|
|
|
|
|
by gsnedders
3567 days ago
|
|
Hopefully the URL spec (https://url.spec.whatwg.org) is helpful here in finding other potentially unsafe behaviours that browsers have, though given much of it seems to be dealing with the fact that urllib.urlparse doesn't match what browsers do in many, many ways it's probably of limited help. (Nobody really implements it yet; it's just an attempt at standardising rough intersection semantics of what browsers currently do. Eventually, however, it should suffice, once legacy browsers eventually die.) |
|
They’re unwilling to modify anything, or standardize anything, but just want to cement the current piece of shit that URL parsing it for the future.