A `\:` route and a `:param` route at the same position make `ServeHTTP` panic or return 404
Nadie ha tomado este issue todavía.
Evaluación
- Dificultad
- 3/5
- Tiempo estimado
- 1-2 días
- Aptitud para principiantes
- 65/100
Línea de trabajo
Start by running the supplied Go reproducer and tracing the route matching reached through ServeHTTP. Add focused regression coverage for both registration orders, with /name:verb/x served by /name:verb/x and /name1 served by /name:id with id=1, without a panic; both routes should remain reachable.
Escrito por el modelo de indexación a partir del texto del issue.
Descripción
Issue Description
Registering a route with an escaped colon (/name\:verb/x) together with a route that has a
parameter at the same position (/name:id) makes one of them unreachable, depending on the order:
registered in that order, GET /name:verb/x panics inside ServeHTTP with index out of range [-1] and GET /name1 is a 404; registered the other way round, GET /name:verb/x is a 404. Each
route on its own is served as expected.
Working code to debug
package main
import (
"fmt"
"net/http"
"net/http/httptest"
"strings"
"github.com/labstack/echo/v5"
)
func get(e *echo.Echo, path string) (out string) {
defer func() {
if r := recover(); r != nil {
out = fmt.Sprintf("panic: %v", r)
}
}()
rec := httptest.NewRecorder()
e.ServeHTTP(rec, httptest.NewRequest(http.MethodGet, path, nil))
return fmt.Sprintf("%d %s", rec.Code, strings.TrimSpace(rec.Body.String()))
}
func main() {
handler := func(c *echo.Context) error {
return c.String(http.StatusOK, "route "+c.RouteInfo().Path+" id="+c.Param("id"))
}
for _, routes := range [][]string{
{`/name\:verb/x`},
{`/name\:verb/x`, `/name:id`},
{`/name:id`, `/name\:verb/x`},
} {
e := echo.New()
for _, p := range routes {
e.GET(p, handler)
}
fmt.Printf("routes %s\n", routes)
for _, path := range []string{"/name:verb/x", "/name1"} {
fmt.Printf(" GET %-13s -> %s\n", path, get(e, path))
}
}
}
Output:
routes [/name\:verb/x]
GET /name:verb/x -> 200 route /name\:verb/x id=
GET /name1 -> 404 {"message":"Not Found"}
routes [/name\:verb/x /name:id]
GET /name:verb/x -> panic: runtime error: index out of range [-1]
GET /name1 -> 404 {"message":"Not Found"}
routes [/name:id /name\:verb/x]
GET /name:verb/x -> 404 {"message":"Not Found"}
GET /name1 -> 200 route /name:id id=1
The recover in get is only there to keep the program going: without it the panic propagates
out of e.ServeHTTP, and with a real server the client gets a closed connection instead of a
response. I expected both routes to be served in either order of registration, as each is when
registered alone: GET /name:verb/x by /name\:verb/x and GET /name1 by /name:id with
id=1.
Version/commit
echo v5.3.1 and current master (3d084be), Go 1.27.1.
BTW, this was found by an automated program that writes property-based tests for various open source projects using hegel (but it has been reviewed by hand before reporting). We've also potentially found (but not yet hand validated) 12 other bugs in echo. You can see the tests at https://github.com/hegeldev/hegel-zoo/tree/main/targets/go/echo. Let us know if you would like us to file the other bugs found and/or contribute the tests. NB the tests are currently LLM generated and probably not yet suitable for inclusion as is, but we're happy to help get them into a better state if you want them.
- Lenguaje dominante
- Go
- Estrellas
- 32.7k
- Forks
- 2.8k
- Merge medio
- 9 h 39 min
- PR fusionados (30 d)
- 6
Guía de contribución
No hay ninguna guía de contribución indexada para este repositorio
Primeros pasos
- Lee el issue completo y luego la guía de contribución del proyecto.
- Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
- Haz un fork del repositorio y trabaja en una rama.
- Abre un pull request que haga referencia al número del issue.
Más de labstack/echo
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 74/100
-
format tag conflicts with swag Abierto
Dificultad 3/5 1-2 días Aptitud para principiantes 68/100
-
Dificultad 3/5 1-2 días Aptitud para principiantes 74/100
-
Dificultad 5/5 Más de una semana Aptitud para principiantes 35/100
-
Dificultad 4/5 3-5 días Aptitud para principiantes 48/100
Todos los issues de labstack/echo
Issues similares
-
Dificultad 1/5 Menos de una hora Aptitud para principiantes 60/100
github/gh-aw-mcpg#13748 ·
-
agentic-workflows
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
-
needs-triage
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 65/100
-
Dificultad 2/5 1-3 horas Aptitud para principiantes 75/100
googleapis/librarian#7670 · 2 comentarios ·