Skip to content

Encode IDs in Legacy client request paths - #408

Merged
anubhav-intercom merged 1 commit into
masterfrom
legacy-encode-path-segments
Oct 7, 2026
Merged

anubhav-intercom merged 1 commit into
masterfrom
legacy-encode-path-segments

Conversation

@anubhav-intercom

Copy link
Copy Markdown
Contributor

Why?

The Legacy client puts IDs into request paths without encoding them. An ID containing /, ? or # changes which URL is requested, and . or .. are treated as relative path segments.

How?

Each ID is now encoded as a single path segment, and an empty, . or .. ID is rejected with an error. Only the hand-written Legacy client changes.

Local test run

phpunit couldn't run locally (no Packagist access). A standalone script calling all 13 changed path helpers passes on this branch and fails on master, and php -l is clean on PHP 8.1.

Generated with Claude Code

Route caller-supplied IDs through a helper that percent-encodes the
value and rejects empty, "." and ".." so each ID stays a single path
segment.

Co-Authored-By: Claude Opus 5.5 (1M context) <noreply@anthropic.com>
@anubhav-intercom
anubhav-intercom merged commit b7be9f3 into master Oct 7, 2026
3 checks passed
@anubhav-intercom
anubhav-intercom deleted the legacy-encode-path-segments branch October 7, 2026 10:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants