Skip to content

[3.10] gh-155694: Scope HTTPPasswordMgr credentials by URL scheme (GH-155696) - #155973

Merged
pablogsal merged 3 commits into
python:3.10from
miss-islington:backport-a7bb524-3.10
Oct 1, 2026
Merged

pablogsal merged 3 commits into
python:3.10from
miss-islington:backport-a7bb524-3.10

Conversation

@miss-islington

@miss-islington miss-islington commented Aug 17, 2026 •

Copy link
Copy Markdown
Contributor

Credentials stored for an https:// URI were also matched against the
corresponding http:// URI, since reduce_uri() discards the scheme.

HTTPPasswordMgr and HTTPPasswordMgrWithPriorAuth now compare the scheme
too; URIs registered without a scheme still match any scheme.
(cherry picked from commit a7bb524)

Co-authored-by: Łukasz lukaszlapinski7@gmail.com

…honGH-155696)

Credentials stored for an https:// URI were also matched against the
corresponding http:// URI, since `reduce_uri()` discards the scheme.

`HTTPPasswordMgr` and `HTTPPasswordMgrWithPriorAuth` now compare the scheme
too; URIs registered without a scheme still match any scheme.
(cherry picked from commit a7bb524)

Co-authored-by: Łukasz <lukaszlapinski7@gmail.com>
Comment thread Misc/NEWS.d/next/Security/2026-07-31-16-20-17.gh-issue-155694.SsxlKG.rst Outdated
Unfortunately, too old Sphinx
@pablogsal
pablogsal merged commit dac88d8 into python:3.10 Oct 1, 2026
15 checks passed
@miss-islington
miss-islington deleted the backport-a7bb524-3.10 branch October 1, 2026 00:27
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

Development

Successfully merging this pull request may close these issues.

4 participants