fixed bug in multipart/form-data parser
Sanic automatically assumes that a form field is a file if it has a content-type header, even though the header is text/plain or application/json. This is a fix for it, I took into account the RFC7578 specification regarding the defaults.
This commit is contained in:
parent
74efa3a108
commit
ed1c563d1f
|
@ -284,7 +284,8 @@ def parse_multipart_form(body, boundary):
|
||||||
form_parts = body.split(boundary)
|
form_parts = body.split(boundary)
|
||||||
for form_part in form_parts[1:-1]:
|
for form_part in form_parts[1:-1]:
|
||||||
file_name = None
|
file_name = None
|
||||||
file_type = None
|
content_type = "text/plain"
|
||||||
|
content_charset = "utf-8"
|
||||||
field_name = None
|
field_name = None
|
||||||
line_index = 2
|
line_index = 2
|
||||||
line_end_index = 0
|
line_end_index = 0
|
||||||
|
@ -304,19 +305,21 @@ def parse_multipart_form(body, boundary):
|
||||||
if form_header_field == 'content-disposition':
|
if form_header_field == 'content-disposition':
|
||||||
if 'filename' in form_parameters:
|
if 'filename' in form_parameters:
|
||||||
file_name = form_parameters['filename']
|
file_name = form_parameters['filename']
|
||||||
field_name = form_parameters.get('name')
|
field_name = form_parameters['name']
|
||||||
elif form_header_field == 'content-type':
|
elif form_header_field == 'content-type':
|
||||||
file_type = form_header_value
|
content_type = form_header_value
|
||||||
|
if 'charset' in form_parameters:
|
||||||
|
content_charset = form_parameters['charset']
|
||||||
|
|
||||||
post_data = form_part[line_index:-4]
|
post_data = form_part[line_index:-4]
|
||||||
if file_name or file_type:
|
if file_name:
|
||||||
file = File(type=file_type, name=file_name, body=post_data)
|
file = File(type=content_type, name=file_name, body=post_data)
|
||||||
if field_name in files:
|
if field_name in files:
|
||||||
files[field_name].append(file)
|
files[field_name].append(file)
|
||||||
else:
|
else:
|
||||||
files[field_name] = [file]
|
files[field_name] = [file]
|
||||||
else:
|
else:
|
||||||
value = post_data.decode('utf-8')
|
value = post_data.decode(content_charset)
|
||||||
if field_name in fields:
|
if field_name in fields:
|
||||||
fields[field_name].append(value)
|
fields[field_name].append(value)
|
||||||
else:
|
else:
|
||||||
|
|
Loading…
Reference in New Issue
Block a user