Information Exposure Vulnerability with Django and Memcached
danpalmer.me
danpalmer.me
I actually don't think that it's wrong for a driver library to have these sorts of features disabled by default, because the target audience is typically a slightly higher level of abstraction rather than the end-developer. I think the aim should be to mimic the API of the service as closely as possible with the same defaults where possible. It's then the responsibility of the abstraction layer closer to the application to decide what's more appropriate on that end, and for that to be resolved between the two.
The length check would still be necessary, but spaces (and other arbitrary bytes) would no longer break things.
Plus, Django actually implements these checks for non-Memcached backends, raising warnings if keys aren't Memcached compatible. This is done because very often in local development users might run the "local memory" cache backend, which is just a Python dict. In this case they probably want to know that what they're doing won't work when it gets to Memcached in production.