use strict hex parsing in decode_query_component (#2472)

This commit is contained in:
metsw24-max
2026-06-12 13:54:04 -04:00
committed by GitHub
parent 7532932276
commit 28d95937b5
2 changed files with 16 additions and 5 deletions
+13
View File
@@ -386,6 +386,19 @@ TEST(DecodePathTest, UnicodeEncoding) {
EXPECT_EQ("", decode_path_component("%uD800"));
}
TEST(DecodeQueryTest, RejectsNonHexEscapes) {
// A sign or whitespace inside the two-character escape window must not be
// accepted as a valid percent-encoding; the sequence is passed through
// literally, matching decode_uri_component / decode_path_component.
EXPECT_EQ("%-1", decode_query_component("%-1", false));
EXPECT_EQ("%-0", decode_query_component("%-0", false));
EXPECT_EQ("%+5", decode_query_component("%+5", false));
EXPECT_EQ("% 5", decode_query_component("% 5", false));
// Well-formed escapes still decode.
EXPECT_EQ("-", decode_query_component("%2D", false));
EXPECT_EQ("A", decode_query_component("%41", false));
}
TEST(SanitizeFilenameTest, VariousPatterns) {
// Path traversal
EXPECT_EQ("passwd", httplib::sanitize_filename("../../../etc/passwd"));