Conversation
When a regexp placeholder is followed by a literal suffix, the slash check was previously bypassed because it was in an else-if branch after the regexp check. Consequently, a regexp parameter could span path segments (e.g. matching 'a/b' in '/re/a/b.json'). Move the slash check outside of the else-if so it applies to both regexp and parameter nodes with suffixes.
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Fixes #1188.
When a regexp placeholder is followed by a literal suffix (such as
{name:[^.]+}.json), the check preventing matches across path segments (strings.IndexByte(xsearch[:p], '/') != -1) was placed inside anelse ifbranch followingntyp == ntRegexp && xn.rex != nil.Because
ntRegexptook the firstifbranch, it bypassed the slash check entirely when a suffix was present. Consequently, a request like/re/a/b.jsonevaluatedxsearch[:p]as"a/b", which matched[^.]+and crossed path segments, contrary to the specification that regexp placeholders do not match/.This change moves the segment boundary slash check before the regexp matching condition so that it guards both regexp and parameter nodes with tail suffixes.
Tests
TestMuxRegexpSuffixSlashinmux_test.goverifying that/re/a.jsonmatches"a"and/re/a/b.jsonreturns 404.go test -v ./...passes.