[4.x] Only replace hostname in tenant_route helper and the domain redirect macro - #1490
Conversation
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Organization UI Review profile: ASSERTIVE Plan: Advanced Run ID: 📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 8 included reviews per hour; 7 remain after this review. 📝 WalkthroughWalkthroughThe redirect and tenant route helper now replace only the first protocol-and-hostname match. Updated tests check that email parameters remain encoded in generated URLs. ChangesURL hostname replacement
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Bug fix · Severity of issue fixed: Low Merge Risk: ⚪ Minimal · up to The URL helpers now limit hostname substitution to the URL authority, preserving encoded email query values. No merge-blocking risk is established. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The change confines hostname replacement to the start of the URL authority and preserves matching text in query values. No new redirect entrypoint or boundary bypass was established, though behavior for less-common URL forms and production callers is not fully covered. Retained concerns Security review detailsSecurity Blast Radius
Trust Boundaries and Controls
🚥 Pre-merge checks | ✅ 4 | ❌ 1❌ Failed checks (1 warning)
✅ Passed checks (4 passed)
✨ Finishing Touches 💡 1📝 Generate docstrings 💡
🧪 Generate unit tests (beta)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. A rabbit hops along the route, Comment |
Codecov Report✅ All modified and coverable lines are covered by tests. Additional details and impacted files@@ Coverage Diff @@
## master #1490 +/- ##
=========================================
Coverage 86.89% 86.89%
Complexity 1252 1252
=========================================
Files 186 186
Lines 3654 3654
=========================================
Hits 3175 3175
Misses 479 479 ☔ View full report in Codecov by Harness. 🚀 New features to boost your workflow:
|
tenant_route()replaces all occurrences of the hostname in the URL generated byroute(). When used liketenant_route('foo.localhost', 'foo', ['email' => 'foo@localhost']), it generateshttp://foo.localhost/abcdef?email=foo%40foo.localhost. So the query parameter'slocalhostgets replaced withfoo.localhostwhich shouldn't happen -- only the actual hostname should be replaced. Same goes for thedomainmacro registered inCrossDomainRedirect.This PR makes both
tenant_route()and thedomain()macro replace only the hostname. Sotenant_route('foo.localhost', 'foo', ['email' => 'foo@localhost'])now generateshttp://foo.localhost/abcdef?email=foo%40localhost, andredirect()->route('home', ['email' => 'foo@localhost'])->domain('abcd')redirects tohttp://abcd/foobar?email=foo%40localhost.Summary by CodeRabbit