[3.10] gh-135661: Fix parsing attributes with whitespaces around the "=" separator in HTMLParser (GH-136908) (GH-136921)
This fixes a regression introduced in GH-135930.
(cherry picked from commit dee650189497735edbc08a54edabb5b06ef1bd09)
Co-authored-by: Serhiy Storchaka <storchaka@gmail.com>
diff --git a/Lib/html/parser.py b/Lib/html/parser.py
index 9a1b430..c7dde2e 100644
--- a/Lib/html/parser.py
+++ b/Lib/html/parser.py
@@ -43,7 +43,7 @@
(
(?<=['"\t\n\r\f /])[^\t\n\r\f />][^\t\n\r\f /=>]* # attribute name
)
- (= # value indicator
+ ([\t\n\r\f ]*=[\t\n\r\f ]* # value indicator
('[^']*' # LITA-enclosed value
|"[^"]*" # LIT-enclosed value
|(?!['"])[^>\t\n\r\f ]* # bare value
@@ -55,7 +55,7 @@
[a-zA-Z][^\t\n\r\f />]* # tag name
[\t\n\r\f /]* # optional whitespace before attribute name
(?:(?<=['"\t\n\r\f /])[^\t\n\r\f />][^\t\n\r\f /=>]* # attribute name
- (?:= # value indicator
+ (?:[\t\n\r\f ]*=[\t\n\r\f ]* # value indicator
(?:'[^']*' # LITA-enclosed value
|"[^"]*" # LIT-enclosed value
|(?!['"])[^>\t\n\r\f ]* # bare value
diff --git a/Lib/test/test_htmlparser.py b/Lib/test/test_htmlparser.py
index 708b351..e78e806 100644
--- a/Lib/test/test_htmlparser.py
+++ b/Lib/test/test_htmlparser.py
@@ -595,7 +595,7 @@ def test_correct_detection_of_start_tags(self):
html = '<div style="", foo = "bar" ><b>The <a href="some_url">rain</a>'
expected = [
- ('starttag', 'div', [('style', ''), (',', None), ('foo', None), ('=', None), ('"bar"', None)]),
+ ('starttag', 'div', [('style', ''), (',', None), ('foo', 'bar')]),
('starttag', 'b', []),
('data', 'The '),
('starttag', 'a', [('href', 'some_url')]),
@@ -751,12 +751,12 @@ def test_attr_syntax(self):
]
self._run_check("""<a b='v' c="v" d=v e>""", output)
self._run_check("<a foo==bar>", [('starttag', 'a', [('foo', '=bar')])])
- self._run_check("<a foo =bar>", [('starttag', 'a', [('foo', None), ('=bar', None)])])
- self._run_check("<a foo\t=bar>", [('starttag', 'a', [('foo', None), ('=bar', None)])])
+ self._run_check("<a foo =bar>", [('starttag', 'a', [('foo', 'bar')])])
+ self._run_check("<a foo\t=bar>", [('starttag', 'a', [('foo', 'bar')])])
self._run_check("<a foo\v=bar>", [('starttag', 'a', [('foo\v', 'bar')])])
self._run_check("<a foo\xa0=bar>", [('starttag', 'a', [('foo\xa0', 'bar')])])
- self._run_check("<a foo= bar>", [('starttag', 'a', [('foo', ''), ('bar', None)])])
- self._run_check("<a foo=\tbar>", [('starttag', 'a', [('foo', ''), ('bar', None)])])
+ self._run_check("<a foo= bar>", [('starttag', 'a', [('foo', 'bar')])])
+ self._run_check("<a foo=\tbar>", [('starttag', 'a', [('foo', 'bar')])])
self._run_check("<a foo=\vbar>", [('starttag', 'a', [('foo', '\vbar')])])
self._run_check("<a foo=\xa0bar>", [('starttag', 'a', [('foo', '\xa0bar')])])
@@ -767,8 +767,8 @@ def test_attr_values(self):
("d", "\txyz\n")])])
self._run_check("""<a b='' c="">""",
[("starttag", "a", [("b", ""), ("c", "")])])
- self._run_check("<a b=\t c=\n>",
- [("starttag", "a", [("b", ""), ("c", "")])])
+ self._run_check("<a b=\tx c=\ny>",
+ [('starttag', 'a', [('b', 'x'), ('c', 'y')])])
self._run_check("<a b=\v c=\xa0>",
[("starttag", "a", [("b", "\v"), ("c", "\xa0")])])
# Regression test for SF patch #669683.
@@ -837,13 +837,17 @@ def test_malformed_attributes(self):
)
expected = [
('starttag', 'a', [('href', "test'style='color:red;bad1'")]),
- ('data', 'test - bad1'), ('endtag', 'a'),
+ ('data', 'test - bad1'),
+ ('endtag', 'a'),
('starttag', 'a', [('href', "test'+style='color:red;ba2'")]),
- ('data', 'test - bad2'), ('endtag', 'a'),
+ ('data', 'test - bad2'),
+ ('endtag', 'a'),
('starttag', 'a', [('href', "test'\xa0style='color:red;bad3'")]),
- ('data', 'test - bad3'), ('endtag', 'a'),
- ('starttag', 'a', [('href', None), ('=', None), ("test' style", 'color:red;bad4')]),
- ('data', 'test - bad4'), ('endtag', 'a')
+ ('data', 'test - bad3'),
+ ('endtag', 'a'),
+ ('starttag', 'a', [('href', "test'\xa0style='color:red;bad4'")]),
+ ('data', 'test - bad4'),
+ ('endtag', 'a'),
]
self._run_check(html, expected)
diff --git a/Misc/NEWS.d/next/Security/2025-06-25-14-13-39.gh-issue-135661.idjQ0B.rst b/Misc/NEWS.d/next/Security/2025-06-25-14-13-39.gh-issue-135661.idjQ0B.rst
index b6f9e10..27e886a 100644
--- a/Misc/NEWS.d/next/Security/2025-06-25-14-13-39.gh-issue-135661.idjQ0B.rst
+++ b/Misc/NEWS.d/next/Security/2025-06-25-14-13-39.gh-issue-135661.idjQ0B.rst
@@ -18,8 +18,3 @@
* Multiple ``=`` between attribute name and value are no longer collapsed.
E.g. ``<a foo==bar>`` produces attribute "foo" with value "=bar".
-
-* Whitespaces between the ``=`` separator and attribute name or value are no
- longer ignored. E.g. ``<a foo =bar>`` produces two attributes "foo" and
- "=bar", both with value None; ``<a foo= bar>`` produces two attributes:
- "foo" with value "" and "bar" with value None.