• Home
  • Features
  • Pricing
  • Docs
  • Announcements
  • Sign In

romshark / datapages / 37024249126

02 Oct 2026 03:02PM UTC coverage: 40.509% (+0.05%) from 40.458%
37024249126

push

github

romshark
fix: Escape or refuse URL characters in routes

- fix: Escape a quote in a route for the single-quoted JavaScript
  strings the generated code writes it into: the stream URL in
  data-init, the URL a reflectsignal query field rewrites and every
  action expression. RFC 3986 allows a quote in a path, but a raw one
  ends the string. For a page declared as

      // PageAuthor is /o'reilly

  the generated code writes data-init="@get('/o'reilly/_$/',{...})",
  and an action such as action.PageAuthor.Follow.POST() returns
  @post('/o'reilly/follow/').
  Both fail in the browser with a syntax error.

- fix: Refuse a route that contains ?, # or a % without two hex digits
  after it in datapages lint and gen, with a hint to write %3F, %23 or
  %25. Generated links, action expressions and stream URLs carry the
  route as written, where none of the three reaches the page:

      // PageSearch is /search?q
      // PageSharp is /c#
      // PagePercent is /100%

  href.PageSearch() returns /search?q/, which a browser requests as
  /search with the query q/; a link to /c#/ requests /c; a request
  for /100%/ does not parse, and net/http answers 400.

45 of 45 new or added lines in 4 files covered. (100.0%)

1 existing line in 1 file now uncovered.

14684 of 36249 relevant lines covered (40.51%)

544.81 hits per line

Source File
Press 'n' to go to next uncovered line, 'b' for previous

85.8
/runtime/httpserve/core.go


Source Not Available

STATUS · Troubleshooting · Open an Issue · Sales · Support · CAREERS · ENTERPRISE · START FREE TRIAL · SCHEDULE DEMO
ANNOUNCEMENTS · TWITTER · TOS & SLA · Supported CI Services · What's a CI service? · Automated Testing

© 2026 Coveralls, Inc