/
usr
/
share
/
doc
/
python2-docs
/
html
/
library
/
/usr/share/doc/python2-docs/html/library
mkdir
upload
Name
Size
Mode
Actions
2to3.html
59507
0644
edit
dl
rm
abc.html
25826
0644
edit
dl
rm
aepack.html
14164
0644
edit
dl
rm
aetools.html
16389
0644
edit
dl
rm
aetypes.html
21021
0644
edit
dl
rm
aifc.html
25064
0644
edit
dl
rm
al.html
18672
0644
edit
dl
rm
allos.html
35297
0644
edit
dl
rm
anydbm.html
18124
0644
edit
dl
rm
archiving.html
10078
0644
edit
dl
rm
argparse.html
263616
0644
edit
dl
rm
array.html
31855
0644
edit
dl
rm
ast.html
38167
0644
edit
dl
rm
asynchat.html
33930
0644
edit
dl
rm
asyncore.html
40631
0644
edit
dl
rm
atexit.html
18455
0644
edit
dl
rm
audioop.html
34252
0644
edit
dl
rm
autogil.html
8733
0644
edit
dl
rm
base64.html
21862
0644
edit
dl
rm
basehttpserver.html
37441
0644
edit
dl
rm
bastion.html
11798
0644
edit
dl
rm
bdb.html
41395
0644
edit
dl
rm
binascii.html
22997
0644
edit
dl
rm
binhex.html
11309
0644
edit
dl
rm
bisect.html
24666
0644
edit
dl
rm
bsddb.html
28589
0644
edit
dl
rm
bz2.html
29048
0644
edit
dl
rm
calendar.html
41762
0644
edit
dl
rm
carbon.html
51998
0644
edit
dl
rm
cd.html
30033
0644
edit
dl
rm
cgi.html
55922
0644
edit
dl
rm
cgihttpserver.html
14026
0644
edit
dl
rm
cgitb.html
12263
0644
edit
dl
rm
chunk.html
15899
0644
edit
dl
rm
cmath.html
28365
0644
edit
dl
rm
cmd.html
29042
0644
edit
dl
rm
code.html
26959
0644
edit
dl
rm
codecs.html
118258
0644
edit
dl
rm
codeop.html
15898
0644
edit
dl
rm
collections.html
147647
0644
edit
dl
rm
colorpicker.html
8035
0644
edit
dl
rm
colorsys.html
11919
0644
edit
dl
rm
commands.html
15516
0644
edit
dl
rm
compileall.html
18621
0644
edit
dl
rm
compiler.html
75897
0644
edit
dl
rm
configparser.html
67751
0644
edit
dl
rm
constants.html
13979
0644
edit
dl
rm
contextlib.html
22777
0644
edit
dl
rm
cookie.html
41854
0644
edit
dl
rm
cookielib.html
91032
0644
edit
dl
rm
copy.html
13004
0644
edit
dl
rm
copy_reg.html
14691
0644
edit
dl
rm
crypt.html
10647
0644
edit
dl
rm
crypto.html
7761
0644
edit
dl
rm
csv.html
76456
0644
edit
dl
rm
ctypes.html
264575
0644
edit
dl
rm
curses.ascii.html
24873
0644
edit
dl
rm
curses.html
167501
0644
edit
dl
rm
curses.panel.html
15824
0644
edit
dl
rm
custominterp.html
8026
0644
edit
dl
rm
datatypes.html
18015
0644
edit
dl
rm
datetime.html
253438
0644
edit
dl
rm
dbhash.html
16825
0644
edit
dl
rm
dbm.html
13507
0644
edit
dl
rm
debug.html
10703
0644
edit
dl
rm
decimal.html
222315
0644
edit
dl
rm
development.html
14828
0644
edit
dl
rm
difflib.html
91975
0644
edit
dl
rm
dircache.html
12299
0644
edit
dl
rm
dis.html
84156
0644
edit
dl
rm
distribution.html
7679
0644
edit
dl
rm
distutils.html
10152
0644
edit
dl
rm
dl.html
17668
0644
edit
dl
rm
doctest.html
185883
0644
edit
dl
rm
docxmlrpcserver.html
17573
0644
edit
dl
rm
dumbdbm.html
15549
0644
edit
dl
rm
dummy_thread.html
10065
0644
edit
dl
rm
dummy_threading.html
8934
0644
edit
dl
rm
easydialogs.html
33124
0644
edit
dl
rm
email-examples.html
47424
0644
edit
dl
rm
email.charset.html
29424
0644
edit
dl
rm
email.encoders.html
12847
0644
edit
dl
rm
email.errors.html
17952
0644
edit
dl
rm
email.generator.html
23141
0644
edit
dl
rm
email.header.html
29108
0644
edit
dl
rm
email.html
55722
0644
edit
dl
rm
email.iterators.html
12623
0644
edit
dl
rm
email.message.html
70189
0644
edit
dl
rm
email.mime.html
31655
0644
edit
dl
rm
email.parser.html
35142
0644
edit
dl
rm
email.utils.html
27076
0644
edit
dl
rm
ensurepip.html
18327
0644
edit
dl
rm
errno.html
40246
0644
edit
dl
rm
exceptions.html
63693
0644
edit
dl
rm
fcntl.html
26245
0644
edit
dl
rm
filecmp.html
23997
0644
edit
dl
rm
fileformats.html
9653
0644
edit
dl
rm
fileinput.html
27071
0644
edit
dl
rm
filesys.html
10866
0644
edit
dl
rm
fl.html
56525
0644
edit
dl
rm
fm.html
13009
0644
edit
dl
rm
fnmatch.html
16258
0644
edit
dl
rm
formatter.html
37371
0644
edit
dl
rm
fpectl.html
16879
0644
edit
dl
rm
fpformat.html
11455
0644
edit
dl
rm
fractions.html
24888
0644
edit
dl
rm
framework.html
36934
0644
edit
dl
rm
frameworks.html
7551
0644
edit
dl
rm
ftplib.html
49577
0644
edit
dl
rm
functions.html
205640
0644
edit
dl
rm
functools.html
29645
0644
edit
dl
rm
future_builtins.html
14477
0644
edit
dl
rm
gc.html
28423
0644
edit
dl
rm
gdbm.html
17805
0644
edit
dl
rm
gensuitemodule.html
12574
0644
edit
dl
rm
getopt.html
25280
0644
edit
dl
rm
getpass.html
11426
0644
edit
dl
rm
gettext.html
84971
0644
edit
dl
rm
gl.html
24342
0644
edit
dl
rm
glob.html
14430
0644
edit
dl
rm
grp.html
11316
0644
edit
dl
rm
gzip.html
20576
0644
edit
dl
rm
hashlib.html
25467
0644
edit
dl
rm
heapq.html
34890
0644
edit
dl
rm
hmac.html
14374
0644
edit
dl
rm
hotshot.html
20147
0644
edit
dl
rm
htmllib.html
27682
0644
edit
dl
rm
htmlparser.html
42433
0644
edit
dl
rm
httplib.html
70932
0644
edit
dl
rm
i18n.html
10047
0644
edit
dl
rm
ic.html
18654
0644
edit
dl
rm
idle.html
42148
0644
edit
dl
rm
imageop.html
16099
0644
edit
dl
rm
imaplib.html
58515
0644
edit
dl
rm
imgfile.html
12732
0644
edit
dl
rm
imghdr.html
12238
0644
edit
dl
rm
imp.html
37603
0644
edit
dl
rm
importlib.html
8926
0644
edit
dl
rm
imputil.html
33563
0644
edit
dl
rm
index.html
79088
0644
edit
dl
rm
inspect.html
56823
0644
edit
dl
rm
internet.html
26138
0644
edit
dl
rm
intro.html
9353
0644
edit
dl
rm
io.html
113701
0644
edit
dl
rm
ipc.html
16598
0644
edit
dl
rm
itertools.html
125397
0644
edit
dl
rm
jpeg.html
13757
0644
edit
dl
rm
json.html
73678
0644
edit
dl
rm
keyword.html
8210
0644
edit
dl
rm
language.html
11687
0644
edit
dl
rm
linecache.html
11416
0644
edit
dl
rm
locale.html
61576
0644
edit
dl
rm
logging.config.html
80045
0644
edit
dl
rm
logging.handlers.html
80194
0644
edit
dl
rm
logging.html
110254
0644
edit
dl
rm
mac.html
23376
0644
edit
dl
rm
macos.html
16129
0644
edit
dl
rm
macosa.html
14080
0644
edit
dl
rm
macostools.html
16898
0644
edit
dl
rm
macpath.html
8386
0644
edit
dl
rm
mailbox.html
171121
0644
edit
dl
rm
mailcap.html
14132
0644
edit
dl
rm
markup.html
19862
0644
edit
dl
rm
marshal.html
19456
0644
edit
dl
rm
math.html
44015
0644
edit
dl
rm
md5.html
15123
0644
edit
dl
rm
mhlib.html
24123
0644
edit
dl
rm
mimetools.html
21206
0644
edit
dl
rm
mimetypes.html
30634
0644
edit
dl
rm
mimewriter.html
16078
0644
edit
dl
rm
mimify.html
15279
0644
edit
dl
rm
miniaeframe.html
13109
0644
edit
dl
rm
misc.html
7236
0644
edit
dl
rm
mm.html
9570
0644
edit
dl
rm
mmap.html
30832
0644
edit
dl
rm
modulefinder.html
18096
0644
edit
dl
rm
modules.html
9017
0644
edit
dl
rm
msilib.html
57853
0644
edit
dl
rm
msvcrt.html
21232
0644
edit
dl
rm
multifile.html
26256
0644
edit
dl
rm
multiprocessing.html
414535
0644
edit
dl
rm
mutex.html
12147
0644
edit
dl
rm
netdata.html
18379
0644
edit
dl
rm
netrc.html
14021
0644
edit
dl
rm
new.html
13177
0644
edit
dl
rm
nis.html
11502
0644
edit
dl
rm
nntplib.html
45689
0644
edit
dl
rm
numbers.html
40636
0644
edit
dl
rm
numeric.html
14292
0644
edit
dl
rm
operator.html
93622
0644
edit
dl
rm
optparse.html
250109
0644
edit
dl
rm
os.html
240195
0644
edit
dl
rm
os.path.html
43402
0644
edit
dl
rm
ossaudiodev.html
45594
0644
edit
dl
rm
othergui.html
9403
0644
edit
dl
rm
parser.html
42558
0644
edit
dl
rm
pdb.html
38603
0644
edit
dl
rm
persistence.html
15676
0644
edit
dl
rm
pickle.html
109684
0644
edit
dl
rm
pickletools.html
11475
0644
edit
dl
rm
pipes.html
19685
0644
edit
dl
rm
pkgutil.html
27367
0644
edit
dl
rm
platform.html
31599
0644
edit
dl
rm
plistlib.html
18344
0644
edit
dl
rm
popen2.html
27601
0644
edit
dl
rm
poplib.html
24320
0644
edit
dl
rm
posix.html
16626
0644
edit
dl
rm
posixfile.html
21387
0644
edit
dl
rm
pprint.html
32207
0644
edit
dl
rm
profile.html
72788
0644
edit
dl
rm
pty.html
10195
0644
edit
dl
rm
pwd.html
12388
0644
edit
dl
rm
pyclbr.html
15812
0644
edit
dl
rm
pydoc.html
13650
0644
edit
dl
rm
pyexpat.html
80886
0644
edit
dl
rm
python.html
12854
0644
edit
dl
rm
py_compile.html
11932
0644
edit
dl
rm
queue.html
26856
0644
edit
dl
rm
quopri.html
12739
0644
edit
dl
rm
random.html
42722
0644
edit
dl
rm
re.html
155985
0644
edit
dl
rm
readline.html
37383
0644
edit
dl
rm
repr.html
21778
0644
edit
dl
rm
resource.html
28286
0644
edit
dl
rm
restricted.html
12366
0644
edit
dl
rm
rexec.html
40566
0644
edit
dl
rm
rfc822.html
46408
0644
edit
dl
rm
rlcompleter.html
14460
0644
edit
dl
rm
robotparser.html
13403
0644
edit
dl
rm
runpy.html
21925
0644
edit
dl
rm
sched.html
19878
0644
edit
dl
rm
scrolledtext.html
9728
0644
edit
dl
rm
select.html
44090
0644
edit
dl
rm
sets.html
40151
0644
edit
dl
rm
sgi.html
10371
0644
edit
dl
rm
sgmllib.html
34464
0644
edit
dl
rm
sha.html
13062
0644
edit
dl
rm
shelve.html
29955
0644
edit
dl
rm
shlex.html
35033
0644
edit
dl
rm
shutil.html
45454
0644
edit
dl
rm
signal.html
34023
0644
edit
dl
rm
simplehttpserver.html
20351
0644
edit
dl
rm
simplexmlrpcserver.html
37794
0644
edit
dl
rm
site.html
26887
0644
edit
dl
rm
smtpd.html
13587
0644
edit
dl
rm
smtplib.html
47054
0644
edit
dl
rm
sndhdr.html
10993
0644
edit
dl
rm
socket.html
116414
0644
edit
dl
rm
socketserver.html
76430
0644
edit
dl
rm
someos.html
16472
0644
edit
dl
rm
spwd.html
11163
0644
edit
dl
rm
sqlite3.html
150014
0644
edit
dl
rm
ssl.html
202453
0644
edit
dl
rm
stat.html
34597
0644
edit
dl
rm
statvfs.html
11326
0644
edit
dl
rm
stdtypes.html
298144
0644
edit
dl
rm
string.html
120219
0644
edit
dl
rm
stringio.html
20061
0644
edit
dl
rm
stringprep.html
17729
0644
edit
dl
rm
strings.html
15905
0644
edit
dl
rm
struct.html
44896
0644
edit
dl
rm
subprocess.html
110447
0644
edit
dl
rm
sun.html
7253
0644
edit
dl
rm
sunau.html
30011
0644
edit
dl
rm
sunaudio.html
19236
0644
edit
dl
rm
symbol.html
8140
0644
edit
dl
rm
symtable.html
25871
0644
edit
dl
rm
sys.html
110996
0644
edit
dl
rm
sysconfig.html
26299
0644
edit
dl
rm
syslog.html
19737
0644
edit
dl
rm
tabnanny.html
11393
0644
edit
dl
rm
tarfile.html
88728
0644
edit
dl
rm
telnetlib.html
27782
0644
edit
dl
rm
tempfile.html
31903
0644
edit
dl
rm
termios.html
17309
0644
edit
dl
rm
test.html
57030
0644
edit
dl
rm
textwrap.html
30135
0644
edit
dl
rm
thread.html
21486
0644
edit
dl
rm
threading.html
86655
0644
edit
dl
rm
time.html
63798
0644
edit
dl
rm
timeit.html
40529
0644
edit
dl
rm
tix.html
50582
0644
edit
dl
rm
tk.html
26568
0644
edit
dl
rm
tkinter.html
84316
0644
edit
dl
rm
token.html
20999
0644
edit
dl
rm
tokenize.html
20607
0644
edit
dl
rm
trace.html
28668
0644
edit
dl
rm
traceback.html
40900
0644
edit
dl
rm
ttk.html
108515
0644
edit
dl
rm
tty.html
9753
0644
edit
dl
rm
turtle.html
230483
0644
edit
dl
rm
types.html
29833
0644
edit
dl
rm
undoc.html
24680
0644
edit
dl
rm
unicodedata.html
20186
0644
edit
dl
rm
unittest.html
225021
0644
edit
dl
rm
unix.html
11223
0644
edit
dl
rm
urllib.html
68266
0644
edit
dl
rm
urllib2.html
113380
0644
edit
dl
rm
urlparse.html
43474
0644
edit
dl
rm
user.html
12707
0644
edit
dl
rm
userdict.html
32069
0644
edit
dl
rm
uu.html
11810
0644
edit
dl
rm
uuid.html
30137
0644
edit
dl
rm
warnings.html
50950
0644
edit
dl
rm
wave.html
24894
0644
edit
dl
rm
weakref.html
38808
0644
edit
dl
rm
webbrowser.html
26565
0644
edit
dl
rm
whichdb.html
9499
0644
edit
dl
rm
windows.html
9817
0644
edit
dl
rm
winsound.html
20466
0644
edit
dl
rm
wsgiref.html
88384
0644
edit
dl
rm
xdrlib.html
33018
0644
edit
dl
rm
xml.dom.html
97877
0644
edit
dl
rm
xml.dom.minidom.html
43230
0644
edit
dl
rm
xml.dom.pulldom.html
13835
0644
edit
dl
rm
xml.etree.elementtree.html
111804
0644
edit
dl
rm
xml.html
18007
0644
edit
dl
rm
xml.sax.handler.html
41877
0644
edit
dl
rm
xml.sax.html
23458
0644
edit
dl
rm
xml.sax.reader.html
44802
0644
edit
dl
rm
xml.sax.utils.html
16087
0644
edit
dl
rm
xmlrpclib.html
69191
0644
edit
dl
rm
zipfile.html
62227
0644
edit
dl
rm
zipimport.html
22769
0644
edit
dl
rm
zlib.html
31230
0644
edit
dl
rm
_winreg.html
64631
0644
edit
dl
rm
__builtin__.html
11069
0644
edit
dl
rm
__future__.html
14688
0644
edit
dl
rm
__main__.html
7512
0644
edit
dl
rm
Edit:
/usr/share/doc/python2-docs/html/library/cgi.html
(55922B)
<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd"> <html xmlns="http://www.w3.org/1999/xhtml"> <head> <meta http-equiv="X-UA-Compatible" content="IE=Edge" /> <meta http-equiv="Content-Type" content="text/html; charset=utf-8" /> <title>20.2. cgi — Common Gateway Interface support — Python 2.7.16 documentation</title> <link rel="stylesheet" href="../_static/classic.css" type="text/css" /> <link rel="stylesheet" href="../_static/pygments.css" type="text/css" /> <script type="text/javascript" id="documentation_options" data-url_root="../" src="../_static/documentation_options.js"></script> <script type="text/javascript" src="../_static/jquery.js"></script> <script type="text/javascript" src="../_static/underscore.js"></script> <script type="text/javascript" src="../_static/doctools.js"></script> <script type="text/javascript" src="../_static/sidebar.js"></script> <link rel="search" type="application/opensearchdescription+xml" title="Search within Python 2.7.16 documentation" href="../_static/opensearch.xml"/> <link rel="author" title="About these documents" href="../about.html" /> <link rel="index" title="Index" href="../genindex.html" /> <link rel="search" title="Search" href="../search.html" /> <link rel="copyright" title="Copyright" href="../copyright.html" /> <link rel="next" title="20.3. cgitb — Traceback manager for CGI scripts" href="cgitb.html" /> <link rel="prev" title="20.1. webbrowser — Convenient Web-browser controller" href="webbrowser.html" /> <link rel="shortcut icon" type="image/png" href="../_static/py.png" /> <link rel="canonical" href="https://docs.python.org/2/library/cgi.html" /> <script type="text/javascript" src="../_static/copybutton.js"></script> </head><body> <div class="related" role="navigation" aria-label="related navigation"> <h3>Navigation</h3> <ul> <li class="right" style="margin-right: 10px"> <a href="../genindex.html" title="General Index" accesskey="I">index</a></li> <li class="right" > <a href="../py-modindex.html" title="Python Module Index" >modules</a> |</li> <li class="right" > <a href="cgitb.html" title="20.3. cgitb — Traceback manager for CGI scripts" accesskey="N">next</a> |</li> <li class="right" > <a href="webbrowser.html" title="20.1. webbrowser — Convenient Web-browser controller" accesskey="P">previous</a> |</li> <li><img src="../_static/py.png" alt="" style="vertical-align: middle; margin-top: -1px"/></li> <li><a href="https://www.python.org/">Python</a> »</li> <li> <a href="../index.html">Python 2.7.16 documentation</a> » </li> <li class="nav-item nav-item-1"><a href="index.html" >The Python Standard Library</a> »</li> <li class="nav-item nav-item-2"><a href="internet.html" accesskey="U">20. Internet Protocols and Support</a> »</li> </ul> </div> <div class="document"> <div class="documentwrapper"> <div class="bodywrapper"> <div class="body" role="main"> <div class="section" id="module-cgi"> <span id="cgi-common-gateway-interface-support"></span><h1>20.2. <a class="reference internal" href="#module-cgi" title="cgi: Helpers for running Python scripts via the Common Gateway Interface."><code class="xref py py-mod docutils literal notranslate"><span class="pre">cgi</span></code></a> — Common Gateway Interface support<a class="headerlink" href="#module-cgi" title="Permalink to this headline">¶</a></h1> <p id="index-0"><strong>Source code:</strong> <a class="reference external" href="https://github.com/python/cpython/tree/2.7/Lib/cgi.py">Lib/cgi.py</a></p> <hr class="docutils" /> <p>Support module for Common Gateway Interface (CGI) scripts.</p> <p>This module defines a number of utilities for use by CGI scripts written in Python.</p> <div class="section" id="introduction"> <h2>20.2.1. Introduction<a class="headerlink" href="#introduction" title="Permalink to this headline">¶</a></h2> <p id="cgi-intro">A CGI script is invoked by an HTTP server, usually to process user input submitted through an HTML <code class="docutils literal notranslate"><span class="pre"><FORM></span></code> or <code class="docutils literal notranslate"><span class="pre"><ISINDEX></span></code> element.</p> <p>Most often, CGI scripts live in the server’s special <code class="file docutils literal notranslate"><span class="pre">cgi-bin</span></code> directory. The HTTP server places all sorts of information about the request (such as the client’s hostname, the requested URL, the query string, and lots of other goodies) in the script’s shell environment, executes the script, and sends the script’s output back to the client.</p> <p>The script’s input is connected to the client too, and sometimes the form data is read this way; at other times the form data is passed via the “query string” part of the URL. This module is intended to take care of the different cases and provide a simpler interface to the Python script. It also provides a number of utilities that help in debugging scripts, and the latest addition is support for file uploads from a form (if your browser supports it).</p> <p>The output of a CGI script should consist of two sections, separated by a blank line. The first section contains a number of headers, telling the client what kind of data is following. Python code to generate a minimal header section looks like this:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="nb">print</span> <span class="s2">"Content-Type: text/html"</span> <span class="c1"># HTML is following</span> <span class="nb">print</span> <span class="c1"># blank line, end of headers</span> </pre></div> </div> <p>The second section is usually HTML, which allows the client software to display nicely formatted text with header, in-line images, etc. Here’s Python code that prints a simple piece of HTML:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="nb">print</span> <span class="s2">"<TITLE>CGI script output</TITLE>"</span> <span class="nb">print</span> <span class="s2">"<H1>This is my first CGI script</H1>"</span> <span class="nb">print</span> <span class="s2">"Hello, world!"</span> </pre></div> </div> </div> <div class="section" id="using-the-cgi-module"> <span id="id1"></span><h2>20.2.2. Using the cgi module<a class="headerlink" href="#using-the-cgi-module" title="Permalink to this headline">¶</a></h2> <p>Begin by writing <code class="docutils literal notranslate"><span class="pre">import</span> <span class="pre">cgi</span></code>. Do not use <code class="docutils literal notranslate"><span class="pre">from</span> <span class="pre">cgi</span> <span class="pre">import</span> <span class="pre">*</span></code> — the module defines all sorts of names for its own use or for backward compatibility that you don’t want in your namespace.</p> <p>When you write a new script, consider adding these lines:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="kn">import</span> <span class="nn">cgitb</span> <span class="n">cgitb</span><span class="o">.</span><span class="n">enable</span><span class="p">()</span> </pre></div> </div> <p>This activates a special exception handler that will display detailed reports in the Web browser if any errors occur. If you’d rather not show the guts of your program to users of your script, you can have the reports saved to files instead, with code like this:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="kn">import</span> <span class="nn">cgitb</span> <span class="n">cgitb</span><span class="o">.</span><span class="n">enable</span><span class="p">(</span><span class="n">display</span><span class="o">=</span><span class="mi">0</span><span class="p">,</span> <span class="n">logdir</span><span class="o">=</span><span class="s2">"/path/to/logdir"</span><span class="p">)</span> </pre></div> </div> <p>It’s very helpful to use this feature during script development. The reports produced by <a class="reference internal" href="cgitb.html#module-cgitb" title="cgitb: Configurable traceback handler for CGI scripts."><code class="xref py py-mod docutils literal notranslate"><span class="pre">cgitb</span></code></a> provide information that can save you a lot of time in tracking down bugs. You can always remove the <code class="docutils literal notranslate"><span class="pre">cgitb</span></code> line later when you have tested your script and are confident that it works correctly.</p> <p>To get at submitted form data, it’s best to use the <code class="xref py py-class docutils literal notranslate"><span class="pre">FieldStorage</span></code> class. The other classes defined in this module are provided mostly for backward compatibility. Instantiate it exactly once, without arguments. This reads the form contents from standard input or the environment (depending on the value of various environment variables set according to the CGI standard). Since it may consume standard input, it should be instantiated only once.</p> <p>The <code class="xref py py-class docutils literal notranslate"><span class="pre">FieldStorage</span></code> instance can be indexed like a Python dictionary. It allows membership testing with the <a class="reference internal" href="../reference/expressions.html#in"><code class="xref std std-keyword docutils literal notranslate"><span class="pre">in</span></code></a> operator, and also supports the standard dictionary method <a class="reference internal" href="stdtypes.html#dict.keys" title="dict.keys"><code class="xref py py-meth docutils literal notranslate"><span class="pre">keys()</span></code></a> and the built-in function <a class="reference internal" href="functions.html#len" title="len"><code class="xref py py-func docutils literal notranslate"><span class="pre">len()</span></code></a>. Form fields containing empty strings are ignored and do not appear in the dictionary; to keep such values, provide a true value for the optional <em>keep_blank_values</em> keyword parameter when creating the <code class="xref py py-class docutils literal notranslate"><span class="pre">FieldStorage</span></code> instance.</p> <p>For instance, the following code (which assumes that the <em class="mailheader">Content-Type</em> header and blank line have already been printed) checks that the fields <code class="docutils literal notranslate"><span class="pre">name</span></code> and <code class="docutils literal notranslate"><span class="pre">addr</span></code> are both set to a non-empty string:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">form</span> <span class="o">=</span> <span class="n">cgi</span><span class="o">.</span><span class="n">FieldStorage</span><span class="p">()</span> <span class="k">if</span> <span class="s2">"name"</span> <span class="ow">not</span> <span class="ow">in</span> <span class="n">form</span> <span class="ow">or</span> <span class="s2">"addr"</span> <span class="ow">not</span> <span class="ow">in</span> <span class="n">form</span><span class="p">:</span> <span class="nb">print</span> <span class="s2">"<H1>Error</H1>"</span> <span class="nb">print</span> <span class="s2">"Please fill in the name and addr fields."</span> <span class="k">return</span> <span class="nb">print</span> <span class="s2">"<p>name:"</span><span class="p">,</span> <span class="n">form</span><span class="p">[</span><span class="s2">"name"</span><span class="p">]</span><span class="o">.</span><span class="n">value</span> <span class="nb">print</span> <span class="s2">"<p>addr:"</span><span class="p">,</span> <span class="n">form</span><span class="p">[</span><span class="s2">"addr"</span><span class="p">]</span><span class="o">.</span><span class="n">value</span> <span class="o">...</span><span class="n">further</span> <span class="n">form</span> <span class="n">processing</span> <span class="n">here</span><span class="o">...</span> </pre></div> </div> <p>Here the fields, accessed through <code class="docutils literal notranslate"><span class="pre">form[key]</span></code>, are themselves instances of <code class="xref py py-class docutils literal notranslate"><span class="pre">FieldStorage</span></code> (or <code class="xref py py-class docutils literal notranslate"><span class="pre">MiniFieldStorage</span></code>, depending on the form encoding). The <code class="xref py py-attr docutils literal notranslate"><span class="pre">value</span></code> attribute of the instance yields the string value of the field. The <code class="xref py py-meth docutils literal notranslate"><span class="pre">getvalue()</span></code> method returns this string value directly; it also accepts an optional second argument as a default to return if the requested key is not present.</p> <p>If the submitted form data contains more than one field with the same name, the object retrieved by <code class="docutils literal notranslate"><span class="pre">form[key]</span></code> is not a <code class="xref py py-class docutils literal notranslate"><span class="pre">FieldStorage</span></code> or <code class="xref py py-class docutils literal notranslate"><span class="pre">MiniFieldStorage</span></code> instance but a list of such instances. Similarly, in this situation, <code class="docutils literal notranslate"><span class="pre">form.getvalue(key)</span></code> would return a list of strings. If you expect this possibility (when your HTML form contains multiple fields with the same name), use the <a class="reference internal" href="#cgi.FieldStorage.getlist" title="cgi.FieldStorage.getlist"><code class="xref py py-meth docutils literal notranslate"><span class="pre">getlist()</span></code></a> method, which always returns a list of values (so that you do not need to special-case the single item case). For example, this code concatenates any number of username fields, separated by commas:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">value</span> <span class="o">=</span> <span class="n">form</span><span class="o">.</span><span class="n">getlist</span><span class="p">(</span><span class="s2">"username"</span><span class="p">)</span> <span class="n">usernames</span> <span class="o">=</span> <span class="s2">","</span><span class="o">.</span><span class="n">join</span><span class="p">(</span><span class="n">value</span><span class="p">)</span> </pre></div> </div> <p>If a field represents an uploaded file, accessing the value via the <code class="xref py py-attr docutils literal notranslate"><span class="pre">value</span></code> attribute or the <code class="xref py py-func docutils literal notranslate"><span class="pre">getvalue()</span></code> method reads the entire file in memory as a string. This may not be what you want. You can test for an uploaded file by testing either the <code class="xref py py-attr docutils literal notranslate"><span class="pre">filename</span></code> attribute or the <code class="xref py py-attr docutils literal notranslate"><span class="pre">file</span></code> attribute. You can then read the data at leisure from the <code class="xref py py-attr docutils literal notranslate"><span class="pre">file</span></code> attribute:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">fileitem</span> <span class="o">=</span> <span class="n">form</span><span class="p">[</span><span class="s2">"userfile"</span><span class="p">]</span> <span class="k">if</span> <span class="n">fileitem</span><span class="o">.</span><span class="n">file</span><span class="p">:</span> <span class="c1"># It's an uploaded file; count lines</span> <span class="n">linecount</span> <span class="o">=</span> <span class="mi">0</span> <span class="k">while</span> <span class="mi">1</span><span class="p">:</span> <span class="n">line</span> <span class="o">=</span> <span class="n">fileitem</span><span class="o">.</span><span class="n">file</span><span class="o">.</span><span class="n">readline</span><span class="p">()</span> <span class="k">if</span> <span class="ow">not</span> <span class="n">line</span><span class="p">:</span> <span class="k">break</span> <span class="n">linecount</span> <span class="o">=</span> <span class="n">linecount</span> <span class="o">+</span> <span class="mi">1</span> </pre></div> </div> <p>If an error is encountered when obtaining the contents of an uploaded file (for example, when the user interrupts the form submission by clicking on a Back or Cancel button) the <code class="xref py py-attr docutils literal notranslate"><span class="pre">done</span></code> attribute of the object for the field will be set to the value -1.</p> <p>The file upload draft standard entertains the possibility of uploading multiple files from one field (using a recursive <em class="mimetype">multipart/*</em> encoding). When this occurs, the item will be a dictionary-like <code class="xref py py-class docutils literal notranslate"><span class="pre">FieldStorage</span></code> item. This can be determined by testing its <code class="xref py py-attr docutils literal notranslate"><span class="pre">type</span></code> attribute, which should be <em class="mimetype">multipart/form-data</em> (or perhaps another MIME type matching <em class="mimetype">multipart/*</em>). In this case, it can be iterated over recursively just like the top-level form object.</p> <p>When a form is submitted in the “old” format (as the query string or as a single data part of type <em class="mimetype">application/x-www-form-urlencoded</em>), the items will actually be instances of the class <code class="xref py py-class docutils literal notranslate"><span class="pre">MiniFieldStorage</span></code>. In this case, the <code class="xref py py-attr docutils literal notranslate"><span class="pre">list</span></code>, <code class="xref py py-attr docutils literal notranslate"><span class="pre">file</span></code>, and <code class="xref py py-attr docutils literal notranslate"><span class="pre">filename</span></code> attributes are always <code class="docutils literal notranslate"><span class="pre">None</span></code>.</p> <p>A form submitted via POST that also has a query string will contain both <code class="xref py py-class docutils literal notranslate"><span class="pre">FieldStorage</span></code> and <code class="xref py py-class docutils literal notranslate"><span class="pre">MiniFieldStorage</span></code> items.</p> </div> <div class="section" id="higher-level-interface"> <h2>20.2.3. Higher Level Interface<a class="headerlink" href="#higher-level-interface" title="Permalink to this headline">¶</a></h2> <div class="versionadded"> <p><span class="versionmodified">New in version 2.2.</span></p> </div> <p>The previous section explains how to read CGI form data using the <code class="xref py py-class docutils literal notranslate"><span class="pre">FieldStorage</span></code> class. This section describes a higher level interface which was added to this class to allow one to do it in a more readable and intuitive way. The interface doesn’t make the techniques described in previous sections obsolete — they are still useful to process file uploads efficiently, for example.</p> <p>The interface consists of two simple methods. Using the methods you can process form data in a generic way, without the need to worry whether only one or more values were posted under one name.</p> <p>In the previous section, you learned to write following code anytime you expected a user to post more than one value under one name:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">item</span> <span class="o">=</span> <span class="n">form</span><span class="o">.</span><span class="n">getvalue</span><span class="p">(</span><span class="s2">"item"</span><span class="p">)</span> <span class="k">if</span> <span class="nb">isinstance</span><span class="p">(</span><span class="n">item</span><span class="p">,</span> <span class="nb">list</span><span class="p">):</span> <span class="c1"># The user is requesting more than one item.</span> <span class="k">else</span><span class="p">:</span> <span class="c1"># The user is requesting only one item.</span> </pre></div> </div> <p>This situation is common for example when a form contains a group of multiple checkboxes with the same name:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="o"><</span><span class="nb">input</span> <span class="nb">type</span><span class="o">=</span><span class="s2">"checkbox"</span> <span class="n">name</span><span class="o">=</span><span class="s2">"item"</span> <span class="n">value</span><span class="o">=</span><span class="s2">"1"</span> <span class="o">/></span> <span class="o"><</span><span class="nb">input</span> <span class="nb">type</span><span class="o">=</span><span class="s2">"checkbox"</span> <span class="n">name</span><span class="o">=</span><span class="s2">"item"</span> <span class="n">value</span><span class="o">=</span><span class="s2">"2"</span> <span class="o">/></span> </pre></div> </div> <p>In most situations, however, there’s only one form control with a particular name in a form and then you expect and need only one value associated with this name. So you write a script containing for example this code:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">user</span> <span class="o">=</span> <span class="n">form</span><span class="o">.</span><span class="n">getvalue</span><span class="p">(</span><span class="s2">"user"</span><span class="p">)</span><span class="o">.</span><span class="n">upper</span><span class="p">()</span> </pre></div> </div> <p>The problem with the code is that you should never expect that a client will provide valid input to your scripts. For example, if a curious user appends another <code class="docutils literal notranslate"><span class="pre">user=foo</span></code> pair to the query string, then the script would crash, because in this situation the <code class="docutils literal notranslate"><span class="pre">getvalue("user")</span></code> method call returns a list instead of a string. Calling the <a class="reference internal" href="stdtypes.html#str.upper" title="str.upper"><code class="xref py py-meth docutils literal notranslate"><span class="pre">upper()</span></code></a> method on a list is not valid (since lists do not have a method of this name) and results in an <a class="reference internal" href="exceptions.html#exceptions.AttributeError" title="exceptions.AttributeError"><code class="xref py py-exc docutils literal notranslate"><span class="pre">AttributeError</span></code></a> exception.</p> <p>Therefore, the appropriate way to read form data values was to always use the code which checks whether the obtained value is a single value or a list of values. That’s annoying and leads to less readable scripts.</p> <p>A more convenient approach is to use the methods <a class="reference internal" href="#cgi.FieldStorage.getfirst" title="cgi.FieldStorage.getfirst"><code class="xref py py-meth docutils literal notranslate"><span class="pre">getfirst()</span></code></a> and <a class="reference internal" href="#cgi.FieldStorage.getlist" title="cgi.FieldStorage.getlist"><code class="xref py py-meth docutils literal notranslate"><span class="pre">getlist()</span></code></a> provided by this higher level interface.</p> <dl class="method"> <dt id="cgi.FieldStorage.getfirst"> <code class="descclassname">FieldStorage.</code><code class="descname">getfirst</code><span class="sig-paren">(</span><em>name</em><span class="optional">[</span>, <em>default</em><span class="optional">]</span><span class="sig-paren">)</span><a class="headerlink" href="#cgi.FieldStorage.getfirst" title="Permalink to this definition">¶</a></dt> <dd><p>This method always returns only one value associated with form field <em>name</em>. The method returns only the first value in case that more values were posted under such name. Please note that the order in which the values are received may vary from browser to browser and should not be counted on. <a class="footnote-reference" href="#id3" id="id2">[1]</a> If no such form field or value exists then the method returns the value specified by the optional parameter <em>default</em>. This parameter defaults to <code class="docutils literal notranslate"><span class="pre">None</span></code> if not specified.</p> </dd></dl> <dl class="method"> <dt id="cgi.FieldStorage.getlist"> <code class="descclassname">FieldStorage.</code><code class="descname">getlist</code><span class="sig-paren">(</span><em>name</em><span class="sig-paren">)</span><a class="headerlink" href="#cgi.FieldStorage.getlist" title="Permalink to this definition">¶</a></dt> <dd><p>This method always returns a list of values associated with form field <em>name</em>. The method returns an empty list if no such form field or value exists for <em>name</em>. It returns a list consisting of one item if only one such value exists.</p> </dd></dl> <p>Using these methods you can write nice compact code:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="kn">import</span> <span class="nn">cgi</span> <span class="n">form</span> <span class="o">=</span> <span class="n">cgi</span><span class="o">.</span><span class="n">FieldStorage</span><span class="p">()</span> <span class="n">user</span> <span class="o">=</span> <span class="n">form</span><span class="o">.</span><span class="n">getfirst</span><span class="p">(</span><span class="s2">"user"</span><span class="p">,</span> <span class="s2">""</span><span class="p">)</span><span class="o">.</span><span class="n">upper</span><span class="p">()</span> <span class="c1"># This way it's safe.</span> <span class="k">for</span> <span class="n">item</span> <span class="ow">in</span> <span class="n">form</span><span class="o">.</span><span class="n">getlist</span><span class="p">(</span><span class="s2">"item"</span><span class="p">):</span> <span class="n">do_something</span><span class="p">(</span><span class="n">item</span><span class="p">)</span> </pre></div> </div> </div> <div class="section" id="old-classes"> <h2>20.2.4. Old classes<a class="headerlink" href="#old-classes" title="Permalink to this headline">¶</a></h2> <div class="deprecated"> <p><span class="versionmodified">Deprecated since version 2.6: </span>These classes, present in earlier versions of the <a class="reference internal" href="#module-cgi" title="cgi: Helpers for running Python scripts via the Common Gateway Interface."><code class="xref py py-mod docutils literal notranslate"><span class="pre">cgi</span></code></a> module, are still supported for backward compatibility. New applications should use the <code class="xref py py-class docutils literal notranslate"><span class="pre">FieldStorage</span></code> class.</p> </div> <p><code class="xref py py-class docutils literal notranslate"><span class="pre">SvFormContentDict</span></code> stores single value form content as dictionary; it assumes each field name occurs in the form only once.</p> <p><code class="xref py py-class docutils literal notranslate"><span class="pre">FormContentDict</span></code> stores multiple value form content as a dictionary (the form items are lists of values). Useful if your form contains multiple fields with the same name.</p> <p>Other classes (<code class="xref py py-class docutils literal notranslate"><span class="pre">FormContent</span></code>, <code class="xref py py-class docutils literal notranslate"><span class="pre">InterpFormContentDict</span></code>) are present for backwards compatibility with really old applications only.</p> </div> <div class="section" id="functions"> <span id="functions-in-cgi-module"></span><h2>20.2.5. Functions<a class="headerlink" href="#functions" title="Permalink to this headline">¶</a></h2> <p>These are useful if you want more control, or if you want to employ some of the algorithms implemented in this module in other circumstances.</p> <dl class="function"> <dt id="cgi.parse"> <code class="descclassname">cgi.</code><code class="descname">parse</code><span class="sig-paren">(</span><em>fp</em><span class="optional">[</span>, <em>environ</em><span class="optional">[</span>, <em>keep_blank_values</em><span class="optional">[</span>, <em>strict_parsing</em><span class="optional">]</span><span class="optional">]</span><span class="optional">]</span><span class="sig-paren">)</span><a class="headerlink" href="#cgi.parse" title="Permalink to this definition">¶</a></dt> <dd><p>Parse a query in the environment or from a file (the file defaults to <code class="docutils literal notranslate"><span class="pre">sys.stdin</span></code> and environment defaults to <code class="docutils literal notranslate"><span class="pre">os.environ</span></code>). The <em>keep_blank_values</em> and <em>strict_parsing</em> parameters are passed to <a class="reference internal" href="urlparse.html#urlparse.parse_qs" title="urlparse.parse_qs"><code class="xref py py-func docutils literal notranslate"><span class="pre">urlparse.parse_qs()</span></code></a> unchanged.</p> </dd></dl> <dl class="function"> <dt id="cgi.parse_qs"> <code class="descclassname">cgi.</code><code class="descname">parse_qs</code><span class="sig-paren">(</span><em>qs</em><span class="optional">[</span>, <em>keep_blank_values</em><span class="optional">[</span>, <em>strict_parsing</em><span class="optional">[</span>, <em>max_num_fields</em><span class="optional">]</span><span class="optional">]</span><span class="optional">]</span><span class="sig-paren">)</span><a class="headerlink" href="#cgi.parse_qs" title="Permalink to this definition">¶</a></dt> <dd><p>This function is deprecated in this module. Use <a class="reference internal" href="urlparse.html#urlparse.parse_qs" title="urlparse.parse_qs"><code class="xref py py-func docutils literal notranslate"><span class="pre">urlparse.parse_qs()</span></code></a> instead. It is maintained here only for backward compatibility.</p> </dd></dl> <dl class="function"> <dt id="cgi.parse_qsl"> <code class="descclassname">cgi.</code><code class="descname">parse_qsl</code><span class="sig-paren">(</span><em>qs</em><span class="optional">[</span>, <em>keep_blank_values</em><span class="optional">[</span>, <em>strict_parsing</em><span class="optional">[</span>, <em>max_num_fields</em><span class="optional">]</span><span class="optional">]</span><span class="optional">]</span><span class="sig-paren">)</span><a class="headerlink" href="#cgi.parse_qsl" title="Permalink to this definition">¶</a></dt> <dd><p>This function is deprecated in this module. Use <a class="reference internal" href="urlparse.html#urlparse.parse_qsl" title="urlparse.parse_qsl"><code class="xref py py-func docutils literal notranslate"><span class="pre">urlparse.parse_qsl()</span></code></a> instead. It is maintained here only for backward compatibility.</p> </dd></dl> <dl class="function"> <dt id="cgi.parse_multipart"> <code class="descclassname">cgi.</code><code class="descname">parse_multipart</code><span class="sig-paren">(</span><em>fp</em>, <em>pdict</em><span class="sig-paren">)</span><a class="headerlink" href="#cgi.parse_multipart" title="Permalink to this definition">¶</a></dt> <dd><p>Parse input of type <em class="mimetype">multipart/form-data</em> (for file uploads). Arguments are <em>fp</em> for the input file and <em>pdict</em> for a dictionary containing other parameters in the <em class="mailheader">Content-Type</em> header.</p> <p>Returns a dictionary just like <a class="reference internal" href="urlparse.html#urlparse.parse_qs" title="urlparse.parse_qs"><code class="xref py py-func docutils literal notranslate"><span class="pre">urlparse.parse_qs()</span></code></a> keys are the field names, each value is a list of values for that field. This is easy to use but not much good if you are expecting megabytes to be uploaded — in that case, use the <code class="xref py py-class docutils literal notranslate"><span class="pre">FieldStorage</span></code> class instead which is much more flexible.</p> <p>Note that this does not parse nested multipart parts — use <code class="xref py py-class docutils literal notranslate"><span class="pre">FieldStorage</span></code> for that.</p> </dd></dl> <dl class="function"> <dt id="cgi.parse_header"> <code class="descclassname">cgi.</code><code class="descname">parse_header</code><span class="sig-paren">(</span><em>string</em><span class="sig-paren">)</span><a class="headerlink" href="#cgi.parse_header" title="Permalink to this definition">¶</a></dt> <dd><p>Parse a MIME header (such as <em class="mailheader">Content-Type</em>) into a main value and a dictionary of parameters.</p> </dd></dl> <dl class="function"> <dt id="cgi.test"> <code class="descclassname">cgi.</code><code class="descname">test</code><span class="sig-paren">(</span><span class="sig-paren">)</span><a class="headerlink" href="#cgi.test" title="Permalink to this definition">¶</a></dt> <dd><p>Robust test CGI script, usable as main program. Writes minimal HTTP headers and formats all information provided to the script in HTML form.</p> </dd></dl> <dl class="function"> <dt id="cgi.print_environ"> <code class="descclassname">cgi.</code><code class="descname">print_environ</code><span class="sig-paren">(</span><span class="sig-paren">)</span><a class="headerlink" href="#cgi.print_environ" title="Permalink to this definition">¶</a></dt> <dd><p>Format the shell environment in HTML.</p> </dd></dl> <dl class="function"> <dt id="cgi.print_form"> <code class="descclassname">cgi.</code><code class="descname">print_form</code><span class="sig-paren">(</span><em>form</em><span class="sig-paren">)</span><a class="headerlink" href="#cgi.print_form" title="Permalink to this definition">¶</a></dt> <dd><p>Format a form in HTML.</p> </dd></dl> <dl class="function"> <dt id="cgi.print_directory"> <code class="descclassname">cgi.</code><code class="descname">print_directory</code><span class="sig-paren">(</span><span class="sig-paren">)</span><a class="headerlink" href="#cgi.print_directory" title="Permalink to this definition">¶</a></dt> <dd><p>Format the current directory in HTML.</p> </dd></dl> <dl class="function"> <dt id="cgi.print_environ_usage"> <code class="descclassname">cgi.</code><code class="descname">print_environ_usage</code><span class="sig-paren">(</span><span class="sig-paren">)</span><a class="headerlink" href="#cgi.print_environ_usage" title="Permalink to this definition">¶</a></dt> <dd><p>Print a list of useful (used by CGI) environment variables in HTML.</p> </dd></dl> <dl class="function"> <dt id="cgi.escape"> <code class="descclassname">cgi.</code><code class="descname">escape</code><span class="sig-paren">(</span><em>s</em><span class="optional">[</span>, <em>quote</em><span class="optional">]</span><span class="sig-paren">)</span><a class="headerlink" href="#cgi.escape" title="Permalink to this definition">¶</a></dt> <dd><p>Convert the characters <code class="docutils literal notranslate"><span class="pre">'&'</span></code>, <code class="docutils literal notranslate"><span class="pre">'<'</span></code> and <code class="docutils literal notranslate"><span class="pre">'>'</span></code> in string <em>s</em> to HTML-safe sequences. Use this if you need to display text that might contain such characters in HTML. If the optional flag <em>quote</em> is true, the quotation mark character (<code class="docutils literal notranslate"><span class="pre">"</span></code>) is also translated; this helps for inclusion in an HTML attribute value delimited by double quotes, as in <code class="docutils literal notranslate"><span class="pre"><a</span> <span class="pre">href="..."></span></code>. Note that single quotes are never translated.</p> <p>If the value to be quoted might include single- or double-quote characters, or both, consider using the <a class="reference internal" href="xml.sax.utils.html#xml.sax.saxutils.quoteattr" title="xml.sax.saxutils.quoteattr"><code class="xref py py-func docutils literal notranslate"><span class="pre">quoteattr()</span></code></a> function in the <a class="reference internal" href="xml.sax.utils.html#module-xml.sax.saxutils" title="xml.sax.saxutils: Convenience functions and classes for use with SAX."><code class="xref py py-mod docutils literal notranslate"><span class="pre">xml.sax.saxutils</span></code></a> module instead.</p> </dd></dl> </div> <div class="section" id="caring-about-security"> <span id="cgi-security"></span><h2>20.2.6. Caring about security<a class="headerlink" href="#caring-about-security" title="Permalink to this headline">¶</a></h2> <p id="index-1">There’s one important rule: if you invoke an external program (via the <a class="reference internal" href="os.html#os.system" title="os.system"><code class="xref py py-func docutils literal notranslate"><span class="pre">os.system()</span></code></a> or <a class="reference internal" href="os.html#os.popen" title="os.popen"><code class="xref py py-func docutils literal notranslate"><span class="pre">os.popen()</span></code></a> functions. or others with similar functionality), make very sure you don’t pass arbitrary strings received from the client to the shell. This is a well-known security hole whereby clever hackers anywhere on the Web can exploit a gullible CGI script to invoke arbitrary shell commands. Even parts of the URL or field names cannot be trusted, since the request doesn’t have to come from your form!</p> <p>To be on the safe side, if you must pass a string gotten from a form to a shell command, you should make sure the string contains only alphanumeric characters, dashes, underscores, and periods.</p> </div> <div class="section" id="installing-your-cgi-script-on-a-unix-system"> <h2>20.2.7. Installing your CGI script on a Unix system<a class="headerlink" href="#installing-your-cgi-script-on-a-unix-system" title="Permalink to this headline">¶</a></h2> <p>Read the documentation for your HTTP server and check with your local system administrator to find the directory where CGI scripts should be installed; usually this is in a directory <code class="file docutils literal notranslate"><span class="pre">cgi-bin</span></code> in the server tree.</p> <p>Make sure that your script is readable and executable by “others”; the Unix file mode should be <code class="docutils literal notranslate"><span class="pre">0755</span></code> octal (use <code class="docutils literal notranslate"><span class="pre">chmod</span> <span class="pre">0755</span> <span class="pre">filename</span></code>). Make sure that the first line of the script contains <code class="docutils literal notranslate"><span class="pre">#!</span></code> starting in column 1 followed by the pathname of the Python interpreter, for instance:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="ch">#!/usr/local/bin/python</span> </pre></div> </div> <p>Make sure the Python interpreter exists and is executable by “others”.</p> <p>Make sure that any files your script needs to read or write are readable or writable, respectively, by “others” — their mode should be <code class="docutils literal notranslate"><span class="pre">0644</span></code> for readable and <code class="docutils literal notranslate"><span class="pre">0666</span></code> for writable. This is because, for security reasons, the HTTP server executes your script as user “nobody”, without any special privileges. It can only read (write, execute) files that everybody can read (write, execute). The current directory at execution time is also different (it is usually the server’s cgi-bin directory) and the set of environment variables is also different from what you get when you log in. In particular, don’t count on the shell’s search path for executables (<span class="target" id="index-2"></span><code class="xref std std-envvar docutils literal notranslate"><span class="pre">PATH</span></code>) or the Python module search path (<span class="target" id="index-3"></span><a class="reference internal" href="../using/cmdline.html#envvar-PYTHONPATH"><code class="xref std std-envvar docutils literal notranslate"><span class="pre">PYTHONPATH</span></code></a>) to be set to anything interesting.</p> <p>If you need to load modules from a directory which is not on Python’s default module search path, you can change the path in your script, before importing other modules. For example:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="kn">import</span> <span class="nn">sys</span> <span class="n">sys</span><span class="o">.</span><span class="n">path</span><span class="o">.</span><span class="n">insert</span><span class="p">(</span><span class="mi">0</span><span class="p">,</span> <span class="s2">"/usr/home/joe/lib/python"</span><span class="p">)</span> <span class="n">sys</span><span class="o">.</span><span class="n">path</span><span class="o">.</span><span class="n">insert</span><span class="p">(</span><span class="mi">0</span><span class="p">,</span> <span class="s2">"/usr/local/lib/python"</span><span class="p">)</span> </pre></div> </div> <p>(This way, the directory inserted last will be searched first!)</p> <p>Instructions for non-Unix systems will vary; check your HTTP server’s documentation (it will usually have a section on CGI scripts).</p> </div> <div class="section" id="testing-your-cgi-script"> <h2>20.2.8. Testing your CGI script<a class="headerlink" href="#testing-your-cgi-script" title="Permalink to this headline">¶</a></h2> <p>Unfortunately, a CGI script will generally not run when you try it from the command line, and a script that works perfectly from the command line may fail mysteriously when run from the server. There’s one reason why you should still test your script from the command line: if it contains a syntax error, the Python interpreter won’t execute it at all, and the HTTP server will most likely send a cryptic error to the client.</p> <p>Assuming your script has no syntax errors, yet it does not work, you have no choice but to read the next section.</p> </div> <div class="section" id="debugging-cgi-scripts"> <h2>20.2.9. Debugging CGI scripts<a class="headerlink" href="#debugging-cgi-scripts" title="Permalink to this headline">¶</a></h2> <p id="index-4">First of all, check for trivial installation errors — reading the section above on installing your CGI script carefully can save you a lot of time. If you wonder whether you have understood the installation procedure correctly, try installing a copy of this module file (<code class="file docutils literal notranslate"><span class="pre">cgi.py</span></code>) as a CGI script. When invoked as a script, the file will dump its environment and the contents of the form in HTML form. Give it the right mode etc, and send it a request. If it’s installed in the standard <code class="file docutils literal notranslate"><span class="pre">cgi-bin</span></code> directory, it should be possible to send it a request by entering a URL into your browser of the form:</p> <div class="highlight-none notranslate"><div class="highlight"><pre><span></span>http://yourhostname/cgi-bin/cgi.py?name=Joe+Blow&addr=At+Home </pre></div> </div> <p>If this gives an error of type 404, the server cannot find the script – perhaps you need to install it in a different directory. If it gives another error, there’s an installation problem that you should fix before trying to go any further. If you get a nicely formatted listing of the environment and form content (in this example, the fields should be listed as “addr” with value “At Home” and “name” with value “Joe Blow”), the <code class="file docutils literal notranslate"><span class="pre">cgi.py</span></code> script has been installed correctly. If you follow the same procedure for your own script, you should now be able to debug it.</p> <p>The next step could be to call the <a class="reference internal" href="#module-cgi" title="cgi: Helpers for running Python scripts via the Common Gateway Interface."><code class="xref py py-mod docutils literal notranslate"><span class="pre">cgi</span></code></a> module’s <a class="reference internal" href="test.html#module-test" title="test: Regression tests package containing the testing suite for Python."><code class="xref py py-func docutils literal notranslate"><span class="pre">test()</span></code></a> function from your script: replace its main code with the single statement</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="n">cgi</span><span class="o">.</span><span class="n">test</span><span class="p">()</span> </pre></div> </div> <p>This should produce the same results as those gotten from installing the <code class="file docutils literal notranslate"><span class="pre">cgi.py</span></code> file itself.</p> <p>When an ordinary Python script raises an unhandled exception (for whatever reason: of a typo in a module name, a file that can’t be opened, etc.), the Python interpreter prints a nice traceback and exits. While the Python interpreter will still do this when your CGI script raises an exception, most likely the traceback will end up in one of the HTTP server’s log files, or be discarded altogether.</p> <p>Fortunately, once you have managed to get your script to execute <em>some</em> code, you can easily send tracebacks to the Web browser using the <a class="reference internal" href="cgitb.html#module-cgitb" title="cgitb: Configurable traceback handler for CGI scripts."><code class="xref py py-mod docutils literal notranslate"><span class="pre">cgitb</span></code></a> module. If you haven’t done so already, just add the lines:</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="kn">import</span> <span class="nn">cgitb</span> <span class="n">cgitb</span><span class="o">.</span><span class="n">enable</span><span class="p">()</span> </pre></div> </div> <p>to the top of your script. Then try running it again; when a problem occurs, you should see a detailed report that will likely make apparent the cause of the crash.</p> <p>If you suspect that there may be a problem in importing the <a class="reference internal" href="cgitb.html#module-cgitb" title="cgitb: Configurable traceback handler for CGI scripts."><code class="xref py py-mod docutils literal notranslate"><span class="pre">cgitb</span></code></a> module, you can use an even more robust approach (which only uses built-in modules):</p> <div class="highlight-default notranslate"><div class="highlight"><pre><span></span><span class="kn">import</span> <span class="nn">sys</span> <span class="n">sys</span><span class="o">.</span><span class="n">stderr</span> <span class="o">=</span> <span class="n">sys</span><span class="o">.</span><span class="n">stdout</span> <span class="nb">print</span> <span class="s2">"Content-Type: text/plain"</span> <span class="nb">print</span> <span class="o">...</span><span class="n">your</span> <span class="n">code</span> <span class="n">here</span><span class="o">...</span> </pre></div> </div> <p>This relies on the Python interpreter to print the traceback. The content type of the output is set to plain text, which disables all HTML processing. If your script works, the raw HTML will be displayed by your client. If it raises an exception, most likely after the first two lines have been printed, a traceback will be displayed. Because no HTML interpretation is going on, the traceback will be readable.</p> </div> <div class="section" id="common-problems-and-solutions"> <h2>20.2.10. Common problems and solutions<a class="headerlink" href="#common-problems-and-solutions" title="Permalink to this headline">¶</a></h2> <ul class="simple"> <li>Most HTTP servers buffer the output from CGI scripts until the script is completed. This means that it is not possible to display a progress report on the client’s display while the script is running.</li> <li>Check the installation instructions above.</li> <li>Check the HTTP server’s log files. (<code class="docutils literal notranslate"><span class="pre">tail</span> <span class="pre">-f</span> <span class="pre">logfile</span></code> in a separate window may be useful!)</li> <li>Always check a script for syntax errors first, by doing something like <code class="docutils literal notranslate"><span class="pre">python</span> <span class="pre">script.py</span></code>.</li> <li>If your script does not have any syntax errors, try adding <code class="docutils literal notranslate"><span class="pre">import</span> <span class="pre">cgitb;</span> <span class="pre">cgitb.enable()</span></code> to the top of the script.</li> <li>When invoking external programs, make sure they can be found. Usually, this means using absolute path names — <span class="target" id="index-5"></span><code class="xref std std-envvar docutils literal notranslate"><span class="pre">PATH</span></code> is usually not set to a very useful value in a CGI script.</li> <li>When reading or writing external files, make sure they can be read or written by the userid under which your CGI script will be running: this is typically the userid under which the web server is running, or some explicitly specified userid for a web server’s <code class="docutils literal notranslate"><span class="pre">suexec</span></code> feature.</li> <li>Don’t try to give a CGI script a set-uid mode. This doesn’t work on most systems, and is a security liability as well.</li> </ul> <p class="rubric">Footnotes</p> <table class="docutils footnote" frame="void" id="id3" rules="none"> <colgroup><col class="label" /><col /></colgroup> <tbody valign="top"> <tr><td class="label"><a class="fn-backref" href="#id2">[1]</a></td><td>Note that some recent versions of the HTML specification do state what order the field values should be supplied in, but knowing whether a request was received from a conforming browser, or even from a browser at all, is tedious and error-prone.</td></tr> </tbody> </table> </div> </div> </div> </div> </div> <div class="sphinxsidebar" role="navigation" aria-label="main navigation"> <div class="sphinxsidebarwrapper"> <h3><a href="../contents.html">Table Of Contents</a></h3> <ul> <li><a class="reference internal" href="#">20.2. <code class="docutils literal notranslate"><span class="pre">cgi</span></code> — Common Gateway Interface support</a><ul> <li><a class="reference internal" href="#introduction">20.2.1. Introduction</a></li> <li><a class="reference internal" href="#using-the-cgi-module">20.2.2. Using the cgi module</a></li> <li><a class="reference internal" href="#higher-level-interface">20.2.3. Higher Level Interface</a></li> <li><a class="reference internal" href="#old-classes">20.2.4. Old classes</a></li> <li><a class="reference internal" href="#functions">20.2.5. Functions</a></li> <li><a class="reference internal" href="#caring-about-security">20.2.6. Caring about security</a></li> <li><a class="reference internal" href="#installing-your-cgi-script-on-a-unix-system">20.2.7. Installing your CGI script on a Unix system</a></li> <li><a class="reference internal" href="#testing-your-cgi-script">20.2.8. Testing your CGI script</a></li> <li><a class="reference internal" href="#debugging-cgi-scripts">20.2.9. Debugging CGI scripts</a></li> <li><a class="reference internal" href="#common-problems-and-solutions">20.2.10. Common problems and solutions</a></li> </ul> </li> </ul> <h4>Previous topic</h4> <p class="topless"><a href="webbrowser.html" title="previous chapter">20.1. <code class="docutils literal notranslate"><span class="pre">webbrowser</span></code> — Convenient Web-browser controller</a></p> <h4>Next topic</h4> <p class="topless"><a href="cgitb.html" title="next chapter">20.3. <code class="docutils literal notranslate"><span class="pre">cgitb</span></code> — Traceback manager for CGI scripts</a></p> <div role="note" aria-label="source link"> <h3>This Page</h3> <ul class="this-page-menu"> <li><a href="../_sources/library/cgi.rst.txt" rel="nofollow">Show Source</a></li> </ul> </div> <div id="searchbox" style="display: none" role="search"> <h3>Quick search</h3> <div class="searchformwrapper"> <form class="search" action="../search.html" method="get"> <input type="text" name="q" /> <input type="submit" value="Go" /> <input type="hidden" name="check_keywords" value="yes" /> <input type="hidden" name="area" value="default" /> </form> </div> </div> <script type="text/javascript">$('#searchbox').show(0);</script> </div> </div> <div class="clearer"></div> </div> <div class="related" role="navigation" aria-label="related navigation"> <h3>Navigation</h3> <ul> <li class="right" style="margin-right: 10px"> <a href="../genindex.html" title="General Index" >index</a></li> <li class="right" > <a href="../py-modindex.html" title="Python Module Index" >modules</a> |</li> <li class="right" > <a href="cgitb.html" title="20.3. cgitb — Traceback manager for CGI scripts" >next</a> |</li> <li class="right" > <a href="webbrowser.html" title="20.1. webbrowser — Convenient Web-browser controller" >previous</a> |</li> <li><img src="../_static/py.png" alt="" style="vertical-align: middle; margin-top: -1px"/></li> <li><a href="https://www.python.org/">Python</a> »</li> <li> <a href="../index.html">Python 2.7.16 documentation</a> » </li> <li class="nav-item nav-item-1"><a href="index.html" >The Python Standard Library</a> »</li> <li class="nav-item nav-item-2"><a href="internet.html" >20. Internet Protocols and Support</a> »</li> </ul> </div> <div class="footer"> © <a href="../copyright.html">Copyright</a> 1990-2019, Python Software Foundation. <br /> The Python Software Foundation is a non-profit corporation. <a href="https://www.python.org/psf/donations/">Please donate.</a> <br /> Last updated on Mar 27, 2019. <a href="../bugs.html">Found a bug</a>? <br /> Created using <a href="http://sphinx.pocoo.org/">Sphinx</a> 1.7.6. </div> </body> </html>
Save
cmd:
run