Use stricter/platform-independent IP parsing for X-Forwarded-For #903

bdarnell opened this Issue Sep 22, 2013 · 0 comments


None yet

1 participant


netutil.is_valid_ip uses getaddrinfo in AI_NUMERICHOST mode to parse IP addresses. This method accepts some surprising formats (e.g. "x.y" is parsed as x.(y >> 16).((y>>8)&0xff).(y&0xff), at least on mac and linux). It would be good to limit this to a more formal specification (e.g. the one in, which is cited in

@bdarnell bdarnell added the httpserver label Jul 16, 2014
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment