4 ms·
Based on their description of the bug, it sounded like the code was modular, but they called the function twice: once when the password reset request was genera
by dan_manges 13y ago
Based on their description of the bug, it sounded like the code was modular, but they called the function twice: once when the password reset request was generated, and again when the link in the email was clicked.
However, when the link was used, canonical_username was once again applied
So after they sent the password reset link, they called "fetchUserIdByName" again, but they passed in a username that had already been canonicalized once. Because of this bug, I wonder if password resets worked at all for users with unicode characters in their names.
- mmahemoff 13y agoIf you're saying canonicalise(canonicalise(name)) is not the same as canonicalise(name), that's going to be seriously bug-prone. Idempotence ftw.
- deleted 13y ago[deleted]
- spicyj 13y agoThat's exactly what they describe as the cause of the bug. They intended for the function to be idempotent but it wasn't because of a misunderstanding with the Python library spec.
- Xorlev 13y agoWorse, it /did/ work that way in Python 2.4 but Python 2.5 stopped throwing an exception for invalid codepoints which broke the Twisted library which broke their canonicalization function.
- sanderjd 13y agoYou should read the article. It prominently features a very interesting description of precisely why their `canonicalise` function turned out to not be idempotent, even though it was meant to be.
- frogpelt 13y agoI see you came here for the comments. You should check out the post. It seems relevant.