Skip to content

Commit 337668d

Browse files
author
deepshekhardas
committed
fix: safe decode malformed URI route params
1 parent 779d52a commit 337668d

6 files changed

Lines changed: 37 additions & 6 deletions

File tree

Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
---
2+
"@refinedev/core": patch
3+
"@refinedev/react-router": patch
4+
"@refinedev/remix-router": patch
5+
---
6+
7+
Safely handle malformed URI-encoded route params when parsing route ids and query targets.

‎packages/core/src/definitions/helpers/handleUseParams/index.tsx‎

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,8 +1,16 @@
1+
const safeDecodeURIComponent = (value: string) => {
2+
try {
3+
return decodeURIComponent(value);
4+
} catch {
5+
return value;
6+
}
7+
};
8+
19
export const handleUseParams = (params: any = {}): any => {
210
if (params?.id) {
311
return {
412
...params,
5-
id: decodeURIComponent(params.id),
13+
id: safeDecodeURIComponent(params.id),
614
};
715
}
816
return params;

‎packages/react-router/src/bindings.tsx‎

Lines changed: 3 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -17,6 +17,7 @@ import {
1717
useParams,
1818
} from "react-router";
1919
import { convertToNumberIfPossible } from "./convert-to-number-if-possible";
20+
import { safeDecodeURIComponent } from "./safe-decode-uri-component";
2021

2122
export const stringifyConfig = {
2223
addQueryPrefix: true,
@@ -124,7 +125,7 @@ export const routerProvider: RouterProvider = {
124125
const response: ParseResponse = {
125126
...(resource && { resource }),
126127
...(action && { action }),
127-
...(params?.id && { id: decodeURIComponent(params.id) }),
128+
...(params?.id && { id: safeDecodeURIComponent(params.id) }),
128129
// ...(params?.action && { action: params.action }), // lets see if there is a need for this
129130
pathname,
130131
params: {
@@ -136,7 +137,7 @@ export const routerProvider: RouterProvider = {
136137
combinedParams.pageSize as string,
137138
) as number | undefined,
138139
to: combinedParams.to
139-
? decodeURIComponent(combinedParams.to as string)
140+
? safeDecodeURIComponent(combinedParams.to as string)
140141
: undefined,
141142
},
142143
};
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
export const safeDecodeURIComponent = (value: string) => {
2+
try {
3+
return decodeURIComponent(value);
4+
} catch {
5+
return value;
6+
}
7+
};

‎packages/remix-router/src/bindings.tsx‎

Lines changed: 4 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -11,6 +11,7 @@ import qs from "qs";
1111
import React, { type ComponentProps, useCallback, useContext } from "react";
1212
import { paramsFromCurrentPath } from "./params-from-current-path";
1313
import { convertToNumberIfPossible } from "./convert-to-number-if-possible";
14+
import { safeDecodeURIComponent } from "./safe-decode-uri-component";
1415

1516
export const stringifyConfig = {
1617
addQueryPrefix: true,
@@ -116,8 +117,8 @@ export const routerProvider: RouterProvider = {
116117
const response: ParseResponse = {
117118
...(resource && { resource }),
118119
...(action && { action }),
119-
...(inferredId && { id: decodeURIComponent(inferredId) }),
120-
...(params?.id && { id: decodeURIComponent(params.id) }),
120+
...(inferredId && { id: safeDecodeURIComponent(inferredId) }),
121+
...(params?.id && { id: safeDecodeURIComponent(params.id) }),
121122
// ...(params?.action && { action: params.action }), // lets see if there is a need for this
122123
pathname,
123124
params: {
@@ -129,7 +130,7 @@ export const routerProvider: RouterProvider = {
129130
combinedParams.pageSize as string,
130131
) as number | undefined,
131132
to: combinedParams.to
132-
? decodeURIComponent(combinedParams.to as string)
133+
? safeDecodeURIComponent(combinedParams.to as string)
133134
: undefined,
134135
},
135136
};
Lines changed: 7 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,7 @@
1+
export const safeDecodeURIComponent = (value: string) => {
2+
try {
3+
return decodeURIComponent(value);
4+
} catch {
5+
return value;
6+
}
7+
};

0 commit comments

Comments
 (0)