Potentially incorrect behaviour processing URL query parameters
Nessuno ha ancora preso questa issue.
Valutazione
- Difficoltà
- 4/5
- Tempo stimato
- 3-5 giorni
- Idoneità per principianti
- 35/100
Direzione di ricerca
Start at ring.middleware.params/assoc-query-params and reproduce the two examples in a Clojure REPL. Trace how java.net.URLDecoder/decode errors are handled and review any nearby tests or middleware behavior. Done means the project has an agreed response for malformed query parameters and coverage for the reported input.
Scritto dal modello di indicizzazione a partire dal testo della issue.
Descrizione
When an error is raised while processing query parameters the offending query parameter is dropped from the response
user=> (require '[ring.middleware.params :as p])
nil
user=> (p/assoc-query-params {:query-string "agencyids=MY_AGENCY&ids=ID_1,ID_2"} "UTF-8")
{:query-string "agencyids=MY_AGENCY&ids=ID_1,ID_2", :query-params {"agencyids" "MY_AGENCY", "ids" "ID_1,ID_2"}, :params {"agencyids" "MY_AGENCY", "ids" "ID_1,ID_2"}}
user=> (p/assoc-query-params {:query-string "agencyids=MY_AGENCY&ids=%3c%%3d77%2a77%%3e"} "UTF-8")
{:query-string "agencyids=MY_AGENCY&ids=%3c%%3d77%2a77%%3e", :query-params {"agencyids" "MY_AGENCY"}, :params {"agencyids" "MY_AGENCY"}}
In the last line the ids parameter is dropped as it contains illegal characters %3c%%3d77%2a77%%3e and cannot be decoded by java.net.URLDecoder/decode.
The downstream effect of this is that the query proceeds and ultimately responds with with a 200 OK while I would expect that you would want a 400 Bad Request response in this case. I have not been able to find an authoritative source on the correct response and I am interested to hear any opinions on this?
- Lingua principale
- Clojure
- Stelle
- 3.9k
- Fork
- 528
- Metriche di merge delle PR
- Nessuna PR unita negli ultimi 30g
Preparare l'ambiente
- Nessun Dockerfile né file Docker Compose
- Nessun modello di pull request
- Leggi la guida per i contributori
Come iniziare
- Leggi tutta la issue e poi la guida ai contributi del progetto.
- Commenta sulla issue per dire che te ne occupi tu — evita che due persone facciano lo stesso lavoro.
- Fai un fork del repository e lavora su un branch.
- Apri una pull request che faccia riferimento al numero della issue.
Altre issue di ring-clojure/ring
-
Typo in wrap-nested-params docstringForse già presa @dajiaohuang l’ha presa 3 giorni fa. Aperta
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 78/100
ring-clojure/ring#546 ·
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 30/100
ring-clojure/ring#544 · 3 commenti ·
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 35/100
ring-clojure/ring#542 · 5 commenti · 2 reazioni ·
-
Difficoltà 5/5 Più di una settimana Idoneità per principianti 25/100
ring-clojure/ring#541 · 3 commenti ·
-
[ring-jetty-adapter] No control over exceptions thrown when obtaining item from ISeq response bodyAperta
Difficoltà 4/5 3-5 giorni Idoneità per principianti 35/100
ring-clojure/ring#531 · 4 commenti ·
Tutte le issue di ring-clojure/ring
Issue simili
-
Sessions are never closedAperta
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
Difficoltà 1/5 Meno di un'ora Idoneità per principianti 72/100
I maintainer di solito rispondono entro 1 giorno
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 64/100
-
Difficoltà 2/5 1-3 ore Idoneità per principianti 72/100
-
category:tooling
Difficoltà 2/5 1-3 ore Idoneità per principianti 62/100
I maintainer di solito rispondono entro 1 giorno