From b16ede9fbe8250b392974fcd559c331b952e3afe Mon Sep 17 00:00:00 2001 From: 4gray Date: Sat, 1 Aug 2026 23:34:53 +0200 Subject: [PATCH] refactor(pwa): make stalker cmd append visibly query-only for CodeQL Rebuild the /stalker request URL through the URL object and concatenate the encoded cmd strictly behind a literal '?', so static analysis can see the tainted value never reaches host or path (js/request-forgery alert on the previous separator ternary). Behavior unchanged; the fragment/bare-'?' regression tests still pin the wire format. Co-Authored-By: Claude Fable 5 --- apps/web-backend/src/app/web-backend-app.ts | 22 ++++++++++++--------- 1 file changed, 13 insertions(+), 9 deletions(-) diff --git a/apps/web-backend/src/app/web-backend-app.ts b/apps/web-backend/src/app/web-backend-app.ts index 7099c9314..3acaf836e 100644 --- a/apps/web-backend/src/app/web-backend-app.ts +++ b/apps/web-backend/src/app/web-backend-app.ts @@ -239,15 +239,19 @@ export function createWebBackendApp( const { cmd, ...proxyParams } = getProxyParams(req, ['targetId']); const portalUrl = new URL(url.href); portalUrl.hash = ''; - let requestUrl = portalUrl.href; - if (cmd) { - const separator = requestUrl.endsWith('?') - ? '' - : portalUrl.search - ? '&' - : '?'; - requestUrl = `${requestUrl}${separator}cmd=${encodeStalkerCmdValue(cmd)}`; - } + const registeredQuery = portalUrl.search.replace(/^\?/, ''); + portalUrl.search = ''; + const query = [ + registeredQuery, + cmd ? `cmd=${encodeStalkerCmdValue(cmd)}` : '', + ] + .filter(Boolean) + .join('&'); + // cmd is appended strictly behind the literal `?`, so it can only + // ever form query content — never host or path. + const requestUrl = query + ? `${portalUrl.href}?${query}` + : portalUrl.href; // Provider URLs are validated by /provider-targets before they enter the registry. // codeql[js/request-forgery]