guzzle / uri-template Goto Github PK
View Code? Open in Web Editor NEWLicense: MIT License
License: MIT License
Change GuzzleHttp\Utility\UriTemplate
to GuzzleHttp\Uri\Template
. This name is what was originally used in development of Guzzle 4, actually, and I think is better than a generic utility namespace.
The current spec recommends explicitly rejecting templates of invalid syntax, and indeed there are tests to check this happens. We currently don't do that. Should we bother? How hard would this be to do correctly?
If anyone wants to do this, that'd be great. If not, I will do it, eventually. :)
PHP version: 8.1.3
Description
As of a community reporting, while the uri was already contains the pct-encoded
(reserved characters) component, eg: AIO%2FFR
. The {+var}
syntax is explained this one as of AIO%252FFR
. It is leading to misinterpreting the original percent data octet string.
I've also checked the RFC3986 and RFC6570 specifications.
RFC3986 2.4. When to Encode or Decode
was mentioned there:
Because the percent ("%") character serves as the indicator for
percent-encoded octets, it must be percent-encoded as "%25" for that
octet to be used as data within a URI. Implementations must not
percent-encode or decode the same string more than once, as decoding
an already decoded string might lead to misinterpreting a percent
data octet as the beginning of a percent-encoding, or vice versa in
the case of percent-encoding an already percent-encoded string.
RFC6570 3.2.1. Variable Expansion
was mentioned there:
The allowed set for a given expansion depends on the expression type:
reserved ("+") and fragment ("#") expansions allow the set of
characters in the union of ( unreserved / reserved / pct-encoded ) to
be passed through without pct-encoding, whereas all other expression
types allow only unreserved characters to be passed through without
pct-encoding. Note that the percent character ("%") is only allowed
as part of a pct-encoded triplet and only for reserved/fragment
expansion: in all other cases, a value character of "%" MUST be pct-
encoded as "%25" by variable expansion.
The pct-encoded reserved character(%2F
) may pass through but it was encoded the char(%
) to %25
. It is mismatched the specs.
How to reproduce
<?php
require_once './vendor/autoload.php';
use GuzzleHttp\UriTemplate\UriTemplate;
echo UriTemplate::expand('merchant-service/images/{+slot}', ['slot' => 'AIO%2FFR']);
// result: merchant-service/images/AIO%252FFR
// Actually, there was required the url like this: `merchant-service/images/AIO%2FFR`
Possible Solution
Additional context
A declarative, efficient, and flexible JavaScript library for building user interfaces.
๐ Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
An Open Source Machine Learning Framework for Everyone
The Web framework for perfectionists with deadlines.
A PHP framework for web artisans
Bring data to life with SVG, Canvas and HTML. ๐๐๐
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
Some thing interesting about web. New door for the world.
A server is a program made to process requests and deliver data to clients.
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
Some thing interesting about visualization, use data art
Some thing interesting about game, make everyone happy.
We are working to build community through open source technology. NB: members must have two-factor auth.
Open source projects and samples from Microsoft.
Google โค๏ธ Open Source for everyone.
Alibaba Open Source for everyone
Data-Driven Documents codes.
China tencent open source team.