[Web-SIG] URL quoting in WSGI (or the lack therof)
lbruno at 100blossoms.com
Tue Jan 22 17:29:09 CET 2008
James Y Knight escreveu:
> FWIW, I think the right thing for a server to do is to reject any URLs
> going to a wsgi (or cgi) script with a %2F in it. I believe this is
> what apache's CGI host does.
You'd reject the following URL?
BTW, I make a beautiful breadcrumb trail out of that:
Home > Catalog > NEC > Laptops > *LN500/9DW*
> BTW, for extra fun, you should be considering ";" too.
True. The urlparse/urlsplit docs mention ';' but I don't understand
where/how it's used.
More information about the Web-SIG