refactor(pwa): make stalker cmd append visibly query-only for CodeQL

Rebuild the /stalker request URL through the URL object and concatenate
the encoded cmd strictly behind a literal '?', so static analysis can
see the tainted value never reaches host or path (js/request-forgery
alert on the previous separator ternary). Behavior unchanged; the
fragment/bare-'?' regression tests still pin the wire format.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
This commit is contained in:
4grayandClaude Fable 5 committed 2026-08-01 23:34:53 +02:00
1 parent e0617e1642
commit b16ede9fbe
1 file changed
+13 -9
+13 -9
View File
@@ -239,15 +239,19 @@ export function createWebBackendApp(
const { cmd, ...proxyParams } = getProxyParams(req, ['targetId']);
const portalUrl = new URL(url.href);
portalUrl.hash = '';
let requestUrl = portalUrl.href;
if (cmd) {
const separator = requestUrl.endsWith('?')
? ''
: portalUrl.search
? '&'
: '?';
requestUrl = `${requestUrl}${separator}cmd=${encodeStalkerCmdValue(cmd)}`;
}
const registeredQuery = portalUrl.search.replace(/^\?/, '');
portalUrl.search = '';
const query = [
registeredQuery,
cmd ? `cmd=${encodeStalkerCmdValue(cmd)}` : '',
]
.filter(Boolean)
.join('&');
// cmd is appended strictly behind the literal `?`, so it can only
// ever form query content — never host or path.
const requestUrl = query
? `${portalUrl.href}?${query}`
: portalUrl.href;
// Provider URLs are validated by /provider-targets before they enter the registry.
// codeql[js/request-forgery]