Merge pull request #1070 from Shopify/url-decode-validation

Validate the character encoding in url_decode.
This commit is contained in:
Clayton Smith
2019-03-08 11:09:40 -05:00
committed by GitHub
2 changed files with 10 additions and 1 deletions

View File

@@ -52,7 +52,12 @@ module Liquid
end
def url_decode(input)
CGI.unescape(input.to_s) unless input.nil?
return if input.nil?
result = CGI.unescape(input.to_s)
raise Liquid::ArgumentError, "invalid byte sequence in #{result.encoding}" unless result.valid_encoding?
result
end
def slice(input, offset, length = nil)

View File

@@ -158,6 +158,10 @@ class StandardFiltersTest < Minitest::Test
assert_equal '1', @filters.url_decode(1)
assert_equal '2001-02-03', @filters.url_decode(Date.new(2001, 2, 3))
assert_nil @filters.url_decode(nil)
exception = assert_raises Liquid::ArgumentError do
@filters.url_decode('%ff')
end
assert_equal 'Liquid error: invalid byte sequence in UTF-8', exception.message
end
def test_truncatewords