Improve uri.parseQuery to never raise an error (#16647)
In case of malformed query string where there is `=` on the value, handle
this character as part of the value instead of throwing an error.
The following query string should no longer crash a program:
key=value&key2=x=1
It will be interpreted as [("key", "value"), ("key2", "x=1")]
This is correct according to latest WhatWG's HTML5 specification
recarding the urlencoded parser:
https://url.spec.whatwg.org/#concept-urlencoded-parser
Older behavior can be restored using the -d:nimLegacyParseQueryStrict
flag.
This commit is contained in:
parent
bb3c6d0797
commit
71db2be833
4 changed files with 38 additions and 27 deletions
|
|
@ -84,11 +84,8 @@ proc getEncodedData(allowedMethods: set[RequestMethod]): string =
|
|||
iterator decodeData*(data: string): tuple[key, value: TaintedString] =
|
||||
## Reads and decodes CGI data and yields the (name, value) pairs the
|
||||
## data consists of.
|
||||
try:
|
||||
for (key, value) in uri.decodeQuery(data):
|
||||
yield (key, value)
|
||||
except UriParseError as e:
|
||||
cgiError(e.msg)
|
||||
for (key, value) in uri.decodeQuery(data):
|
||||
yield (key, value)
|
||||
|
||||
iterator decodeData*(allowedMethods: set[RequestMethod] =
|
||||
{methodNone, methodPost, methodGet}): tuple[key, value: TaintedString] =
|
||||
|
|
@ -96,11 +93,8 @@ iterator decodeData*(allowedMethods: set[RequestMethod] =
|
|||
## data consists of. If the client does not use a method listed in the
|
||||
## `allowedMethods` set, a `CgiError` exception is raised.
|
||||
let data = getEncodedData(allowedMethods)
|
||||
try:
|
||||
for (key, value) in uri.decodeQuery(data):
|
||||
yield (key, value)
|
||||
except UriParseError as e:
|
||||
cgiError(e.msg)
|
||||
for (key, value) in uri.decodeQuery(data):
|
||||
yield (key, value)
|
||||
|
||||
proc readData*(allowedMethods: set[RequestMethod] =
|
||||
{methodNone, methodPost, methodGet}): StringTableRef =
|
||||
|
|
|
|||
Loading…
Add table
Add a link
Reference in a new issue