Skip to content

gh api URL encoding change is incomplete #10628

Description

@digimangos

Describe the bug

The regex for the package name detection

var pathWithPackageNameRE = regexp.MustCompile(`^\/(?:orgs|user|users)(?:\/.*)?\/packages\/(?:npm|maven|rubygems|docker|nuget|container)\/(?<package>.*?)(?:\/(?:restore|versions)|$)`)
hasn't been thought through properly.

Similar to #10592 we had been url escaping the package name which got broken by the change in #10384, removing the escaping also does not work in some cases when the package name contains the words versions or restore.

Now this is problematic because we are unable to use the previously escaped naming (similar to the issue raised in #10592), but we're also unable to parse the name in with or without escaping.

Affected version

2.68.1

Steps to reproduce the behaviour

Assume you have a container named: golden/public/restoreabc or golden/public/versionsabc

  1. Type this gh api "/orgs/myorg/packages/container/golden/public/restoreabc/versions" --verbose
  2. View the output GET /orgs/myorg/packages/container/golden%2Fpublic/restoreabc/versions HTTP/1.1
  3. See error: This is fictitious so won't be found.

There doesn't appear to be a work around for this, because if you escape the slash which isn't correctly escaped, i.e.

  1. Type this gh api "/orgs/myorg/packages/container/golden/public%2Frestoreabc/versions" --verbose
  2. View the output GET /orgs/myorg/packages/container/golden%2Fpublic%252frestoreabc/versions HTTP/1.1

It does escape the %

Expected vs actual behavior

The correct escaped URL should be:

  • /orgs/myorg/packages/container/golden%2Fpublic%2Frestoreabc/versions

So the slash between public/restoreabc is not escaped.

The same problem occurs if you have a package name including the word versions. Presumably the regex should be anchored to the end of the string.

Logs

Not sure this is needed.

Activity

  1. williammartin commented on Mar 18, 2025

    @williammartin
    Member

    Thanks and sorry for this.

    I think I'm going to just revert #10384 for the next release (maybe today?) and then we can figure out how to move forward.

  2. williammartin commented on Mar 18, 2025

    @williammartin
    Member

    Reverted here: #10630

  3. williammartin commented on Mar 19, 2025

    @williammartin
    Member

    Released https://github.com/cli/cli/releases/tag/v2.69.0 which should revert the behaviour to the old way, so I'm going to close this. Please let me know if you experience any more issues.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workinggh-apirelating to the gh api commandneeds-triageneeds to be reviewed

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions