mirror of
https://github.com/cloudflare/vinext.git
synced 2026-05-09 08:25:34 +02:00
[PR #801] [MERGED] fix: normalize URL scheme detection for control characters #855
Labels
No labels
enhancement
enhancement
good first issue
help wanted
nextjs-tracking
nextjs-tracking
pull-request
No milestone
No project
No assignees
1 participant
Notifications
Due date
No due date set.
Dependencies
No dependencies set.
Reference
starred/vinext#855
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "%!s()"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
📋 Pull Request Information
Original PR: https://github.com/cloudflare/vinext/pull/801
Author: @southpolesteve
Created: 4/9/2026
Status: ✅ Merged
Merged: 4/9/2026
Merged by: @southpolesteve
Base:
main← Head:fix/harden-url-scheme-control-chars📝 Commits (1)
4145e92fix: normalize dangerous URL scheme detection for control chars📊 Changes
2 files changed (+61 additions, -12 deletions)
View changed files
📝
packages/vinext/src/shims/url-safety.ts(+27 -4)📝
tests/url-safety.test.ts(+34 -8)📄 Description
Summary
Improve URL scheme detection so control-character-obfuscated values are recognized consistently in
LinkandForm.Details
The previous detector used a single regex that only matched contiguous scheme names, so values with embedded tab/newline characters or leading C0 controls were not handled consistently.
This change switches to scheme-specific patterns that mirror Next.js's
javascript:detector while preserving vinext's broaderdata:/vbscript:blocking:packages/next/src/client/lib/javascript-url.tsBehavior changes covered by tests:
java\nscript:/java\rscript:/java\tscript:are treated as dangerousTests
Updated
tests/url-safety.test.tswith 38 passing unit tests covering:🔄 This issue represents a GitHub Pull Request. It cannot be merged through Gitea due to API limitations.