Skip to content

Commit

Permalink
fix(parse): handle excessive slashes in scheme-relative URLs
Browse files Browse the repository at this point in the history
reported by @zeyu2001 via huntr.dev
  • Loading branch information
rodneyrehm committed Apr 3, 2022
1 parent 926b2aa commit 88805fd
Show file tree
Hide file tree
Showing 3 changed files with 104 additions and 0 deletions.
4 changes: 4 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -2,6 +2,10 @@

The release notes tracked in this document are also made available on the [releases page](https://github.com/medialize/URI.js/releases)

### master ###

* **SECURITY** fixing [`URI.parse()`](http://medialize.github.io/URI.js/docs.html#static-parse) handle excessive slashes in scheme-relative URLs - disclosed by [zeyu2001](https://github.com/zeyu2001) via https://huntr.dev/

### 1.19.10 (March 5th 2022) ###

* **SECURITY** fixing [`URI.parse()`](http://medialize.github.io/URI.js/docs.html#static-parse) handle excessive colons in protocol delimiter - disclosed by [huydoppa](https://github.com/huydoppa) via https://huntr.dev/
Expand Down
2 changes: 2 additions & 0 deletions src/URI.js
Original file line number Diff line number Diff line change
Expand Up @@ -518,6 +518,8 @@

// slashes and backslashes have lost all meaning for the web protocols (https, http, wss, ws)
string = string.replace(/^(https?|ftp|wss?)?:+[/\\]*/i, '$1://');
// slashes and backslashes have lost all meaning for scheme relative URLs
string = string.replace(/^[/\\]{2,}/i, '//');

// extract protocol
if (string.substring(0, 2) === '//') {
Expand Down
98 changes: 98 additions & 0 deletions test/urls.js
Original file line number Diff line number Diff line change
Expand Up @@ -581,6 +581,55 @@ var urls = [{
idn: false,
punycode: false
}
}, {
name: 'ignoring scheme excessive slashes',
url: ':/\\//user:pass@example.org:123/some/directory/file.html?query=string#fragment',
_url: '//user:pass@example.org:123/some/directory/file.html?query=string#fragment',
parts: {
protocol: null,
username: 'user',
password: 'pass',
hostname: 'example.org',
port: '123',
path: '/some/directory/file.html',
query: 'query=string',
fragment: 'fragment'
},
accessors: {
protocol: '',
username: 'user',
password: 'pass',
port: '123',
path: '/some/directory/file.html',
query: 'query=string',
fragment: 'fragment',
resource: '/some/directory/file.html?query=string#fragment',
authority: 'user:pass@example.org:123',
origin: 'user:pass@example.org:123',
userinfo: 'user:pass',
subdomain: '',
domain: 'example.org',
tld: 'org',
directory: '/some/directory',
filename: 'file.html',
suffix: 'html',
hash: '#fragment',
search: '?query=string',
host: 'example.org:123',
hostname: 'example.org'
},
is: {
urn: false,
url: true,
relative: false,
name: true,
sld: false,
ip: false,
ip4: false,
ip6: false,
idn: false,
punycode: false
}
}, {
name: 'scheme-relative URL',
url: '//www.example.org/',
Expand Down Expand Up @@ -629,6 +678,55 @@ var urls = [{
idn: false,
punycode: false
}
}, {
name: 'scheme-relative URL excessive slashes',
url: '//\\/www.example.org/',
_url: '//www.example.org/',
parts: {
protocol: null,
username: null,
password: null,
hostname: 'www.example.org',
port: null,
path: '/',
query: null,
fragment: null
},
accessors: {
protocol: '',
username: '',
password: '',
port: '',
path: '/',
query: '',
fragment: '',
resource: '/',
authority: 'www.example.org',
origin: 'www.example.org',
userinfo: '',
subdomain: 'www',
domain: 'example.org',
tld: 'org',
directory: '/',
filename: '',
suffix: '',
hash: '',
search: '',
host: 'www.example.org',
hostname: 'www.example.org'
},
is: {
urn: false,
url: true,
relative: false,
name: true,
sld: false,
ip: false,
ip4: false,
ip6: false,
idn: false,
punycode: false
}
}, {
name: 'missing authority',
url: 'food:///test/file.csv',
Expand Down

0 comments on commit 88805fd

Please sign in to comment.