blob: cc11acc04f338487cfc918d2c4c02084c79166e4 [file] [log] [blame]
Benjamin Petersonee8712c2008-05-20 21:35:26 +00001from test.support import run_unittest
Jeremy Hyltond9827c42000-08-03 22:11:43 +00002import cgi
3import os
4import sys
Thomas Wouters00ee7ba2006-08-21 19:07:27 +00005import tempfile
Thomas Wouters89f507f2006-12-13 04:49:30 +00006import unittest
Guido van Rossum34d19282007-08-09 01:03:29 +00007from io import StringIO
Jeremy Hyltond9827c42000-08-03 22:11:43 +00008
9class HackedSysModule:
10 # The regression test will have real values in sys.argv, which
Fred Drake004d5e62000-10-23 17:22:08 +000011 # will completely confuse the test of the cgi module
Jeremy Hyltond9827c42000-08-03 22:11:43 +000012 argv = []
13 stdin = sys.stdin
14
15cgi.sys = HackedSysModule()
16
17try:
Guido van Rossum34d19282007-08-09 01:03:29 +000018 from io import StringIO
Jeremy Hyltond9827c42000-08-03 22:11:43 +000019except ImportError:
Guido van Rossum34d19282007-08-09 01:03:29 +000020 from io import StringIO
Jeremy Hyltond9827c42000-08-03 22:11:43 +000021
22class ComparableException:
23 def __init__(self, err):
24 self.err = err
25
26 def __str__(self):
27 return str(self.err)
28
Guido van Rossum47b9ff62006-08-24 00:41:19 +000029 def __eq__(self, anExc):
Jeremy Hyltond9827c42000-08-03 22:11:43 +000030 if not isinstance(anExc, Exception):
Guido van Rossum47b9ff62006-08-24 00:41:19 +000031 return NotImplemented
32 return (self.err.__class__ == anExc.__class__ and
33 self.err.args == anExc.args)
Jeremy Hyltond9827c42000-08-03 22:11:43 +000034
35 def __getattr__(self, attr):
Guido van Rossum846d6db2001-01-17 15:08:37 +000036 return getattr(self.err, attr)
Jeremy Hyltond9827c42000-08-03 22:11:43 +000037
38def do_test(buf, method):
39 env = {}
40 if method == "GET":
41 fp = None
42 env['REQUEST_METHOD'] = 'GET'
43 env['QUERY_STRING'] = buf
44 elif method == "POST":
45 fp = StringIO(buf)
46 env['REQUEST_METHOD'] = 'POST'
47 env['CONTENT_TYPE'] = 'application/x-www-form-urlencoded'
48 env['CONTENT_LENGTH'] = str(len(buf))
49 else:
Collin Winter3add4d72007-08-29 23:37:32 +000050 raise ValueError("unknown method: %s" % method)
Jeremy Hyltond9827c42000-08-03 22:11:43 +000051 try:
52 return cgi.parse(fp, env, strict_parsing=1)
Guido van Rossumcd16bf62007-06-13 18:07:49 +000053 except Exception as err:
Jeremy Hyltond9827c42000-08-03 22:11:43 +000054 return ComparableException(err)
55
56# A list of test cases. Each test case is a a two-tuple that contains
57# a string with the query and a dictionary with the expected result.
Fred Drake004d5e62000-10-23 17:22:08 +000058
Neil Schemenauer66edb622004-07-19 15:38:11 +000059parse_qsl_test_cases = [
60 ("", []),
61 ("&", []),
62 ("&&", []),
63 ("=", [('', '')]),
64 ("=a", [('', 'a')]),
65 ("a", [('a', '')]),
66 ("a=", [('a', '')]),
67 ("a=", [('a', '')]),
68 ("&a=b", [('a', 'b')]),
69 ("a=a+b&b=b+c", [('a', 'a b'), ('b', 'b c')]),
70 ("a=1&a=2", [('a', '1'), ('a', '2')]),
Guido van Rossum52dbbb92008-08-18 21:44:30 +000071 ("a=%26&b=%3D", [('a', '&'), ('b', '=')]),
72 ("a=%C3%BC&b=%CA%83", [('a', '\xfc'), ('b', '\u0283')]),
Neil Schemenauer66edb622004-07-19 15:38:11 +000073]
74
75parse_strict_test_cases = [
Jeremy Hyltond9827c42000-08-03 22:11:43 +000076 ("", ValueError("bad query field: ''")),
77 ("&", ValueError("bad query field: ''")),
78 ("&&", ValueError("bad query field: ''")),
Jeremy Hyltonafde7e22000-09-15 20:06:57 +000079 (";", ValueError("bad query field: ''")),
80 (";&;", ValueError("bad query field: ''")),
Jeremy Hyltond9827c42000-08-03 22:11:43 +000081 # Should the next few really be valid?
82 ("=", {}),
83 ("=&=", {}),
Jeremy Hyltonafde7e22000-09-15 20:06:57 +000084 ("=;=", {}),
Jeremy Hyltond9827c42000-08-03 22:11:43 +000085 # This rest seem to make sense
86 ("=a", {'': ['a']}),
87 ("&=a", ValueError("bad query field: ''")),
88 ("=a&", ValueError("bad query field: ''")),
89 ("=&a", ValueError("bad query field: 'a'")),
90 ("b=a", {'b': ['a']}),
91 ("b+=a", {'b ': ['a']}),
92 ("a=b=a", {'a': ['b=a']}),
93 ("a=+b=a", {'a': [' b=a']}),
94 ("&b=a", ValueError("bad query field: ''")),
95 ("b&=a", ValueError("bad query field: 'b'")),
96 ("a=a+b&b=b+c", {'a': ['a b'], 'b': ['b c']}),
97 ("a=a+b&a=b+a", {'a': ['a b', 'b a']}),
98 ("x=1&y=2.0&z=2-3.%2b0", {'x': ['1'], 'y': ['2.0'], 'z': ['2-3.+0']}),
Jeremy Hyltonafde7e22000-09-15 20:06:57 +000099 ("x=1;y=2.0&z=2-3.%2b0", {'x': ['1'], 'y': ['2.0'], 'z': ['2-3.+0']}),
100 ("x=1;y=2.0;z=2-3.%2b0", {'x': ['1'], 'y': ['2.0'], 'z': ['2-3.+0']}),
Jeremy Hyltond9827c42000-08-03 22:11:43 +0000101 ("Hbc5161168c542333633315dee1182227:key_store_seqid=400006&cuyer=r&view=bustomer&order_id=0bb2e248638833d48cb7fed300000f1b&expire=964546263&lobale=en-US&kid=130003.300038&ss=env",
102 {'Hbc5161168c542333633315dee1182227:key_store_seqid': ['400006'],
103 'cuyer': ['r'],
104 'expire': ['964546263'],
105 'kid': ['130003.300038'],
106 'lobale': ['en-US'],
107 'order_id': ['0bb2e248638833d48cb7fed300000f1b'],
108 'ss': ['env'],
109 'view': ['bustomer'],
110 }),
Fred Drake004d5e62000-10-23 17:22:08 +0000111
Jeremy Hyltond9827c42000-08-03 22:11:43 +0000112 ("group_id=5470&set=custom&_assigned_to=31392&_status=1&_category=100&SUBMIT=Browse",
113 {'SUBMIT': ['Browse'],
114 '_assigned_to': ['31392'],
115 '_category': ['100'],
116 '_status': ['1'],
117 'group_id': ['5470'],
118 'set': ['custom'],
119 })
120 ]
121
Guido van Rossum47b9ff62006-08-24 00:41:19 +0000122def norm(seq):
Guido van Rossumcc2b0162007-02-11 06:12:03 +0000123 return sorted(seq, key=repr)
Jeremy Hyltond9827c42000-08-03 22:11:43 +0000124
125def first_elts(list):
Guido van Rossumc1f779c2007-07-03 08:25:58 +0000126 return [p[0] for p in list]
Jeremy Hyltond9827c42000-08-03 22:11:43 +0000127
128def first_second_elts(list):
Guido van Rossumc1f779c2007-07-03 08:25:58 +0000129 return [(p[0], p[1][0]) for p in list]
130
Benjamin Petersondcf97b92008-07-02 17:30:14 +0000131def gen_result(data, environ):
132 fake_stdin = StringIO(data)
133 fake_stdin.seek(0)
134 form = cgi.FieldStorage(fp=fake_stdin, environ=environ)
135
136 result = {}
137 for k, v in dict(form).items():
138 result[k] = type(v) is list and form.getlist(k) or v.value
139
140 return result
Jeremy Hyltond9827c42000-08-03 22:11:43 +0000141
Thomas Wouters89f507f2006-12-13 04:49:30 +0000142class CgiTests(unittest.TestCase):
Neil Schemenauer66edb622004-07-19 15:38:11 +0000143
Thomas Wouters89f507f2006-12-13 04:49:30 +0000144 def test_qsl(self):
145 for orig, expect in parse_qsl_test_cases:
146 result = cgi.parse_qsl(orig, keep_blank_values=True)
147 self.assertEqual(result, expect, "Error parsing %s" % repr(orig))
Jeremy Hyltond9827c42000-08-03 22:11:43 +0000148
Thomas Wouters89f507f2006-12-13 04:49:30 +0000149 def test_strict(self):
150 for orig, expect in parse_strict_test_cases:
151 # Test basic parsing
152 d = do_test(orig, "GET")
153 self.assertEqual(d, expect, "Error parsing %s" % repr(orig))
154 d = do_test(orig, "POST")
155 self.assertEqual(d, expect, "Error parsing %s" % repr(orig))
156
157 env = {'QUERY_STRING': orig}
Thomas Wouters89f507f2006-12-13 04:49:30 +0000158 fs = cgi.FieldStorage(environ=env)
159 if type(expect) == type({}):
160 # test dict interface
Georg Brandl49d1b4f2008-05-11 21:42:51 +0000161 self.assertEqual(len(expect), len(fs))
162 self.assertEqual(norm(expect.keys()), norm(fs.keys()))
163 ##self.assertEqual(norm(expect.values()), norm(fs.values()))
164 ##self.assertEqual(norm(expect.items()), norm(fs.items()))
Thomas Wouters89f507f2006-12-13 04:49:30 +0000165 self.assertEqual(fs.getvalue("nonexistent field", "default"), "default")
166 # test individual fields
167 for key in expect.keys():
168 expect_val = expect[key]
Thomas Wouters89f507f2006-12-13 04:49:30 +0000169 self.assert_(key in fs)
170 if len(expect_val) > 1:
Thomas Wouters89f507f2006-12-13 04:49:30 +0000171 self.assertEqual(fs.getvalue(key), expect_val)
172 else:
Thomas Wouters89f507f2006-12-13 04:49:30 +0000173 self.assertEqual(fs.getvalue(key), expect_val[0])
Thomas Wouters89f507f2006-12-13 04:49:30 +0000174
175 def test_log(self):
176 cgi.log("Testing")
177
178 cgi.logfp = StringIO()
179 cgi.initlog("%s", "Testing initlog 1")
180 cgi.log("%s", "Testing log 2")
181 self.assertEqual(cgi.logfp.getvalue(), "Testing initlog 1\nTesting log 2\n")
182 if os.path.exists("/dev/null"):
183 cgi.logfp = None
184 cgi.logfile = "/dev/null"
185 cgi.initlog("%s", "Testing log 3")
186 cgi.log("Testing log 4")
187
188 def test_fieldstorage_readline(self):
189 # FieldStorage uses readline, which has the capacity to read all
190 # contents of the input file into memory; we use readline's size argument
191 # to prevent that for files that do not contain any newlines in
192 # non-GET/HEAD requests
193 class TestReadlineFile:
194 def __init__(self, file):
195 self.file = file
196 self.numcalls = 0
197
198 def readline(self, size=None):
199 self.numcalls += 1
200 if size:
201 return self.file.readline(size)
Jeremy Hyltond9827c42000-08-03 22:11:43 +0000202 else:
Thomas Wouters89f507f2006-12-13 04:49:30 +0000203 return self.file.readline()
Jeremy Hyltond9827c42000-08-03 22:11:43 +0000204
Thomas Wouters89f507f2006-12-13 04:49:30 +0000205 def __getattr__(self, name):
206 file = self.__dict__['file']
207 a = getattr(file, name)
208 if not isinstance(a, int):
209 setattr(self, name, a)
210 return a
Jeremy Hyltond9827c42000-08-03 22:11:43 +0000211
Guido van Rossuma1a68522007-08-28 03:11:34 +0000212 f = TestReadlineFile(tempfile.TemporaryFile("w+"))
213 f.write('x' * 256 * 1024)
Thomas Wouters89f507f2006-12-13 04:49:30 +0000214 f.seek(0)
215 env = {'REQUEST_METHOD':'PUT'}
216 fs = cgi.FieldStorage(fp=f, environ=env)
217 # if we're not chunking properly, readline is only called twice
218 # (by read_binary); if we are chunking properly, it will be called 5 times
219 # as long as the chunksize is 1 << 16.
220 self.assert_(f.numcalls > 2)
Jeremy Hyltond9827c42000-08-03 22:11:43 +0000221
Thomas Wouters89f507f2006-12-13 04:49:30 +0000222 def test_fieldstorage_multipart(self):
223 #Test basic FieldStorage multipart parsing
224 env = {'REQUEST_METHOD':'POST', 'CONTENT_TYPE':'multipart/form-data; boundary=---------------------------721837373350705526688164684', 'CONTENT_LENGTH':'558'}
225 postdata = """-----------------------------721837373350705526688164684
Thomas Wouters00ee7ba2006-08-21 19:07:27 +0000226Content-Disposition: form-data; name="id"
227
2281234
229-----------------------------721837373350705526688164684
230Content-Disposition: form-data; name="title"
231
232
233-----------------------------721837373350705526688164684
234Content-Disposition: form-data; name="file"; filename="test.txt"
235Content-Type: text/plain
236
237Testing 123.
238
239-----------------------------721837373350705526688164684
240Content-Disposition: form-data; name="submit"
241
242 Add\x20
243-----------------------------721837373350705526688164684--
244"""
Thomas Wouters89f507f2006-12-13 04:49:30 +0000245 fs = cgi.FieldStorage(fp=StringIO(postdata), environ=env)
246 self.assertEquals(len(fs.list), 4)
247 expect = [{'name':'id', 'filename':None, 'value':'1234'},
248 {'name':'title', 'filename':None, 'value':''},
Barry Warsaw596097e2008-06-12 02:38:51 +0000249 {'name':'file', 'filename':'test.txt', 'value':'Testing 123.'},
Thomas Wouters89f507f2006-12-13 04:49:30 +0000250 {'name':'submit', 'filename':None, 'value':' Add '}]
251 for x in range(len(fs.list)):
252 for k, exp in expect[x].items():
253 got = getattr(fs.list[x], k)
254 self.assertEquals(got, exp)
Thomas Wouters00ee7ba2006-08-21 19:07:27 +0000255
Benjamin Petersondcf97b92008-07-02 17:30:14 +0000256 _qs_result = {
257 'key1': 'value1',
258 'key2': ['value2x', 'value2y'],
259 'key3': 'value3',
260 'key4': 'value4'
261 }
262 def testQSAndUrlEncode(self):
263 data = "key2=value2x&key3=value3&key4=value4"
264 environ = {
265 'CONTENT_LENGTH': str(len(data)),
266 'CONTENT_TYPE': 'application/x-www-form-urlencoded',
267 'QUERY_STRING': 'key1=value1&key2=value2y',
268 'REQUEST_METHOD': 'POST',
269 }
270 v = gen_result(data, environ)
271 self.assertEqual(self._qs_result, v)
272
273 def testQSAndFormData(self):
274 data = """
275---123
276Content-Disposition: form-data; name="key2"
277
278value2y
279---123
280Content-Disposition: form-data; name="key3"
281
282value3
283---123
284Content-Disposition: form-data; name="key4"
285
286value4
287---123--
288"""
289 environ = {
290 'CONTENT_LENGTH': str(len(data)),
291 'CONTENT_TYPE': 'multipart/form-data; boundary=-123',
292 'QUERY_STRING': 'key1=value1&key2=value2x',
293 'REQUEST_METHOD': 'POST',
294 }
295 v = gen_result(data, environ)
296 self.assertEqual(self._qs_result, v)
297
298 def testQSAndFormDataFile(self):
299 data = """
300---123
301Content-Disposition: form-data; name="key2"
302
303value2y
304---123
305Content-Disposition: form-data; name="key3"
306
307value3
308---123
309Content-Disposition: form-data; name="key4"
310
311value4
312---123
313Content-Disposition: form-data; name="upload"; filename="fake.txt"
314Content-Type: text/plain
315
316this is the content of the fake file
317
318---123--
319"""
320 environ = {
321 'CONTENT_LENGTH': str(len(data)),
322 'CONTENT_TYPE': 'multipart/form-data; boundary=-123',
323 'QUERY_STRING': 'key1=value1&key2=value2x',
324 'REQUEST_METHOD': 'POST',
325 }
326 result = self._qs_result.copy()
327 result.update({
328 'upload': 'this is the content of the fake file'
329 })
330 v = gen_result(data, environ)
331 self.assertEqual(result, v)
332
Thomas Wouters89f507f2006-12-13 04:49:30 +0000333def test_main():
334 run_unittest(CgiTests)
335
336if __name__ == '__main__':
337 test_main()