Repository navigation
LWPCookieJar.save() creates *.lwp file in 644 mode #79096
Description
Activity
The LWPCookieJar.save() creates an *.lwp file containing session cookies in non-safe 644 mode (everyone can read it). This is not a secure behavior, especially for storing session keys or session cookies. The file should be created in 600 mode in my opinion.
https://github.com/python/cpython/blob/3.7/Lib/http/cookiejar.py#L1872
- added3.7 (EOL)end of lifeend of lifestdlibStandard Library Python modules in the Lib/ directoryStandard Library Python modules in the Lib/ directorytype-securityA security issueA security issue
on Oct 6, 2018 I guess this is a good choice and distutils stores .pypirc [0] in this manner that has username and password.
[0]
cpython/Lib/distutils/config.py
Line 45 in 2f54908
with os.fdopen(os.open(rc, os.O_CREAT | os.O_WRONLY, 0o600), 'w') as f: Martin, any thoughts on this change?
- added3.8 (EOL)end of lifeend of life3.9 (EOL)end of lifeend of life3.10 (EOL)end of lifeend of life
on Oct 21, 2020 I don't have a strong opinion, but it does seem a sensible change that matches the high-level nature of the "cookiejar" module, with low risk of users relying on the current file permissions. On the other hand, the "curl" command seems to use the default mode when creating a cookies file (in Netscape a.k.a. Mozilla format):
$ curl --cookie-jar cookies https://www.google.com/ [. . .] $ ls -l cookies -rw-r--r-- 1 vadmium vadmium 418 Mar 14 17:12 cookiesThe MozillaCookieJar class also seems to use the default file mode. I suppose it should be changed as well as the LWP class.
18 remaining items
@pablogsal, let us know if you'd agree for this to still land in 3.11. Otherwise this can be closed.
I'm fine landing this in 3.11 as long as it goes in before next beta
Alright, I'll do the backport now in one commit.
Alright, this is landed to 3.11 and 3.12. Thanks, @pSub! ✨ 🍰 ✨
Reacted by Pascal WittmannReacted by Pascal Wittmann- added a commit that references this issue
on Jun 26, 2022
Metadata
Metadata
Assignees
Labels
Projects
- StatusShow more project fieldsDone
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields: