Skip to content

fix(server): tolerate malformed percent-encoding in MongoDB URI database - #333

Open
tahodev wants to merge 1 commit into
wordbricks:mainfrom
tahodev:fix/mongodb-uri-malformed-percent-encoding
Open

tahodev wants to merge 1 commit into
wordbricks:mainfrom
tahodev:fix/mongodb-uri-malformed-percent-encoding

Conversation

@tahodev

@tahodev tahodev commented Sep 25, 2026

Copy link
Copy Markdown

What

extractDatabaseFromMongoUri in packages/server/src/services/mongodb/relay.ts ran decodeURIComponent on the connection-string path without guarding against URIError.

Why

URL.canParse / new URL(...) do not validate percent-encoding, so a MongoDB connection string whose database path contains a literal % or a truncated escape (for example mongodb://user:pass@host:27017/db%zz) passes the existing parse guards and then crashes resolveMongoDatabaseAccess with an uncaught URIError: URI malformed. That exception fires before any database validation and surfaces as an unhelpful server error from the relay endpoints (listMongoDatabases, listMongoCollections, findMongoDocuments).

Change

Treat an undecodable path exactly like an unparseable URI: catch the URIError and return null, matching the URL.canParse guard directly above. Valid percent-encoded database names keep decoding as before.

Validation

  • New regression test in relay.test.ts fails before the fix (thrown URIError: URI malformed instead of the expected allowlist error) and passes after it: vitest run src/services/mongodb/relay.test.ts — 4/4.
  • oxfmt --check passes on the changed files.
  • Note: local oxlint aborts with a Rust allocator panic in this environment, so lint was not run locally.

extractDatabaseFromMongoUri ran decodeURIComponent on the URI path
without guarding against URIError. URL parsing does not validate
percent-encoding, so a connection string whose database path contains a
literal "%" or truncated escape (for example db%zz) crashed the relay
with an uncaught URIError before any validation could run.

Treat an undecodable path like an unparseable URI and return null, which
matches the existing URL.canParse guard just above. Adds a regression
test that fails with URIError: URI malformed before the fix.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant