-
Notifications
You must be signed in to change notification settings - Fork 356
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
fix: properly parse relative URL with a "@" character
A query parameter with a "@" character could be incorrectly parsed. Example: "/[email protected]" => host: example.com The parse() method is also used in the `socket.io-client` package, to extract the namespace and the query parameters. Notes: - this bug does not seem exploitable, as an attacker would need to inject the query parameter in the code executed by the client. - we might use the URL object in the next major version, but that means dropping support for some platforms such as IE Reference: https://caniuse.com/url Thanks to Li Jiantao of STAR Labs (@starlabs_sg) for the responsible disclosure.
- Loading branch information
1 parent
ed6d016
commit 12b7d78
Showing
3 changed files
with
83 additions
and
2 deletions.
There are no files selected for viewing
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Original file line number | Diff line number | Diff line change |
---|---|---|
@@ -0,0 +1,68 @@ | ||
// imported from https://github.com/galkn/parseuri | ||
const expect = require("expect.js"); | ||
const parseuri = require("..").parse; | ||
|
||
describe("parseuri", function () { | ||
it("should parse an uri", function () { | ||
const http = parseuri("http://google.com"), | ||
https = parseuri("https://www.google.com:80"), | ||
query = parseuri("google.com:8080/foo/bar?foo=bar"), | ||
localhost = parseuri("localhost:8080"), | ||
ipv6 = parseuri("2001:0db8:85a3:0042:1000:8a2e:0370:7334"), | ||
ipv6short = parseuri("2001:db8:85a3:42:1000:8a2e:370:7334"), | ||
ipv6port = parseuri("2001:db8:85a3:42:1000:8a2e:370:7334:80"), | ||
ipv6abbrev = parseuri("2001::7334:a:80"), | ||
ipv6http = parseuri("http://[2001::7334:a]:80"), | ||
ipv6query = parseuri("http://[2001::7334:a]:80/foo/bar?foo=bar"); | ||
|
||
expect(http.protocol).to.be("http"); | ||
expect(http.port).to.be(""); | ||
expect(http.host).to.be("google.com"); | ||
expect(https.protocol).to.be("https"); | ||
expect(https.port).to.be("80"); | ||
expect(https.host).to.be("www.google.com"); | ||
expect(query.port).to.be("8080"); | ||
expect(query.query).to.be("foo=bar"); | ||
expect(query.path).to.be("/foo/bar"); | ||
expect(query.relative).to.be("/foo/bar?foo=bar"); | ||
expect(query.queryKey.foo).to.be("bar"); | ||
expect(query.pathNames[0]).to.be("foo"); | ||
expect(query.pathNames[1]).to.be("bar"); | ||
expect(localhost.protocol).to.be(""); | ||
expect(localhost.host).to.be("localhost"); | ||
expect(localhost.port).to.be("8080"); | ||
expect(ipv6.protocol).to.be(""); | ||
expect(ipv6.host).to.be("2001:0db8:85a3:0042:1000:8a2e:0370:7334"); | ||
expect(ipv6.port).to.be(""); | ||
expect(ipv6short.protocol).to.be(""); | ||
expect(ipv6short.host).to.be("2001:db8:85a3:42:1000:8a2e:370:7334"); | ||
expect(ipv6short.port).to.be(""); | ||
expect(ipv6port.protocol).to.be(""); | ||
expect(ipv6port.host).to.be("2001:db8:85a3:42:1000:8a2e:370:7334"); | ||
expect(ipv6port.port).to.be("80"); | ||
expect(ipv6abbrev.protocol).to.be(""); | ||
expect(ipv6abbrev.host).to.be("2001::7334:a:80"); | ||
expect(ipv6abbrev.port).to.be(""); | ||
expect(ipv6http.protocol).to.be("http"); | ||
expect(ipv6http.port).to.be("80"); | ||
expect(ipv6http.host).to.be("2001::7334:a"); | ||
expect(ipv6query.protocol).to.be("http"); | ||
expect(ipv6query.port).to.be("80"); | ||
expect(ipv6query.host).to.be("2001::7334:a"); | ||
expect(ipv6query.relative).to.be("/foo/bar?foo=bar"); | ||
|
||
const withUserInfo = parseuri("ws://foo:[email protected]"); | ||
|
||
expect(withUserInfo.protocol).to.eql("ws"); | ||
expect(withUserInfo.userInfo).to.eql("foo:bar"); | ||
expect(withUserInfo.user).to.eql("foo"); | ||
expect(withUserInfo.password).to.eql("bar"); | ||
expect(withUserInfo.host).to.eql("google.com"); | ||
|
||
const relativeWithQuery = parseuri("/[email protected]"); | ||
|
||
expect(relativeWithQuery.host).to.be(""); | ||
expect(relativeWithQuery.path).to.be("/foo"); | ||
expect(relativeWithQuery.query).to.be("[email protected]"); | ||
}); | ||
}); |