Skip to content

fix: reject trailing newline in slug and control characters in telnet URIs - #492

Merged
nandgator merged 2 commits into
masterfrom
fix-slug-telnet-newline
Oct 10, 2026
Merged

nandgator merged 2 commits into
masterfrom
fix-slug-telnet-newline

Conversation

@nandgator

Copy link
Copy Markdown
Collaborator

Follow-up to #439 and #446, whose review fixes did not make it into the merge.

  • slug(): use fullmatch so $ no longer accepts a trailing newline (Django's validate_slug anchors with \Z for the same reason).
  • telnet URIs: urlsplit silently strips tabs and newlines, so telnet://example.com\n and telnet://exa\nmple.com were accepted. Reject whitespace and non-printable characters up front, and fix a docstring typo.

Both come with tests.

🤖 Generated with Claude Code

@nandgator
nandgator merged commit 3aa3b67 into master Oct 10, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant