Describe the bug
The regex for the package name detection
|
var pathWithPackageNameRE = regexp.MustCompile(`^\/(?:orgs|user|users)(?:\/.*)?\/packages\/(?:npm|maven|rubygems|docker|nuget|container)\/(?<package>.*?)(?:\/(?:restore|versions)|$)`) |
hasn't been thought through properly.
Similar to #10592 we had been url escaping the package name which got broken by the change in #10384, removing the escaping also does not work in some cases when the package name contains the words versions or restore.
Now this is problematic because we are unable to use the previously escaped naming (similar to the issue raised in #10592), but we're also unable to parse the name in with or without escaping.
Affected version
2.68.1
Steps to reproduce the behaviour
Assume you have a container named: golden/public/restoreabc or golden/public/versionsabc
- Type this
gh api "/orgs/myorg/packages/container/golden/public/restoreabc/versions" --verbose
- View the output
GET /orgs/myorg/packages/container/golden%2Fpublic/restoreabc/versions HTTP/1.1
- See error: This is fictitious so won't be found.
There doesn't appear to be a work around for this, because if you escape the slash which isn't correctly escaped, i.e.
- Type this
gh api "/orgs/myorg/packages/container/golden/public%2Frestoreabc/versions" --verbose
- View the output
GET /orgs/myorg/packages/container/golden%2Fpublic%252frestoreabc/versions HTTP/1.1
It does escape the %
Expected vs actual behavior
The correct escaped URL should be:
/orgs/myorg/packages/container/golden%2Fpublic%2Frestoreabc/versions
So the slash between public/restoreabc is not escaped.
The same problem occurs if you have a package name including the word versions. Presumably the regex should be anchored to the end of the string.
Logs
Not sure this is needed.
Describe the bug
The regex for the package name detection
cli/pkg/cmd/api/api.go
Line 718 in 234d2ef
Similar to #10592 we had been url escaping the package name which got broken by the change in #10384, removing the escaping also does not work in some cases when the package name contains the words
versionsorrestore.Now this is problematic because we are unable to use the previously escaped naming (similar to the issue raised in #10592), but we're also unable to parse the name in with or without escaping.
Affected version
2.68.1
Steps to reproduce the behaviour
Assume you have a container named:
golden/public/restoreabcorgolden/public/versionsabcgh api "/orgs/myorg/packages/container/golden/public/restoreabc/versions" --verboseGET /orgs/myorg/packages/container/golden%2Fpublic/restoreabc/versions HTTP/1.1There doesn't appear to be a work around for this, because if you escape the slash which isn't correctly escaped, i.e.
gh api "/orgs/myorg/packages/container/golden/public%2Frestoreabc/versions" --verboseGET /orgs/myorg/packages/container/golden%2Fpublic%252frestoreabc/versions HTTP/1.1It does escape the
%Expected vs actual behavior
The correct escaped URL should be:
/orgs/myorg/packages/container/golden%2Fpublic%2Frestoreabc/versionsSo the slash between
public/restoreabcis not escaped.The same problem occurs if you have a package name including the word
versions. Presumably the regex should be anchored to the end of the string.Logs
Not sure this is needed.