Skip to content

Do not throw when a redirect URL has a malformed escape sequence - #223

Open
RaphaelFakhri wants to merge 1 commit into
cloudflare:mainfrom
RaphaelFakhri:fix/safe-redirect-malformed-url
Open

RaphaelFakhri wants to merge 1 commit into
cloudflare:mainfrom
RaphaelFakhri:fix/safe-redirect-malformed-url

Conversation

@RaphaelFakhri

Copy link
Copy Markdown

Problem

safeRedirect passes the target URL through decodeURI before it builds the redirect. decodeURI throws a URIError when the string contains a malformed escape sequence such as %zz. A return-url query parameter or a room URL with such a sequence makes the set-username action and the root loader fail with a 500 instead of redirecting.

For example, open /set-username?return-url=%2Froom%2F100%25zz without a display name set and submit the form. The action throws URIError: URI malformed.

Solution

Decode through a small helper that falls back to the raw value when decodeURI throws. The existing scheme check runs on that value unchanged.

Testing

npx vitest --watch false app/utils/safeReturnUrl.test.ts

The new test file covers a normal redirect, the existing scheme check, and two URLs with a malformed sequence. Without the change, the two malformed cases fail with URIError: URI malformed. With the change, all four tests pass.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant