Encode server action URLs safely and fix GraphArea lint return path#340
Merged
pradeeban merged 3 commits intoControlCore-Project:devfrom Feb 23, 2026
Merged
Conversation
Member
|
Such special characters are unlikely in practice. So, we did not bother with this. But the PR looks harmless and fixes something that might happen at some point. So, merging. |
Author
|
Thanks for merging this, @pradeeban, |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Hi @pradeeban , Fixes #339
This PR makes our server action requests much more robust by properly encoding dynamic URL segments and query parameters. It also includes a tiny linting fix to keep the build perfectly green.
What was the problem?
Previously, server action URLs were built using raw string concatenation. This meant that if a user had spaces,
&,?, or newlines in their workflow, folder, or library names, it would result in malformed requests that could break the application.How i fixed it
6-server.js(The core fix):URLSearchParamsto safely build query strings for thebuild(),clear(), andlibrary()actions.encodeURIComponent()across the board (build,debug,run,clear,stop,destroy, andlibrary).fileName(getCurrentGraphName()path) was preserved exactly as is.GraphArea.jsx(Linting cleanup):useEffectreturn path to satisfy theconsistent-returnlint rule (ensuring the cleanup function always returns). There is absolutely no change to runtime behavior here; it just keeps the linter happy!Validation
npm run buildcompletes successfully with these changes.Let me know if you'd like any adjustments
Thanks!