Sitelet https://github.com/python/cpython/issues/79096
Skip to content

LWPCookieJar.save() creates *.lwp file in 644 mode #79096

Description

@aleskva
mannequin
BPO 34915
Nosy @vadmium, @tirkarthi

Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.

Show more details

GitHub fields:

assignee = None
closed_at = None
created_at = <Date 2018-10-06.13:58:56.935>
labels = ['type-security', '3.8', '3.9', 'expert-IO', '3.7', 'library', '3.10']
title = 'LWPCookieJar.save() creates *.lwp file in 644 mode'
updated_at = <Date 2021-03-14.06:38:53.953>
user = 'https://bugs.python.org/aleskva'

bugs.python.org fields:

activity = <Date 2021-03-14.06:38:53.953>
actor = 'martin.panter'
assignee = 'none'
closed = False
closed_date = None
closer = None
components = ['Library (Lib)', 'IO']
creation = <Date 2018-10-06.13:58:56.935>
creator = 'aleskva'
dependencies = []
files = []
hgrepos = []
issue_num = 34915
keywords = []
message_count = 4.0
messages = ['327246', '339126', '341422', '388664']
nosy_count = 3.0
nosy_names = ['martin.panter', 'aleskva', 'xtreak']
pr_nums = []
priority = 'normal'
resolution = None
stage = None
status = 'open'
superseder = None
type = 'security'
url = 'https://bugs.python.org/issue34915'
versions = ['Python 3.6', 'Python 3.7', 'Python 3.8', 'Python 3.9', 'Python 3.10']

Activity

  1. aleskva commented on Oct 6, 2018

    aleskvamannequin
    MannequinAuthor

    The LWPCookieJar.save() creates an *.lwp file containing session cookies in non-safe 644 mode (everyone can read it). This is not a secure behavior, especially for storing session keys or session cookies. The file should be created in 600 mode in my opinion.

    https://github.com/python/cpython/blob/3.7/Lib/http/cookiejar.py#L1872

  2. tirkarthi commented on Mar 29, 2019

    @tirkarthi
    Member

    I guess this is a good choice and distutils stores .pypirc [0] in this manner that has username and password.

    [0]

    with os.fdopen(os.open(rc, os.O_CREAT | os.O_WRONLY, 0o600), 'w') as f:

  3. tirkarthi commented on May 5, 2019

    @tirkarthi
    Member

    Martin, any thoughts on this change?

  4. removed their assignment
    on Oct 21, 2020
  5. vadmium commented on Mar 14, 2021

    @vadmium
    Member

    I don't have a strong opinion, but it does seem a sensible change that matches the high-level nature of the "cookiejar" module, with low risk of users relying on the current file permissions. On the other hand, the "curl" command seems to use the default mode when creating a cookies file (in Netscape a.k.a. Mozilla format):

    $ curl --cookie-jar cookies https://www.google.com/
    [. . .]
    $ ls -l cookies
    -rw-r--r-- 1 vadmium vadmium 418 Mar 14 17:12 cookies

    The MozillaCookieJar class also seems to use the default file mode. I suppose it should be changed as well as the LWP class.

  6. 18 remaining items

  7. ambv commented on Jun 9, 2022

    @ambv
    Contributor

    @pablogsal, let us know if you'd agree for this to still land in 3.11. Otherwise this can be closed.

  8. pablogsal commented on Jun 9, 2022

    @pablogsal
    Member

    I'm fine landing this in 3.11 as long as it goes in before next beta

  9. ambv commented on Jun 9, 2022

    @ambv
    Contributor

    Alright, I'll do the backport now in one commit.

  10. added 3 commits that reference this issue on Jun 9, 2022
  11. ambv commented on Jun 9, 2022

    @ambv
    Contributor

    Alright, this is landed to 3.11 and 3.12. Thanks, @pSub! ✨ 🍰 ✨

  12. added 2 commits that reference this issue on May 21, 2024
  13. added 2 commits that reference this issue on Sep 19, 2024
  14. added a commit that references this issue on Jul 30, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    3.10 (EOL)end of life3.11only security fixes3.12only security fixesstdlibStandard Library Python modules in the Lib/ directorytopic-IOtype-securityA security issue

    Projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions