Skip to content

fix(client): trim apiUrl slashes, no backtracking - #12

Merged
danieltruong merged 1 commit into
mainfrom
fix/client-trailing-slash
Sep 7, 2026
Merged

danieltruong merged 1 commit into
mainfrom
fix/client-trailing-slash

Conversation

@danieltruong

Copy link
Copy Markdown
Collaborator

CodeQL flagged js/polynomial-redos on the client's config.apiUrl.replace(/\/+$/, ''): a long run of slashes followed by any other character makes that regex retry from every offset, taking about 13 seconds on 100,000 slashes. The trim is now a backwards scan over the string, and client/test/transport.test.ts covers one, several and no trailing slashes plus a timing check on the 100,000-slash input.

@danieltruong
danieltruong merged commit 0a000b3 into main Sep 7, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant