From 92128df91e1ccd401793a6eaf46366028d964415 Mon Sep 17 00:00:00 2001 From: Akshay Date: Mon, 28 Apr 2025 21:35:10 +0100 Subject: [PATCH] appview: path-escape all refs passed between appview & knotserver --- appview/state/pull.go | 2 +- appview/state/signer.go | 2 +- knotserver/routes.go | 6 ++++++ 3 files changed, 8 insertions(+), 2 deletions(-) diff --git a/appview/state/pull.go b/appview/state/pull.go index 790d8a81..931ac3ef 100644 --- a/appview/state/pull.go +++ b/appview/state/pull.go @@ -779,7 +779,7 @@ func (s *State) handleForkBasedPull(w http.ResponseWriter, r *http.Request, f *F return } - hiddenRef := url.QueryEscape(fmt.Sprintf("hidden/%s/%s", sourceBranch, targetBranch)) + hiddenRef := fmt.Sprintf("hidden/%s/%s", sourceBranch, targetBranch) // We're now comparing the sourceBranch (on the fork) against the hiddenRef which is tracking // the targetBranch on the target repository. This code is a bit confusing, but here's an example: // hiddenRef: hidden/feature-1/main (on repo-fork) diff --git a/appview/state/signer.go b/appview/state/signer.go index fc65ec5c..687b6ab9 100644 --- a/appview/state/signer.go +++ b/appview/state/signer.go @@ -328,7 +328,7 @@ func (us *UnsignedClient) Branch(ownerDid, repoName, branch string) (*http.Respo Method = "GET" ) - endpoint := fmt.Sprintf("/%s/%s/branches/%s", ownerDid, repoName, branch) + endpoint := fmt.Sprintf("/%s/%s/branches/%s", ownerDid, repoName, url.PathEscape(branch)) req, err := us.newRequest(Method, endpoint, nil) if err != nil { diff --git a/knotserver/routes.go b/knotserver/routes.go index 3f390a28..4ab94618 100644 --- a/knotserver/routes.go +++ b/knotserver/routes.go @@ -461,6 +461,8 @@ func (h *Handle) Branches(w http.ResponseWriter, r *http.Request) { func (h *Handle) Branch(w http.ResponseWriter, r *http.Request) { path, _ := securejoin.SecureJoin(h.c.Repo.ScanPath, didPath(r)) branchName := chi.URLParam(r, "branch") + branchName, _ = url.PathUnescape(branchName) + l := h.l.With("handler", "Branch") gr, err := git.PlainOpen(path) @@ -829,7 +831,11 @@ func (h *Handle) NewHiddenRef(w http.ResponseWriter, r *http.Request) { l := h.l.With("handler", "NewHiddenRef") forkRef := chi.URLParam(r, "forkRef") + forkRef, _ = url.PathUnescape(forkRef) + remoteRef := chi.URLParam(r, "remoteRef") + remoteRef, _ = url.PathUnescape(remoteRef) + path, _ := securejoin.SecureJoin(h.c.Repo.ScanPath, didPath(r)) gr, err := git.PlainOpen(path) if err != nil { -- 2.51.2