Skip to content

fix: encode the paybutton id used in its detail fetch - #1136

Open
Klakurka wants to merge 4 commits into
masterfrom
cursor/fix-paybutton-fetch-url-2e84
Open

Klakurka wants to merge 4 commits into
masterfrom
cursor/fix-paybutton-fetch-url-2e84

Conversation

@Klakurka

@Klakurka Klakurka commented Oct 1, 2026 •

Copy link
Copy Markdown
Member

Related to https://github.com/PayButton/paybutton-server/security/code-scanning/3
Related to https://github.com/PayButton/paybutton-server/security/code-scanning/6
Related to https://github.com/PayButton/paybutton-server/security/code-scanning/7
Related to https://github.com/PayButton/paybutton-server/security/code-scanning/8

Description

CodeQL js/request-forgery flagged the button detail page. getServerSideProps passed the route id into a client fetch URL. A route id containing path characters could change which same-origin path was requested.

The id is normalized to a string and passed through encodeURIComponent, so it stays one path segment. A normal UUID is unchanged.

The GitHub token for this run cannot read code-scanning alert bodies, so this is one of the fixes from a local CodeQL code-scanning run of the same default query suite.

Test plan

  • Re-ran CodeQL js/request-forgery against the page; the finding is gone.
  • Valid paybutton ids are not modified by encodeURIComponent (hyphens are left as-is).
Open in Web Open in Cursor 

The button page built a fetch URL from the route id. Encoding that id keeps
it a single path segment, so a crafted id cannot change the request target.

Co-authored-by: David <Klakurka@users.noreply.github.com>
@coderabbitai

coderabbitai Bot commented Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Warning

Review limit reached

You've used all free OSS reviews for now. Wait for the free limit to reset to keep reviewing this public repository.

Next included review available in 13 minutes.

Check out review usage here.

View limit details

Limit details: You’ve used the included review currently available.

Learn how review limits work.

Review configuration:

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 1cbfc1d6-047f-4b11-81c4-c3451a57aa0d

📥 Commits

Reviewing files that changed from the base of the PR and between 0ee5fc3 and 332330a.

📒 Files selected for processing (1)
  • pages/button/[id].tsx
  • Autopilot · Keep fixing CodeRabbit findings and required CI, and resolving merge conflicts

Autopilot is currently an internal CodeRabbit preview.


Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@Klakurka
Klakurka marked this pull request as ready for review October 1, 2026 17:08
@Klakurka Klakurka self-assigned this Oct 1, 2026
@Klakurka Klakurka added the bug Something isn't working label Oct 1, 2026
@Klakurka Klakurka added this to the Phase 3 milestone Oct 1, 2026
@Klakurka
Klakurka requested a balanced review from Copilot October 1, 2026 17:14

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The empty-ID fallback can route authentication-error requests to an API handler that never responds to GET requests.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Encodes paybutton route IDs before API detail requests to prevent path manipulation.

Changes:

  • Normalizes the route parameter to a string.
  • Applies encodeURIComponent before fetching paybutton details.
File Description
pages/​button/​[id].tsx Normalizes and encodes the paybutton ID used in API requests.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread pages/button/[id].tsx Outdated

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug Something isn't working

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants