NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #1859 most downloaded on PyPI
WSGI request and response object
Last release 2 months ago
02 Aug 2026
Ships unpredictably
gaps range from 4 weeks to 3.5 years
Most releases are documented
notes for 49 of the last 60 stable releases
Nothing withdrawn
no release was ever pulled
19 years old
75 releases · first in 2007
Open redirect in Location header normalization via leading C0 control / space characters
Open redirect in Location header normalization via leading C0 control / space characters
Security Fix
- The fixes for CVE-2024-42353 and GHSA-fh3h-vg37-cc95 were still
incomplete: besides removing tab, CR, and LF, ``urllib.parse.urljoin``
also strips leading and trailing C0 control and space characters from a
URL before parsing it. A Location value such as
``" //www.example.com/test"`` could therefore still be interpreted as a
protocol-relative URL (and ``" https://www.example.com/test"`` as an
absolute one), allowing an open redirect.
WebOb no longer uses ``urllib.parse.urljoin`` and instead ships its own
implementation of the RFC 3986 reference resolution algorithm,
``webob.util.urljoin``, which resolves the URL exactly as given without
removing any characters. It is now used to make the Location header
absolute, by ``Request.relative_url``, and by the ``_HTTPMove`` based
HTTP exceptions, which normalize the Location header through the same
code path as the Response object (so a protocol-relative location
passed to e.g. ``HTTPFound`` no longer redirects off-host either).
See https://github.com/Pylons/webob/security/advisories/GHSA-6hx8-3wjj-gr8g
One column per quarter.
Fix open redirect issue due to changes made in cPython >=3.10
Fix open redirect issue due to changes made in cPython >=3.10
Security Fix
- The fix for CVE-2024-42353 was incomplete: a Location value containing
ASCII tab, carriage return, or line feed characters between consecutive
slashes could still be interpreted as a protocol-relative URL by
``urllib.parse.urljoin`` on Python 3.10+, allowing an open redirect.
See https://github.com/Pylons/webob/security/advisories/GHSA-fh3h-vg37-cc95
Thanks to Caleb Brown of Google for the report.
Add info for 1.8.9 fix for Python 3.13
Add info for 1.8.9 fix for Python 3.13
Bugfix
- Add `legacy-cgi` to required packages to be installed for Python 3.13
compatibility. See https://github.com/Pylons/webob/pull/469
Fix open redirect issue in 1.8-branch
Fix open redirect issue in 1.8-branch
Security Fix
- The use of WebOb's Response object to redirect a request to a new location
can lead to an open redirect if the Location header is not a full URI.
See https://github.com/Pylons/webob/security/advisories/GHSA-mg3v-6m49-jhp3
and CVE-2024-42353
Thanks to Sara Gao for the report
Decoding deflate-encoded responses now supports data which is packed in a zlib container as it is supposed to be. The old, non-standard behaviour is s
Bugfix
- Decoding deflate-encoded responses now supports data which is packed in
a zlib container as it is supposed to be. The old, non-standard behaviour
is still supported.
See https://github.com/Pylons/webob/pull/426
…SameSite on cookies by default, so there is no backwards incompatible change here.
Experimental Features
- The SameSite value now includes a new option named "None", this is a new
change that was introduced in
https://tools.ietf.org/html/draft-west-cookie-incrementalism-00
Please be aware that older clients are incompatible with this change:
https://www.chromium.org/updates/same-site/incompatible-clients, WebOb does
not enable SameSite on cookies by default, so there is no backwards
incompatible change here.
See https://github.com/Pylons/webob/issues/406
- Validation of SameSite values can be disabled by toggling a module flag. This
is in anticipation of future changes in evolving cookie standards.
The discussion in https://github.com/Pylons/webob/pull/407 (which initially
expanded the allowed options) notes the sudden change to browser cookie
implementation details may happen again.
In May 2019, Google announced a new model for privacy controls in their
browsers, which affected the list of valid options for the SameSite attribute
of cookies. In late 2019, the company began to roll out these changes to their
browsers to force developer adoption of the new specification.
See https://www.chromium.org/updates/same-site and
https://blog.chromium.org/2019/10/developers-get-ready-for-new.html for more
details on this change.
See https://github.com/Pylons/webob/pull/409
Fixed one last remaining invalid escape sequence in a docstring.
Warnings
- Fixed one last remaining invalid escape sequence in a docstring.
Some backslashes introduced with the new accept handling code were causing DeprecationWarnings upon compiling the source to pyc files, all of the back…
Bugfix
- Response.content_type now accepts unicode strings on Python 2 and encodes
them to latin-1. See https://github.com/Pylons/webob/pull/389 and
https://github.com/Pylons/webob/issues/388
- Accept header classes now support a .copy() function that may be used to
create a copy. This allows ``create_accept_header`` and other like functions
to accept an pre-existing Accept header. See
https://github.com/Pylons/webob/pull/386 and
https://github.com/Pylons/webob/issues/385
Warnings
acceptparse.AcceptValidHeader, acceptparse.AcceptInvalidHeader, and acceptparse.AcceptNoHeader will now always ignore offers that do not match the req
Bugfix
- ``acceptparse.AcceptValidHeader``, ``acceptparse.AcceptInvalidHeader``, and
``acceptparse.AcceptNoHeader`` will now always ignore offers that do not
match the required media type grammar when calling ``.acceptable_offers()``.
Previous versions raised a ``ValueError`` for invalid offers in
``AcceptValidHeader`` and returned them as acceptable in the others.
See https://github.com/Pylons/webob/pull/372
Feature
Add Request.remote_host, exposing REMOTE_HOST environment variable.
Added acceptparse.Accept.parse_offer to codify what types of offers
are compatible with acceptparse.AcceptValidHeader.acceptable_offers,
acceptparse.AcceptMissingHeader.acceptable_offers, and
acceptparse.AcceptInvalidHeader.acceptable_offers. This API also
normalizes the offer with lowercased type/subtype and parameter names.
See https://github.com/Pylons/webob/pull/376 and
https://github.com/Pylons/webob/pull/379
SameSite may now be passed as str or bytes to Response.set_cookie and cookies.make_cookie. This was an oversight as all other arguments would be corre
Bugfix
- SameSite may now be passed as str or bytes to `Response.set_cookie` and
`cookies.make_cookie`. This was an oversight as all other arguments would be
correctly coerced before being serialized. See
https://github.com/Pylons/webob/issues/361 and
https://github.com/Pylons/webob/pull/362
acceptparse.MIMEAccept which is deprecated in WebOb 1.8.0 made a backwards incompatible change that led to it raising on an invalid Accept header. Thi…
Bugfix
- acceptparse.MIMEAccept which is deprecated in WebOb 1.8.0 made a backwards
incompatible change that led to it raising on an invalid Accept header. This
behaviour has now been reversed, as well as some other fixes to allow
MIMEAccept to behave more like the old version. See
https://github.com/Pylons/webob/pull/356
Backwards Incompatibilities ~~~~~~~~~~~~~~~~~~~~~~~~~~~
Feature
- ``request.POST`` now supports any requests with the appropriate
Content-Type. Allowing any HTTP method to access form encoded content,
including DELETE, PUT, and others. See
https://github.com/Pylons/webob/pull/352
Compatibility
Backwards Incompatibilities
- Many changes have been made to the way WebOb does Accept handling, not just
for the Accept header itself, but also for Accept-Charset, Accept-Encoding
and Accept-Language. This was a `Google Summer of Code
<https://summerofcode.withgoogle.com/>`_ project completed by
Whiteroses (https://github.com/whiteroses). Many thanks to Google for running
GSoC, the Python Software Foundation for organising and a huge thanks to Ira
for completing the work. See https://github.com/Pylons/webob/pull/338 and
https://github.com/Pylons/webob/pull/335. Documentation is available at
https://docs.pylonsproject.org/projects/webob/en/main/api/webob.html
- When calling a ``@wsgify`` decorated function, the default arguments passed
to ``@wsgify`` are now used when called with the request, and not as a
`start_response`
.. code::
def hello(req, name):
return "Hello, %s!" % name
app = wsgify(hello, args=("Fred",))
req = Request.blank('/')
resp = req.get_response(app) # => "Hello, Fred"
resp2 = app(req) # => "Hello, Fred"
Previously the ``resp2`` line would have failed with a ``TypeError``. With
this change there is no way to override the default arguments with no
arguments. See https://github.com/Pylons/webob/pull/203
- When setting ``app_iter`` on a ``Response`` object the ``content_md5`` header
is no longer cleared. This behaviour is odd and disallows setting the
``content_md5`` and then returning an iterator for chunked content encoded
responses. See https://github.com/Pylons/webob/issues/86
Experimental Features
~~~~~~~~~~~~~~~~~~~~~
These features are experimental and may change at any point in the future.
- The cookie APIs now have the ability to set the SameSite attribute on a
cookie in both ``webob.cookies.make_cookie`` and
``webob.cookies.CookieProfile``. See https://github.com/Pylons/webob/pull/255
Bugfix
~~~~~~
- Exceptions now use string.Template.safe_substitute rather than
string.Template.substitute. The latter would raise for missing mappings, the
former will simply not substitute the missing variable. This is safer in case
the WSGI environ does not contain the keys necessary for the body template.
See https://github.com/Pylons/webob/issues/345.
- Request.host_url, Request.host_port, Request.domain correctly parse IPv6 Host
headers as provided by a browser. See
https://github.com/Pylons/webob/pull/332
- Request.authorization would raise ValueError for unusual or malformed header
values. See https://github.com/Pylons/webob/issues/231
- Allow unnamed fields in form data to be properly transcoded when calling
request.decode with an alternate encoding. See
https://github.com/Pylons/webob/pull/309
- ``Response.__init__`` would discard ``app_iter`` when a ``Response`` had no
body, this would cause issues when ``app_iter`` was an object that was tied
to the life-cycle of a web application and had to be properly closed.
``app_iter`` is more advanced API for ``Response`` and thus even if it
contains a body and is thus against the HTTP RFC's, we should let the users
shoot themselves by returning a body. See
https://github.com/Pylons/webob/issues/305
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Python 3.2 is no longer supported by WebOb
Compatibility
- Python 3.2 is no longer supported by WebOb
Bugfix
~~~~~~
- Request.decode attempted to read from the an already consumed stream, it has
now been redirected to another stream to read from. See
https://github.com/Pylons/webob/pull/183
- The application/json media type does not allow for a charset as discovery of
the encoding is done at the JSON layer. Upon initialization of a Response
WebOb will no longer add a charset if the content-type is set to JSON. See
https://github.com/Pylons/webob/pull/197 and
https://github.com/Pylons/pyramid/issues/1611
Features
~~~~~~~~
- Lazily HTML escapes environment keys in HTTP Exceptions so that those keys in
the environ that are not used in the output of the page don't raise an
exception due to inability to be properly escaped. See
https://github.com/Pylons/webob/pull/139
- MIMEAccept now accepts comparisons against wildcards, this allows one to
match on just the media type or sub-type, without having to explicitly match
on both the media type and sub-type at the same time. See
https://github.com/Pylons/webob/pull/185
- Add the ability to return a JSON body from an exception. Using the Accept
information in the request, the exceptions will now automatically return a
JSON version of the exception instead of just HTML or text. See
https://github.com/Pylons/webob/pull/230 and
https://github.com/Pylons/webob/issues/209
Security
~~~~~~~~
- exc._HTTPMove and any subclasses will now raise a ValueError if the location
field contains a line feed or carriage return. These values may lead to
possible HTTP Response Splitting. The header_getter descriptor has also been
modified to no longer accept headers with a line feed or carriage return.
See: https://github.com/Pylons/webob/pull/229 and
https://github.com/Pylons/webob/issues/217
Nothing published for this version
The exceptions HTTPNotAcceptable, HTTPUnsupportedMediaType and HTTPNotImplemented will now correctly use the sub-classed template rather than the defa
Bug Fixes
- The exceptions HTTPNotAcceptable, HTTPUnsupportedMediaType and
HTTPNotImplemented will now correctly use the sub-classed template rather
than the default error template. See https://github.com/Pylons/webob/issues/221
- Response's from_file now correctly deals with a status line that contains an
HTTP version identifier. HTTP/1.1 200 OK is now correctly parsed, whereas
before this would raise an error upon setting the Response.status in
from_file. See https://github.com/Pylons/webob/issues/121
Backwards Incompatibilities ~~~~~~~~~~~~~~~~~~~~~~~~~~~
Bug Fixes
- The cookie API functions will now make sure that `max_age` is an integer or
an string that can convert to an integer. Previously passing in
max_age='test' would have silently done the wrong thing.
Features
~~~~~~~~
- Unbreak req.POST when the request method is PATCH. Instead of returning
something cmpletely unrelated we return NoVar. See:
https://github.com/Pylons/webob/pull/215
- HTTP Status Code 308 is now supported as a Permanent Redirect. See
https://github.com/Pylons/webob/pull/207
Backwards Incompatibilities
Response.set_cookie renamed the only required parameter from "key" to
"name". The code will now still accept "key" as a keyword argument, and will
issue a DeprecationWarning until WebOb 1.7.
The status attribute of a Response object no longer takes a string
like None None and allows that to be set as the status. It now has to at
least match the pattern of <integer status code> <explenation of status code>. Invalid status strings will now raise a ValueError.
Nothing published for this version
Nothing published for this version
Backwards Incompatibilities ~~~~~~~~~~~~~~~~~~~~~~~~~~~
Backwards Incompatibilities
- ``Morsel`` will no longer accept a cookie value that does not meet RFC6265's
cookie-octet specification. Upon calling ``Morsel.serialize`` a warning will
be issued, in the future this will raise a ``ValueError``, please update your
cookie handling code. See https://github.com/Pylons/webob/pull/172
The cookie-octet specification in RFC6265 states the following characters are
valid in a cookie value:
=============== =======================================
Hex Range Actual Characters
=============== =======================================
``[0x21 ]`` ``!``
``[0x25-0x2B]`` ``#$%&'()*+``
``[0x2D-0x3A]`` ``-./0123456789:``
``[0x3C-0x5B]`` ``<=>?@ABCDEFGHIJKLMNOPQRSTUVWXYZ[``
``[0x5D-0x7E]`` ``]^_`abcdefghijklmnopqrstuvwxyz{|}~``
=============== =======================================
RFC6265 suggests using base 64 to serialize data before storing data in a
cookie.
Cookies that meet the RFC6265 standard will no longer be quoted, as this is
unnecessary. This is a no-op as far as browsers and cookie storage is
concerned.
- ``Response.set_cookie`` now uses the internal ``make_cookie`` API, which will
issue warnings if cookies are set with invalid bytes. See
https://github.com/Pylons/webob/pull/172
Features
~~~~~~~~
- Add support for some new caching headers, stale-while-revalidate and
stale-if-error that can be used by reverse proxies to cache stale responses
temporarily if the backend disappears. From RFC5861. See
https://github.com/Pylons/webob/pull/189
Bug Fixes
~~~~~~~~~
- Response.status now uses duck-typing for integers, and has also learned to
raise a ValueError if the status isn't an integer followed by a space, and
then the reason. See https://github.com/Pylons/webob/pull/191
- Fixed a bug in ``webob.multidict.GetDict`` which resulted in the
QUERY_STRING not being updated when changes were made to query
params using ``Request.GET.extend()``.
- Read the body of a request if we think it might have a body. This fixes PATCH
to support bodies. See https://github.com/Pylons/webob/pull/184
- Response.from_file returns HTTP headers as latin1 rather than UTF-8, this
fixes the usage on Google AppEngine. See
https://github.com/Pylons/webob/issues/99 and
https://github.com/Pylons/webob/pull/150
- Fix a bug in parsing the auth parameters that contained bad white space. This
makes the parsing fall in line with what's required in RFC7235. See
https://github.com/Pylons/webob/issues/158
- Use '\r\n' line endings in ``Response.__str__``. See:
https://github.com/Pylons/webob/pull/146
Documentation Changes
~~~~~~~~~~~~~~~~~~~~~
- ``response.set_cookie`` now has proper documentation for ``max_age`` and
``expires``. The code has also been refactored to use ``cookies.make_cookie``
instead of duplicating the code. This fixes
https://github.com/Pylons/webob/issues/166 and
https://github.com/Pylons/webob/issues/171
- Documentation didn't match the actual code for the wsgify function signature.
See https://github.com/Pylons/webob/pull/167
- Remove the WebDAV only from certain HTTP Exceptions, these exceptions may
also be used by REST services for example.
Nothing published for this version
Nothing published for this version
Remove webob.__version__, the version number had not been kept in sync with the official pkg version. To obtain the WebOb version number, use pkg_reso
Features
- Remove ``webob.__version__``, the version number had not been kept in sync
with the official pkg version. To obtain the WebOb version number, use
``pkg_resources.get_distribution('webob').version`` instead.
Bug Fixes
Fix a bug in EmptyResponse that prevents it from setting self.close as
appropriate due to testing truthiness of object rather than if it is
something other than None.
Fix a bug in SignedSerializer preventing secrets from containing
higher-order characters. See https://github.com/Pylons/webob/issues/136
Use the hmac.compare_digest method when available for constant-time
comparisons.
Backwards Incompatibilities ~~~~~~~~~~~~~~~~~~~~~~~~~~~
Bug Fixes
- Fix a bug in ``SignedCookieProfile`` whereby we didn't keep the original
serializer around, this would cause us to have ``SignedSerializer`` be added on
top of a ``SignedSerializer`` which would cause it to be run twice when
attempting to verify a cookie. See https://github.com/Pylons/webob/pull/127
Backwards Incompatibilities
CookieProfile.get_value and SignedCookieProfile.get_value fails
to deserialize a badly encoded value, we now return None as if the cookie
was never set in the first place instead of allowing a ValueError to be
raised to the calling code. See https://github.com/Pylons/webob/pull/126Added a read-only domain property to BaseRequest. This property returns the domain portion of the host value. For example, if the environment contains
Features
- Added a read-only ``domain`` property to ``BaseRequest``. This property
returns the domain portion of the host value. For example, if the
environment contains an ``HTTP_HOST`` value of ``foo.example.com:8000``,
``request.domain`` will return ``foo.example.com``.
- Added five new APIs: ``webob.cookies.CookieProfile``,
``webob.cookies.SignedCookieProfile``, ``webob.cookies.JSONSerializer`` and
``webob.cookies.SignedSerializer``, and ``webob.cookies.make_cookie``. These
APIs are convenience APIs for generating and parsing cookie headers as well
as dealing with signing cookies.
- Cookies generated via webob.cookies quoted characters in cookie values that
did not need to be quoted per RFC 6265. The following characters are no
longer quoted in cookie values: ``~/=<>()[]{}?@`` . The full set of
non-letter-or-digit unquoted cookie value characters is now
``!#$%&'*+-.^_`|~/: =<>()[]{}?@``. See
https://tools.ietf.org/html/rfc6265#section-4.1.1 for more information.
- Cookie names are now restricted to the set of characters expected by RFC
6265. Previously they could contain unsupported characters such as ``/``.
- Older versions of Webob escaped the doublequote to ``\"`` and the backslash
to ``\\`` when quoting cookie values. Now, instead, cookie serialization
generates ``\042`` for the doublequote and ``\134`` for the backslash. This
is what is expected as per RFC 6265. Note that old cookie values that do
have the older style quoting in them will still be unquoted correctly,
however.
- Added support for draft status code 451 ("Unavailable for Legal Reasons").
See https://tools.ietf.org/html/draft-tbray-http-legally-restricted-status-00
- Added status codes 428, 429, 431 and 511 to ``util.status_reasons`` (they
were already present in a previous release as ``webob.exc`` exceptions).
Bug Fixes
MIMEAccept happily parsed malformed wildcard strings like "image/pn*" at parse time, but then threw an AssertionError during matching. See https://github.com/Pylons/webob/pull/83 .
Preserve document ordering of GET and POST request data when POST data passed to Request.blank is a MultiDict. See https://github.com/Pylons/webob/pull/96
Allow query strings attached to PATCH requests to populate request.params. See https://github.com/Pylons/webob/pull/106
Added Python 3.3 trove classifier.
Maintainership transferred to Pylons Project
Maintainership transferred to Pylons Project <http://www.pylonsproject.org/>
Fix parsing of form submissions where fields have transfer-content-encoding headers.
Fix multiple calls to cache_expires() not fully overriding the previously set headers.
Fix multiple calls to cache_expires() not fully overriding the
previously set headers.
Fix parsing of form submissions where fields have different encodings.
Fix docs references to some deprecated classes.
Add index page (e.g., index.html) support for webob.static.DirectoryApp.
Detect mime-type when creating a test request with file uploads (Request.blank("/", POST=dict(file1=("foo.jpg", "xxx"))))
Relax parsing of Accept and Range headers to allow uppercase and extra whitespace.
Fix docs references to some deprecated classes.
Fix webob.client handling of connection-refused on Windows.
Fix webob.client handling of connection-refused on Windows.
Use simplejson in webob.request if present.
Fix resp.retry_after = <long> interpreting value as a UNIX timestamp (should interpret as time delta in seconds).
Add Response.json and Request.json which reads and sets the body using a JSON encoding (previously only the readable attribute Request.json_body exist
Add Response.json and Request.json which reads and sets the body using a JSON encoding (previously only the readable attribute Request.json_body existed). Request.json_body is still available as an alias.
Rename Response.status_int to Response.status_code (the .status_int name is still available and will be supported indefinitely).
Add Request.text, the unicode version of the request body (similar to Response.text).
Add webob.client which contains the WSGI application send_request_app and SendRequest. All requests sent to this application are turned into HTTP requests.
Renamed Request.get_response(app) to Request.send(app). The .get_response() name is still available.
Use send_request_app as the default application for Request.send(), so you can do:
resp = Request.blank("http://python.org").send()
Add webob.static which contains two new WSGI applications, FileApp serve one static file and DirectoryApp to serve the content of a directory. They should provide a reusable implementation of file-example. It also comes with support for wsgi.file_wrapper.
The implementation has been imported and simplified from PasteOb.fileapp.
Add dev and docs setup.py aliases (to install development and docs dependencies respectively, e.g. "python setup.py dev").
Backwards incompatibility: Request and BaseRequest objects now return Unicode for request.path_info and request.script_name under Python
Added request.host_port API (returns port number implied by HTTP_HOST,
falling back to SERVER_PORT).
Added request.client_addr API (returns IP address implied by
HTTP_X_FORWARDED_FOR, falling back to REMOTE_ADDR).
Fix corner-case response.status_int and response.status mutation
bug on py3 (use explicit floor division).
Backwards incompatibility: Request and BaseRequest objects now return
Unicode for request.path_info and request.script_name under Python
2. Rationale: the legacy behavior of returning the respective raw environ
values was nonsensical on Python 3. Working with non-ascii encoded environ
variables as raw WSGI values under Python 3 makes no sense, as PEP 3333
specifies that environ variables are bytes-tunneled-as-latin-1 strings.
If you don't care about Python 3, and you need strict backwards
compatibility, to get legacy behavior of returning bytes on Python 2 for
these attributes, use webob.LegacyRequest instead of webob.Request.
Although it's possible to use webob.LegacyRequest under Python 3, it
makes no sense, and it should not be used there.
The above backwards incompatibility fixed nonsensical behavior of
request.host_url, request.application_url, request.path_url,
request.path, request.path_qs, request.url,
request.relative_url, request.path_info_peek,
request.path_info_pop under Python 3. These methods previously dealt
with raw SCRIPT_NAME and PATH_INFO values, which caused nonsensical
results.
The WebOb Request object now respects an additional WSGI environment
variable: webob.url_encoding. webob.url_encoding will be used to
decode the raw WSGI PATH_INFO and SCRIPT_NAME variables when the
request.path_info and request.script_name APIs are used.
Request objects now accept an additional constructor parameter:
url_encoding. url_encoding will be used to decode PATH_INFO and
SCRIPT_NAME from its WSGI-encoded values. If webob.url_encoding is not
set in the environ and url_encoding is not passed to the Request
constructor, the default value utf-8 will be used to decode the
PATH_INFO and SCRIPT_NAME.
Note that passing url_encoding will cause the WSGI environment variable
webob.url_encoding to be set.
Fix webob.response._request_uri internal function to generate sensible
request URI under Python 3. This fixed a problem under Python 3 if you
were using non-absolute Location headers in responses.
Fix request.cookies.get('name', 'default'). Previously default was ignored.
request.cookies.get('name', 'default'). Previously default was
ignored.Response.request and Response.environ attrs are undeprecated and no longer raise exceptions when used. These can also be passed to the Response constr…
Mutating the request.cookies property now reflects the mutations into
the HTTP_COOKIES environ header.
Response.etag = (tag, False) sets weak etag.
Range only parses single range now.
Range.satisfiable(..) is gone.
Accept.best_matches() is gone; use list(request.accept) or
request.accept.best_match(..) instead (applies to all Accept-*
headers) or similar with request.accept_language.
Response.request and Response.environ attrs are undeprecated and no
longer raise exceptions when used. These can also be passed to the
Response constructor. This is to support codebases that pass them to the
constructor or assign them to a response instance. However, some behavior
differences from 1.1 exist. In particular, synchronization is no longer
done between environ and request attribute properties of Response; you may
pass either to the constructor (or both) or assign one or the other or
both, but they wont be managed specially and will remain the same over the
lifetime of the response just as you passed them. Default values for both
request and environ on any given response are None now.
Undeprecated uscript_name and upath_info.
For backwards compatibility purposes, switch req.script_name and
path_info back again to contain "raw" undecoded native strings rather
than text. Use uscript_name and upath_info to get the text version
of SCRIPT_NAME and PATH_INFO.
Don't raise an exception if unicode_errors or decode_param_names is
passed to the Request constructor. Instead, emit a warning. For benefit
of Pylons 1.X, which passes both.
Don't raise an exception if HTTPException.exception is used; instead emit a warning. For benefit of Pylons 1.X, which uses it.
Deprecate Response.request and Response.environ attrs.
Fix disconnect detection being incorrect in some cases (issue 21 <https://bitbucket.org/ianb/webob/issues/21>_).
Fix exception when calling .accept.best_match(..) on a header containing
'*' (instead of '*/*').
Extract some of the Accept code into subclasses (AcceptCharset,
AcceptLanguage).
Improve language matching so that the app can now offer a generic
language code and it will match any of the accepted dialects
('en' in AcceptLanguage('en-gb')).
Normalize locale names when matching
('en_GB' in AcceptLanguage('en-gb')).
Deprecate etag.weak_match(..).
Deprecate Response.request and Response.environ attrs.
Remove deprecation warnings for unicode_body and ubody.
unicode_body and ubody.Deprecate Response.ubody / .unicode_body in favor of new .text attribute (the old names will be removed in 1.3 or even later).
Deprecate Response.ubody / .unicode_body in favor of new .text attribute
(the old names will be removed in 1.3 or even later).
Make Response.write much more efficient (issue 18 <https://bitbucket.org/ianb/webob/issues/18>_).
Make sure copying responses does not reset Content-Length or Content-MD5 of the original (and that of future copies).
Change del res.body semantics so that it doesn't make the response invalid,
but only removes the response body.
Remove Response._body so the _app_iter is the only representation.
Deprecate req.str_GET, str_POST, str_params and str_cookies (warning).
Add detection for browser / user-agent disconnects. If the client disconnected
before sending the entire request body (POST / PUT), req.POST, req.body
and other related properties and methods will raise an exception.
Previously this caused the application get a truncated request with no indication that it
is incomplete.
Make Response.body_file settable. This is now valid:
Response(body_file=open('foo.bin'), content_type=...)
Revert the restriction on req.body not being settable for GET and some
other requests. Such requests actually can have a body according to HTTP BIS
(see also commit message <https://bitbucket.org/ianb/webob/commits/b3ef34c57936>_)
Add support for file upload testing via Request.blank(POST=..). Patch contributed by
Tim Perevezentsev. See also:
ticket <https://bitbucket.org/ianb/webob/issues/15>,
changeset <https://bitbucket.org/ianb/webob/commits/4ba9ab0c3f99>.
Deprecate req.str_GET, str_POST, str_params and str_cookies (warning).
Deprecate req.decode_param_names (warning).
Change req.decode_param_names default to True. This means that .POST, .GET,
.params and .cookies keys are now unicode. This is necessary for WebOb to behave
as close as possible on Python 2 and Python 3.
Deprecate HTTPException.exception (warning on use).
We have acquired the webob.org domain, docs are now hosted at https://docs.pylonsproject.org/projects/webob/en/stable/ <https://docs.pylonsproject.org/projects/webob/en/stable/>_
Make accept.quality(..) return best match quality, not first match quality.
Fix Range.satisfiable(..) edge cases.
Make sure WSGIHTTPException instances return the same headers for HEAD
and GET requests.
Drop Python 2.4 support
Deprecate HTTPException.exception (warning on use).
Deprecate accept.first_match(..) (warning on use).
Use .best_match(..) instead.
Complete deprecation of req.[str_]{post|query}vars properties
(exception on use).
Remove FakeCGIBody.seek hack (no longer necessary).
Escape commas in cookie values (see also: stdlib Cookie bug _)
Escape commas in cookie values (see also:
stdlib Cookie bug <https://bugs.python.org/issue9824>_)
Change cookie serialization to more closely match how cookies usually are serialized (unquoted expires, semicolon separators even between morsels)
Fix some rare cases in cookie parsing
Enhance the req.is_body_readable to always guess GET, HEAD, DELETE and TRACE
as unreadable and PUT and POST as readable
(issue 12 <https://bitbucket.org/ianb/webob/issues/12>_)
Deny setting req.body or req.body_file to non-empty values for GET, HEAD and other bodiless requests
Fix running nosetests with arguments on UNIX systems
(issue 11 <https://bitbucket.org/ianb/webob/issues/11>_)
Fix Accept header matching for items with zero-quality (issue 10 _)
Fix Accept header matching for items with zero-quality
(issue 10 <https://bitbucket.org/ianb/webob/issues/10>_)
Hide password values in MultiDict.__repr__
Setting req.body_file to a string now produces a PendingDeprecationWarning. It will produce DeprecationWarning in 1.1 and raise an error in 1.2. Eithe…
Use environ['wsgi.input'].read() instead of .read(-1) because the former
is explicitly mentioned in PEP-3333 and CherryPy server does not support the latter.
Add new environ['webob.is_body_readable'] flag which specifies if the
input stream is readable even if the CONTENT_LENGTH is not set.
WebOb now only ever reads the input stream if the content-length is known
or this flag is set.
The two changes above fix a hangup with CherryPy and wsgiref servers
(issue 6 <https://bitbucket.org/ianb/webob/issues/6>_)
req.body_file is now safer to read directly. For GET and other similar requests
it returns an empty StringIO or BytesIO object even if the server passed in
something else.
Setting req.body_file to a string now produces a PendingDeprecationWarning.
It will produce DeprecationWarning in 1.1 and raise an error in 1.2. Either
set req.body_file to a file-like object or set req.body to a string value.
Fix .pop() and .setdefault(..) methods of req/resp.cache_control
Thanks to the participants of Pyramid sprint at the PyCon US 2011 <https://bitbucket.org/ianb/webob/commits/7b7dc3ec6159>_ WebOb now has
100% test coverage.
Restore Python 2.4 compatibility.
The field names escaping bug semi-fixed in 1.0.3 and originally blamed on cgi module was in fact a webob.request._encode_multipart bug (also in Google
The field names escaping bug semi-fixed in 1.0.3 and originally blamed on cgi module
was in fact a webob.request._encode_multipart bug (also in Google Chrome) and was
lurking in webob code for quite some time -- 1.0.2 just made it trigger more often.
Now it is fixed properly.
Make sure that req.url and related properties do not unnecessarily escape some chars
(:@&+$) in the URI path (issue 5 <https://bitbucket.org/ianb/webob/issues/5>_)
Revert some changes from 1.0.3 that have broken backwards compatibility for some apps.
Getting req.body_file does not make input stream seekable, but there's a new property
req.body_file_seekable that does.
Request.get_response and Request.call_application seek the input body to start
before calling the app (if possible).
Accessing req.body 'rewinds' the input stream back to pos 0 as well.
When accessing req.POST we now avoid making the body seekable as the input stream data
are preserved in FakeCGIBody anyway.
Add new method Request.from_string.
Make sure Request.as_string() uses CRLF to separate headers.
Improve parity between Request.as_string() and .from_file/.from_string
methods, so that the latter can parse output of the former and create a similar
request object which wasn't always the case previously.
Correct a caching issue introduced in WebOb 1.0.2 that was causing unnecessary reparsing of POST requests.
Correct a caching issue introduced in WebOb 1.0.2 that was causing unnecessary reparsing of POST requests.
Fix a bug regarding field names escaping for forms submitted as multipart/form-data.
For more infromation see the bug report and discussion <https://bitbucket.org/ianb/webob/issues/2>_ and 1.0.4 notes for further fix.
Add req.http_version attribute.
Primary maintainer is now Sergey Schetinin.
Primary maintainer is now Sergey Schetinin.
Issue tracker moved from Trac to bitbucket's issue tracker
WebOb 1.0.1 changed the behavior of MultiDict.update to be more in line with other dict-like objects. We now also issue a warning when we detect that the client code seems to expect the old, extending semantics.
Make Response.set_cookie(key, None) set the 'delete-cookie' (same as .delete_cookie(key))
Make req.upath_info and req.uscript_name settable
Add :meth:Request.as_string() method
Add a req.is_body_seekable property
Support for the deflate method with resp.decode_content()
To better conform to WSGI spec we no longer attempt to use seek on wsgi.input file instead we assume it is not seekable unless env['webob.is_body_seekable'] is set. When making the body seekable we set that flag.
A call to req.make_body_seekable() now guarantees that the body is seekable, is at 0 position and that a correct req.content_length is present.
req.body_file is always seekable. To access env['wsgi.input'] without any processing, use req.body_file_raw. (Partially reverted in 1.0.4)
Fix responses to HEAD requests with Range.
Fix del resp.content_type, del req.body, del req.cache_control
Fix resp.merge_cookies() when called with an argument that is not a Response instance.
Fix resp.content_body = None (was removing Cache-Control instead)
Fix req.body_file = f setting CONTENT_LENGTH to -1 (now removes from environ)
Fix: make sure req.copy() leaves the original with seekable body
Fix handling of WSGI environs with missing SCRIPT_NAME
A lot of tests were added by Mariano Mara and Danny Navarro.
As WebOb requires Python 2.4 or later, drop some compatibility modules and update the code to use the decorator syntax.
As WebOb requires Python 2.4 or later, drop some compatibility modules and update the code to use the decorator syntax.
Implement optional on-the-fly response compression (resp.encode_content(lazy=True))
Drop util.safezip module and make util a module instead of a subpackage.
Merge statusreasons into it.
Instead of using stdlib Cookie with monkeypatching, add a derived
but thoroughly rewritten, cleaner, safer and faster webob.cookies module.
Fix: Response.merge_cookies now copies the headers before modification instead of
doing it in-place.
Fix: setting request header attribute to None deletes that header.
(Bug only affected the 1.0 release).
Use io.BytesIO for the request body file on Python 2.7 and newer.
If a UnicodeMultiDict was used as the multi argument of another
UnicodeMultiDict, and a cgi.FieldStorage with a filename
with high-order characters was present in the underlying
UnicodeMultiDict, a UnicodeEncodeError would be raised when any
helper method caused the _decode_value method to be called,
because the method would try to decode an already decoded string.
Fix tests to pass under Python 2.4.
Add descriptive docstrings to each exception in webob.exc.
Change the behaviour of MultiDict.update to overwrite existing header
values instead of adding new headers. The extending semantics are now available
via the extend method.
Fix a bug in webob.exc.WSGIHTTPException.__init__. If a list of
headers was passed as a sequence which contained duplicate keys (for
example, multiple Set-Cookie headers), all but one of those headers
would be lost, because the list was effectively flattened into a dictionary
as the result of calling self.headers.update. Fixed via calling
self.headers.extend instead.
Pull in werkzeug Cookie fix for malformed cookie bug.
1.0, yay!
Pull in werkzeug Cookie fix for malformed cookie bug.
Implement Request.from_file and Response.from_file which are kind of the inversion of str(req) and str(resp)
Add optional pattern argument to Request.path_info_pop that requires the path_info segment to match the passed regexp to get popped and returned.
Rewrite most of descriptor implementations for speed.
Reorder descriptor declarations to group them by their semantics.
Move code around so that there are fewer compat modules.
Change :meth:HTTPError.__str__ to better conform to PEP 352.
Make Request.cache_control a view on the headers.
Correct Accept-Language and Accept-Charset matching to fully conform to the HTTP spec.
Expose parts of Request.blank as environ_from_url and environ_add_POST
Fix Authorization header parsing for some corner cases.
Fix an error generated if the user-agent sends a 'Content_Length' header (note the underscore).
Kill Request.default_charset. Request charset defaults to UTF-8. This ensures that all values in req.GET, req.POST and req.params are always unicode.
Fix the headerlist and content_type constructor arguments priorities for HTTPError and subclasses.
Add support for weak etags to conditional Response objects.
Fix locale-dependence for some cookie dates strings.
Improve overall test coverage.
Rename class webob.datastruct.EnvironHeaders to webob.headers.EnvironHeaders
Rename class webob.headerdict.HeaderDict to webob.headers.ResponseHeaders
Rename class webob.updatedict.UpdateDict to webob.cachecontrol.UpdateDict
Fix issue with WSGIHTTPException inadvertently generating unicode body and failing to encode it
Fix issue with WSGIHTTPException inadvertently generating unicode body and failing to encode it
WWW-Authenticate response header is accessible as response.www_authenticate
response.www_authenticate and request.authorization hold None or tuple (auth_method, params) where params is a dictionary (or a string when auth_method is not one of known auth schemes and for Authenticate: Basic ...)
Don't share response headers when getting a response like resp = req.get_response(some_app); this can avoid some funny errors with modifying headers and reusing Response objects.
Add overwrite argument to Response.set_cookie that make the new value overwrite the previously set. False by default.
Add strict argument to Response.unset_cookie that controls if an exception should be raised in case there are no cookies to unset. True by default.
Fix req.GET.copy()
Make sure that 304 Not Modified responses generated by Response.conditional_response_app exclude Content-{Length/Type} headers
Fix Response.copy() not being an independent copy
When the requested range is not satisfiable, return a 416 error (was returning entire body)
Truncate response for range requests that go beyond the end of body (was treating as invalid).
Fix an import problem with Pylons
Your coding agent can read these notes before it upgrades. Set up the MCP server →