Sitelet https://github.com/unjs/ufo/pull/352
Skip to content

fix: don't add // authority when stringifying opaque-path protocols - #352

Open
sarathfrancis90 wants to merge 1 commit into
unjs:mainfrom
sarathfrancis90:fix/stringify-opaque-protocol
Open

sarathfrancis90 wants to merge 1 commit into
unjs:mainfrom
sarathfrancis90:fix/stringify-opaque-protocol

Conversation

@sarathfrancis90

@sarathfrancis90 sarathfrancis90 commented Jun 14, 2026 •

Copy link
Copy Markdown

I noticed stringifyParsedurl(/sitelet?url=https%3A%2F%2Fgithub.com%2Funjs%2Fufo%2Fpull%2FparseURL%28x)) corrupts data: URLs (and other opaque-path schemes), and the damage compounds on every round-trip:

import { parseURL, stringifyParsedURL, normalizeURL } from "ufo";

stringifyParsedURL(parseURL("data:text/plain"));
// "data://text/plain"   ← spurious //

normalizeURL("data:text/plain");                 // "data://text/plain"
normalizeURL(normalizeURL("data:text/plain"));   // "data:////text/plain"
// each pass adds two more slashes

Same for blob:, javascript: and vbscript:.

parseURL correctly keeps the opaque path of these schemes (that was fixed in #158), but stringifyParsedURL always appended // after any protocol — opaque-path schemes have no // authority, so the extra slashes break the URL and the parse↔stringify round-trip.

The fix only emits the // authority for non-opaque protocols (or protocol-relative URLs). file://, http://, //host and protocol-relative URLs are unaffected.

Found by fuzzing the parse→stringify round-trip / normalizeURL idempotency. Added stringify round-trip cases plus two normalizeURL cases; full suite, lint and typecheck pass.

Summary by CodeRabbit

Release Notes

  • Bug Fixes
    • Fixed URL parsing logic to correctly handle opaque protocols (data:, blob:, javascript:, vbscript:). These special protocols now preserve their format during round-trip serialization without incorrectly appending authority prefixes.

parseURL keeps the path of opaque-path schemes (data:, blob:, javascript:,
vbscript:) verbatim, but stringifyParsedURL unconditionally appended // after
any protocol. As a result stringifyParsedurl(/sitelet?url=https%3A%2F%2Fgithub.com%2Funjs%2Fufo%2Fpull%2FparseURL%28%2522data%3Atext%2Fplain%2522))
returned "data://text/plain", and the extra slashes compounded on every
round-trip ("data:////text/plain", ...). normalizeURL was likewise
non-idempotent for these URLs.

Only emit the // authority for non-opaque protocols (or protocol-relative
URLs).
@coderabbitai

coderabbitai Bot commented Jun 14, 2026 •

Copy link
Copy Markdown

Review Change Stack

📝 Walkthrough

Walkthrough

src/parse.ts gains a OPAQUE_PROTOCOL_RE constant matching data:, blob:, javascript:, and vbscript: schemes, and stringifyParsedURL is updated to omit the // authority prefix for those protocols. New tests verify both stringification and round-trip behaviour for these opaque-path URLs.

Changes

Opaque Protocol Fix in stringifyParsedURL

Layer / File(s) Summary
OPAQUE_PROTOCOL_RE regex and stringifyParsedURL logic
src/parse.ts
Introduces OPAQUE_PROTOCOL_RE (matching data:, blob:, javascript:, vbscript:) and conditionally skips the // authority separator in stringifyParsedURL when the protocol is opaque, leaving all other protocols unchanged.
Opaque protocol round-trip and normalization tests
test/utilities.test.ts, test/normalize.test.ts
Adds parseURL import; extends stringifyParsedURL test matrix for data:, blob:, and javascript: inputs; adds a dedicated round-trip test (parseURL → stringifyParsedURL); adds normalizeURL cases for data: and blob: URLs.

Estimated code review effort

🎯 2 (Simple) | ⏱️ ~10 minutes

Poem

🐇 Hop, hop, no double-slash for me!
data: and blob: stay opaque, you see.
A tiny regex guards the URL gate,
No // sneaks in — the round-trip is great.
This bunny approves, the scheme is now straight! ✨

🚥 Pre-merge checks | ✅ 5
✅ Passed checks (5 passed)
Check name Status Explanation
Description Check ✅ Passed Check skipped - CodeRabbit’s high-level summary is enabled.
Title check ✅ Passed The title clearly and specifically describes the main fix: preventing erroneous // authority insertion for opaque-path protocols like data: and blob: during URL stringification.
Docstring Coverage ✅ Passed Docstring coverage is 100.00% which is sufficient. The required threshold is 80.00%.
Linked Issues check ✅ Passed Check skipped because no linked issues were found for this pull request.
Out of Scope Changes check ✅ Passed Check skipped because no linked issues were found for this pull request.

✏️ Tip: You can configure your own custom pre-merge checks in the settings.

✨ Finishing Touches
🧪 Generate unit tests (beta)
  • Create PR with unit tests

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands and usage tips.

@coderabbitai coderabbitai Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

🧹 Nitpick comments (1)
test/normalize.test.ts (1)

45-46: ⚡ Quick win

Extend normalizeURL opaque cases to javascript: and vbscript:.

Since opaque handling now explicitly includes those schemes, add normalize identity checks for both to prevent partial coverage drift.

Suggested patch
     "data:text/plain;base64,aGVsbG8=": "data:text/plain;base64,aGVsbG8=",
     "blob:https://example.com/uuid": "blob:https://example.com/uuid",
+    "javascript:alert('hello')": "javascript:alert('hello')",
+    "vbscript:msgbox('hello')": "vbscript:msgbox('hello')",
   };
🤖 Prompt for AI Agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

In `@test/normalize.test.ts` around lines 45 - 46, The normalizeURL test cases for
opaque URL schemes are incomplete. In the test/normalize.test.ts file around
lines 45-46, add identity check test cases for the javascript: and vbscript:
schemes to the test object, following the same pattern as the existing data: and
blob: scheme cases. Each new case should verify that URLs with these schemes are
normalized to themselves unchanged.
🤖 Prompt for all review comments with AI agents
Verify each finding against current code. Fix only still-valid issues, skip the
rest with a brief reason, keep changes minimal, and validate.

Nitpick comments:
In `@test/normalize.test.ts`:
- Around line 45-46: The normalizeURL test cases for opaque URL schemes are
incomplete. In the test/normalize.test.ts file around lines 45-46, add identity
check test cases for the javascript: and vbscript: schemes to the test object,
following the same pattern as the existing data: and blob: scheme cases. Each
new case should verify that URLs with these schemes are normalized to themselves
unchanged.

ℹ️ Review info
⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Pro

Run ID: 156b2e19-d527-4fe8-a326-98258cd75ca9

📥 Commits

Reviewing files that changed from the base of the PR and between f06c800 and 4f3ea42.

📒 Files selected for processing (3)
  • src/parse.ts
  • test/normalize.test.ts
  • test/utilities.test.ts

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant