Skip to content

fix: prevent web-test errors and validate domain inputs - #50

Merged
pparage merged 1 commit into
mainfrom
fix/web-test-csp-cookie-errors
Sep 14, 2026
Merged

pparage merged 1 commit into
mainfrom
fix/web-test-csp-cookie-errors

Conversation

@pparage

@pparage pparage commented Sep 14, 2026 •

Copy link
Copy Markdown
Contributor

What does it do?

Web-test submissions could return HTTP 500 when the tested site supplied a valueless CSP directive, returned an HTTP/network error during cookie checks, or supplied malformed HSTS max-age data. These cases now produce assessment results. CSP parsing also preserves the first directive regardless of case and accepts flag directives and trailing semicolons.

The web-test form now accepts hyphenated domains, complete www hostnames, internationalized names, surrounding whitespace and HTTP(S) URLs. It normalizes these to the hostname whose homepage is assessed. Missing/incomplete names, malformed labels, unsupported schemes, credentials and ports return an escaped validation message with HTTP 400 before any network request or report write.

Validation: reproduced the failures before implementation; all 15 Django tests now pass, including full-view tests with isolated HTTP responses and a temporary test database. Added regressions for DNS errors, HTTP 403, malformed CSP/HSTS, normalized report names and invalid-input handling. Updated the Django CI matrix to Python 3.12/3.13, matching the existing Django 6 dependency requirements.

Django CI passes on Python 3.12 and 3.13. The separate Python application lint job still reports 14 pre-existing undefined-name findings in untouched IoT, cipher and IPv6 modules; the changed runtime files introduce no new core lint errors.

Release Type

  • Major
  • Minor
  • Patch

@chatgpt-codex-connector

chatgpt-codex-connector Bot commented Sep 14, 2026 •

Copy link
Copy Markdown

Codex Review Summary

This comment shows the latest Codex review activity on this pull request.

Review Status Commit Review trigger
📝 Code Review ✅ Completed 2026-09-14T11:16:39.934067Z 996e377 PR opened
ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review" or "@codex security review".

Codex reacts with 👀 while any review is running, comments if it has suggestions, and reacts with 👍 once all reviews finish with no findings.

@pparage
pparage merged commit 933bcc2 into main Sep 14, 2026
2 of 4 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant