Merge pull request #3738 from breken-ai/fix/path-rule-percent-encoding

▚▚ fix(rules): decode percent-encoded PATH rule patterns before matching
This commit is contained in:
Owen Schwartz
2026-09-21 13:55:25 -04:00
committed by GitHub
2 changed files with 39 additions and 1 deletions
+6 -1
View File
@@ -20,6 +20,11 @@ function getSegmentRegex(patternPart: string): RegExp {
// resolves `.` / `..` segments, so a request like `/public%2F..%2Fadmin/`
// or `/public/../admin/` is matched as `/admin/`, not as a literal segment
// or a wildcard-swallowed sequence under `/public/*`.
//
// Applied to both the request path and the rule pattern: the pattern
// validator only accepts spaces / non-ASCII in percent-encoded form, so a
// rule like `/my%20docs/*` must be compared against the decoded segment
// `my docs`, not the literal text `my%20docs`.
function decodeAndResolvePath(p: string): string[] {
const rawParts = p.split("/").filter(Boolean);
@@ -48,7 +53,7 @@ function decodeAndResolvePath(p: string): string[] {
}
export function isPathAllowed(pattern: string, path: string): boolean {
const patternParts = pattern.split("/").filter(Boolean);
const patternParts = decodeAndResolvePath(pattern);
const pathParts = decodeAndResolvePath(path);
function matchSegments(