Repository navigation
Conversation
The button page built a fetch URL from the route id. Encoding that id keeps it a single path segment, so a crafted id cannot change the request target. Co-authored-by: David <Klakurka@users.noreply.github.com>
|
Warning Review limit reachedYou've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository. Next included review available in 13 minutes. View limit detailsLimit details: You’ve used the included review currently available. Review configuration: ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: 📒 Files selected for processing (1)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The empty-ID fallback can route authentication-error requests to an API handler that never responds to GET requests.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Encodes paybutton route IDs before API detail requests to prevent path manipulation.
Changes:
- Normalizes the route parameter to a string.
- Applies
encodeURIComponentbefore fetching paybutton details.
| File | Description |
|---|---|
pages/button/[id].tsx |
Normalizes and encodes the paybutton ID used in API requests. |
💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.
… hanging GET request' Co-authored-by: Copilot Autofix powered by AI <175728472+Copilot@users.noreply.github.com>

Related to https://github.com/PayButton/paybutton-server/security/code-scanning/3
Related to https://github.com/PayButton/paybutton-server/security/code-scanning/6
Related to https://github.com/PayButton/paybutton-server/security/code-scanning/7
Related to https://github.com/PayButton/paybutton-server/security/code-scanning/8
Description
CodeQL
js/request-forgeryflagged the button detail page.getServerSidePropspassed the route id into a clientfetchURL. A route id containing path characters could change which same-origin path was requested.The id is normalized to a string and passed through
encodeURIComponent, so it stays one path segment. A normal UUID is unchanged.The GitHub token for this run cannot read code-scanning alert bodies, so this is one of the fixes from a local CodeQL code-scanning run of the same default query suite.
Test plan
js/request-forgeryagainst the page; the finding is gone.encodeURIComponent(hyphens are left as-is).