fix(router): stop double-encoding route variables when URL rewriting is off - #3667
Merged
bpamiri merged 1 commit intoSep 27, 2026
Conversation
…is off With URLRewriting="Off", urlFor() replaces the route pattern with the `?controller=...&action=...&key=...&format=...` query string, so a custom route variable such as `[slug]` is not in the pattern and is appended to `params`. $urlForSubstituteVariables appended the already URL-encoded (and, for linkTo / startFormTag, HTML-attribute-encoded) value, and $constructParams encoded it again: `slug="a b"` became `slug=a%2Bb` (server receives "a+b"), and with HTML encoding the `&` of the `+` entity split the value into garbage params. Append the raw value instead, escaping only the `&` / `=` delimiters that $constructParams splits on, so the value is encoded exactly once. In-pattern substitution (On / Partial) is unchanged. Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_018RdXpVKos1AZ24dM4X8wL1 Signed-off-by: Claude <noreply@anthropic.com>
bpamiri
deleted the
claude/wheels-framework-bug-review-odsc9d-rewrite-off-encoding
branch
September 27, 2026 02:10
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
With
URLRewriting="Off",$urlForSubstituteVariables()replaces the route pattern with?controller=…&action=…&key=…&format=…. So a custom route variable such as[slug]is "not in pattern" and gets appended toparamsinstead. The value appended was the one that had already been URL-encoded, and$constructParamsencodes params again:urlFor(route="post", slug="a b")→slug=a%2Bb, so the server receives"a+b".linkTo,startFormTag), the&inside the encoded entity split the value into junk parameters:slug=a&%23x2b%3Bb=.Fix: the raw value is kept and appended in the not-in-pattern branch, so
$constructParamsencodes it exactly once. When encoding is on, only&and=are escaped (%26,%3D). Those are the delimiters$constructParamssplits on, and escaping them is what theparamsdocs ask for. This keepsslug="a&b"intact. Withencode=falsethe output is unchanged.On/Partialmodes substitute into the path and were never affected.Related Issue
None filed. Found during a framework bug review.
Type of Change
Feature Completeness Checklist
global/urlforSpec.cfc:&and=;$encodeForHtmlAttribute=true, compared againstEncodeForHTMLAttribute("a+b")so it holds on every engine;changelog.d/rewrite-off-route-variable-encoding.fixed.mdTest Plan
I ran the real
$urlForSubstituteVariables(old and new) and$constructParams, extracted verbatim, on Lucee 6.2. The ESAPI encoders were stubbed with Java equivalents."a b"slug=a%2Bbslug=a+b"a b"slug=a&%23x2b%3Bb=slug=a+b/,&,=without HTML encoding🤖 Generated with Claude Code
https://claude.ai/code/session_018RdXpVKos1AZ24dM4X8wL1
Generated by Claude Code