Skip to content

Validate multipart part headers - #1142

Merged
Kludex merged 3 commits into
mainfrom
validate-multipart-part-headers
Aug 18, 2026
Merged

Kludex merged 3 commits into
mainfrom
validate-multipart-part-headers

Conversation

@Kludex

@Kludex Kludex commented Aug 18, 2026 •

Copy link
Copy Markdown
Member

Summary

  • validate multipart file header names and values before serialization
  • reject control characters disallowed in HTTP field lines
  • cover custom file content types and headers

Validation

  • uv run pytest tests/httpx2/test_multipart.py -q
  • uv run pytest tests/httpx2 -q
  • scripts/check

AI Disclaimer

This PR was developed with the assistance of either Claude or Codex. I've reviewed and verified the changes.

Review in cubic

@chatgpt-codex-connector

Copy link
Copy Markdown

You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard.
To continue using code reviews, add credits to your account and enable them for code reviews in your settings.

@github-actions

github-actions Bot commented Aug 18, 2026 •

Copy link
Copy Markdown

Comment thread src/httpx2/httpx2/_multipart.py Outdated
@codspeed

codspeed Bot commented Aug 18, 2026 •

Copy link
Copy Markdown

Merging this PR will not alter performance

✅ 17 untouched benchmarks
⏩ 7 skipped benchmarks1


Comparing validate-multipart-part-headers (e6fa6be) with main (51c3269)

Open in CodSpeed

Footnotes

  1. 7 benchmarks were skipped, so the baseline results were used instead. If they were deleted from the codebase, click here and archive them to remove them from the performance reports. ↩

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 2 files (changes from recent commits).

Reply with feedback, questions, or to request a fix.

Re-trigger cubic

Comment thread tests/httpx2/test_multipart.py
@Kludex
Kludex merged commit de96d81 into main Aug 18, 2026
19 checks passed
@Kludex
Kludex deleted the validate-multipart-part-headers branch August 18, 2026 07:25
netbsd-srcmastr pushed a commit to NetBSD/pkgsrc that referenced this pull request Aug 25, 2026
## 2.12.0 (August 18th, 2026)

### Changed

* Use `backports.zstd` for Zstandard decoding on Python 3.13 and earlier.
  ([#1146](pydantic/httpx2#1146))

### Fixed

* Bound peak memory while streaming compressed responses and close response streams when decoding fails.
  ([#1126](pydantic/httpx2#1126))

## 2.11.0 (August 18th, 2026)

### Added

* Add the public `Origin` value object and `URL.origin` property for normalized,
  hashable origin comparisons. ([#1134](pydantic/httpx2#1134))

### Changed

* Require Brotli 1.2.0 or later for the `brotli` extra. ([#1141](pydantic/httpx2#1141))

### Fixed

* Restore deprecated status code aliases. ([#1135](pydantic/httpx2#1135))
* Extract HTTP/2 release notes from changelog headings correctly. ([#1136](pydantic/httpx2#1136))
* Respect explicit `Transfer-Encoding` headers and expose buffered request body lengths to WSGI applications.
  ([#1137](pydantic/httpx2#1137))
* Validate multipart part header names and values before serialization.
  ([#1142](pydantic/httpx2#1142))

This branch was previously deployed

1 inactive deployment
cloudflare — e6fa6be1 Deployed Aug 18, 2026 by Kludex via Docs preview (Cloudflare) #719
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant