diff options
| author | Nicolai Dagestad <nicolai@dagestad.fr> | 2024-09-15 15:03:21 +0200 |
|---|---|---|
| committer | Nicolai Dagestad <nicolai@dagestad.fr> | 2024-09-15 18:39:49 +0200 |
| commit | ba5cbb6d828165a43826c6afdd71fa2edbdca302 (patch) | |
| tree | 87290e2f2a97433c35f0ce86cd14cabe9703dd2c /mastoapi.c | |
| parent | 31ce1af73630143036d9cfc6a8a5083402f6b7aa (diff) | |
URL decode data after splitting the arguments
Data decoding should happen after the parsing if not, a '?', '&', '#'
or other character decoded will interfere with the parsing. e.g. the
users password contains a '&', then it is truncated on that character,
and login will fail.
Diffstat (limited to 'mastoapi.c')
| -rw-r--r-- | mastoapi.c | 12 |
1 files changed, 4 insertions, 8 deletions
@@ -262,8 +262,7 @@ int oauth_post_handler(const xs_dict *req, const char *q_path, } else if (i_ctype && xs_startswith(i_ctype, "application/x-www-form-urlencoded") && payload) { - xs *upl = xs_url_dec(payload); - args = xs_url_vars(upl); + args = xs_url_vars(payload); } else args = xs_dup(xs_dict_get(req, "p_vars")); @@ -2361,8 +2360,7 @@ int mastoapi_post_handler(const xs_dict *req, const char *q_path, { // Some apps send form data instead of json so we should cater for those if (!xs_is_null(payload)) { - xs *upl = xs_url_dec(payload); - args = xs_url_vars(upl); + args = xs_url_vars(payload); } } else @@ -2959,8 +2957,7 @@ int mastoapi_delete_handler(const xs_dict *req, const char *q_path, { // Some apps send form data instead of json so we should cater for those if (!xs_is_null(payload)) { - xs *upl = xs_url_dec(payload); - args = xs_url_vars(upl); + args = xs_url_vars(payload); } } else @@ -3194,8 +3191,7 @@ int mastoapi_patch_handler(const xs_dict *req, const char *q_path, { // Some apps send form data instead of json so we should cater for those if (!xs_is_null(payload)) { - xs *upl = xs_url_dec(payload); - args = xs_url_vars(upl); + args = xs_url_vars(payload); } } else |