You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
assignee=Noneclosed_at=<Date2011-05-19.11:49:06.915>created_at=<Date2011-05-19.11:37:22.237>labels= ['type-feature', 'library']
title="email's use of __setitem__ is highly counterintuitive"updated_at=<Date2011-05-19.11:49:06.912>user='https://bugs.python.org/tonimueller'
email's usage of __setitem__ is highly counterintuitive to the point of being dangerous. The documented behaviour is (quote):
__setitem__(name, val)
Add a header to the message with field name name and value val. The field is appended to the end of the message’s existing fields.
Note that this does not overwrite or delete any existing header with the same name. If you want to ensure that the new header is the only one present in the message with field name name, delete the field first, e.g.:
The use case of *appending* a header of the same type (eg. a "Received:" header) should be performed by the add_header() method, or an extend_header() method, or something similar, and not by abusing the __setitem__ method. The current behaviour imho deviates extremely from the behaviour of similar libraries in all other programming languages that I'm aware of, and from the standard dict functionality, too. It makes it much too easy to have duplicate headers, esp., duplicate "To:" headers, resulting in mailbombing and information leakage. For the potential damage, this property of the library is highly under-advertised.
A side effect appears to be that trying to have your message headers set up in a unique fashion, probably the most frequent use case, one has to make sure to use each operator only once, or "decorate" everything with a del msg[myheader], as the operation is not idempotent.
This is a long-standing design choice in the email package. If you want to advocate for changing it, please join the email-sig mailing list (see mail.python.org). We are in the process of developing a new version, which will at least reject things like duplicate To headers.
I'm closing this issue since as things stand this is not something that is likely to change. If you carry the day in a discussion on the email-sig, we can reopen the issue. In any case it is a feature request, not a bug.
Note: these values reflect the state of the issue at the time it was migrated and might not reflect the current state.
Show more details
GitHub fields:
bugs.python.org fields:
The text was updated successfully, but these errors were encountered: