Skip to content

fix: percent-encode path parameters in sendRequest - #361

Open
RaphaelFakhri wants to merge 1 commit into
GetStream:mainfrom
RaphaelFakhri:fix/encode-path-params
Open

RaphaelFakhri wants to merge 1 commit into
GetStream:mainfrom
RaphaelFakhri:fix/encode-path-params

Conversation

@RaphaelFakhri

Copy link
Copy Markdown

Summary

ApiClient.sendRequest substituted path parameters into the URL without encoding them. A value that contains /, ?, # or % changed the request instead of identifying a resource. For example, getMessage({ id: 'a/b' }) requested /messages/a/b, and an id containing # or ? was cut off at that character.

Each value is now encoded with encodeURIComponent before it replaces its {name} token in the path template. Plain ids (letters, digits, -, _) are unchanged. Values with :, such as feed ids, go on the wire as %3A, which is how stream-py (quote(v, safe="")) and getstream-go (url.QueryEscape) already send path parameters.

Testing

__tests__/path-params.test.ts mocks fetch and checks the requested URL for plain values, reserved characters, and several path parameters in one URL. It needs no API credentials.

yarn vitest run __tests__/path-params.test.ts

Prettier and ESLint are clean on the changed files.

Path parameter values were substituted into the URL as-is, so an id containing '/', '?', '#' or '%' changed the request path or was truncated. Each value is now encoded with encodeURIComponent.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant