.x/CHANGES)
- [Commits](sphinx-doc/sphinx@v3.3.0...v3.3.1)

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…io-libs#5231)

* Add aiohttp-pydantic to third party libraries

* Update docs/third_party.rst

Co-authored-by: Andrew Svetlov <andrew.svetlov@gmail.com>

Co-authored-by: MAILLOL Vincent <vmaillol@webgeoservices.com>
Co-authored-by: Andrew Svetlov <andrew.svetlov@gmail.com>
(cherry picked from commit 61eab8c)

Co-authored-by: Andrew Svetlov <andrew.svetlov@gmail.com>
(cherry picked from commit 98b4c1d)

Co-authored-by: Andrew Svetlov <andrew.svetlov@gmail.com>
Bumps [yarl](https://github.com/aio-libs/yarl) from 1.6.2 to 1.6.3.
- [Release notes](https://github.com/aio-libs/yarl/releases)
- [Changelog](https://github.com/aio-libs/yarl/blob/master/CHANGES.rst)
- [Commits](aio-libs/yarl@v1.6.2...v1.6.3)

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [multidict](https://github.com/aio-libs/multidict) from 5.0.0 to 5.0.2.
- [Release notes](https://github.com/aio-libs/multidict/releases)
- [Changelog](https://github.com/aio-libs/multidict/blob/master/CHANGES.rst)
- [Commits](aio-libs/multidict@v5.0.0...v5.0.2)

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Andrew Svetlov <andrew.svetlov@gmail.com>
Bumps [pre-commit](https://github.com/pre-commit/pre-commit) from 2.8.2 to 2.9.0.
- [Release notes](https://github.com/pre-commit/pre-commit/releases)
- [Changelog](https://github.com/pre-commit/pre-commit/blob/master/CHANGELOG.md)
- [Commits](pre-commit/pre-commit@v2.8.2...v2.9.0)

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [pre-commit](https://github.com/pre-commit/pre-commit) from 2.9.0 to 2.9.2.
- [Release notes](https://github.com/pre-commit/pre-commit/releases)
- [Changelog](https://github.com/pre-commit/pre-commit/blob/master/CHANGELOG.md)
- [Commits](pre-commit/pre-commit@v2.9.0...v2.9.2)

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [multidict](https://github.com/aio-libs/multidict) from 5.0.2 to 5.1.0.
- [Release notes](https://github.com/aio-libs/multidict/releases)
- [Changelog](https://github.com/aio-libs/multidict/blob/master/CHANGES.rst)
- [Commits](aio-libs/multidict@v5.0.2...v5.1.0)

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [pygments](https://github.com/pygments/pygments) from 2.7.2 to 2.7.3.
- [Release notes](https://github.com/pygments/pygments/releases)
- [Changelog](https://github.com/pygments/pygments/blob/master/CHANGES)
- [Commits](pygments/pygments@2.7.2...2.7.3)

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [pre-commit](https://github.com/pre-commit/pre-commit) from 2.9.2 to 2.9.3.
- [Release notes](https://github.com/pre-commit/pre-commit/releases)
- [Changelog](https://github.com/pre-commit/pre-commit/blob/master/CHANGELOG.md)
- [Commits](pre-commit/pre-commit@v2.9.2...v2.9.3)

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Bumps [chardet](https://github.com/chardet/chardet) from 3.0.4 to 4.0.0.
- [Release notes](https://github.com/chardet/chardet/releases)
- [Commits](chardet/chardet@3.0.4...4.0.0)

Signed-off-by: dependabot[bot] <support@github.com>

Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
(cherry picked from commit b0ed732)
This patch fixes an open redirect vulnerability bug in
`aiohttp.web_middlewares.normalize_path_middleware` by
making sure that there's at most one slash at the
beginning of the `Location` header value.

Refs:
* https://cheatsheetseries.owasp.org/cheatsheets/Unvalidated_Redirects_and_Forwards_Cheat_Sheet.html
* GHSA-v6wp-4m6f-gcjg

(cherry picked from commit 76c1fa1315faf48d44b061a1433d0d0c3e4dc12f)
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.