Skip to content

breaking: reject invalid relative routes in goto - #16164

Merged
Rich-Harris merged 7 commits into
version-3from
elliott/goto-reject-invalid-relative-routes
Jun 26, 2026
Merged

breaking: reject invalid relative routes in goto#16164
Rich-Harris merged 7 commits into
version-3from
elliott/goto-reject-invalid-relative-routes

Conversation

@elliott-with-the-longest-name-on-github

@elliott-with-the-longest-name-on-github elliott-with-the-longest-name-on-github commented Jun 24, 2026

Copy link
Copy Markdown
Contributor

closes #14285

goto now errors if you navigate to a route that doesn't exist, even when it's a relative route

This also changes remote functions to use _goto to navigate to redirects so that they don't error for external redirects.

@changeset-bot

changeset-bot Bot commented Jun 24, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: c17f3da

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@sveltejs/kit Major

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@elliott-with-the-longest-name-on-github
elliott-with-the-longest-name-on-github marked this pull request as ready for review June 24, 2026 22:27
@svelte-docs-bot

Copy link
Copy Markdown

@vercel vercel Bot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Additional Suggestion:

Server-issued remote-function redirects to same-origin non-client-route (or external) URLs now fail because the handlers call the public goto, which was changed to reject when the target doesn't resolve to a client route.

Fix on Vercel

@teemingc teemingc linked an issue Jun 25, 2026 that may be closed by this pull request
Comment thread packages/kit/src/runtime/client/client.js Outdated
Co-authored-by: Tee Ming <chewteeming01@gmail.com>
Comment thread packages/kit/types/index.d.ts Outdated
Co-authored-by: vercel[bot] <35613825+vercel[bot]@users.noreply.github.com>
@teemingc

Copy link
Copy Markdown
Member

/autofix

@Rich-Harris
Rich-Harris merged commit f0eab52 into version-3 Jun 26, 2026
28 of 33 checks passed
@Rich-Harris
Rich-Harris deleted the elliott/goto-reject-invalid-relative-routes branch June 26, 2026 01:46
Rich-Harris pushed a commit that referenced this pull request Jun 26, 2026
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to version-3, this PR
will be updated.

⚠️⚠️⚠️⚠️⚠️⚠️

`version-3` is currently in **pre mode** so this branch has prereleases
rather than normal releases. If you want to exit prereleases, run
`changeset pre exit` on `version-3`.

⚠️⚠️⚠️⚠️⚠️⚠️

# Releases
## @sveltejs/adapter-netlify@7.0.0-next.1

### Major Changes


- breaking: require `vite@^8.0.12`, the first Vite 8 release bundling
stable `rolldown` 1.0.0
([#16134](#16134))


### Patch Changes

- Updated dependencies
[[`a9629f1`](a9629f1),
[`53d37f9`](53d37f9),
[`dba6239`](dba6239),
[`ab12cb6`](ab12cb6),
[`f0eab52`](f0eab52),
[`cd884c1`](cd884c1),
[`9ed38a8`](9ed38a8),
[`53aa049`](53aa049),
[`984e57a`](984e57a),
[`51785be`](51785be),
[`4f6bcbb`](4f6bcbb),
[`78e7137`](78e7137)]:
  - @sveltejs/kit@3.0.0-next.5
## @sveltejs/adapter-node@6.0.0-next.1

### Major Changes


- breaking: require `vite@^8.0.12`, the first Vite 8 release bundling
stable `rolldown` 1.0.0
([#16134](#16134))


### Patch Changes

- Updated dependencies
[[`a9629f1`](a9629f1),
[`53d37f9`](53d37f9),
[`dba6239`](dba6239),
[`ab12cb6`](ab12cb6),
[`f0eab52`](f0eab52),
[`cd884c1`](cd884c1),
[`9ed38a8`](9ed38a8),
[`53aa049`](53aa049),
[`984e57a`](984e57a),
[`51785be`](51785be),
[`4f6bcbb`](4f6bcbb),
[`78e7137`](78e7137)]:
  - @sveltejs/kit@3.0.0-next.5
## @sveltejs/adapter-vercel@7.0.0-next.1

### Major Changes


- breaking: require `vite@^8.0.12`, the first Vite 8 release bundling
stable `rolldown` 1.0.0
([#16134](#16134))


### Patch Changes

- Updated dependencies
[[`a9629f1`](a9629f1),
[`53d37f9`](53d37f9),
[`dba6239`](dba6239),
[`ab12cb6`](ab12cb6),
[`f0eab52`](f0eab52),
[`cd884c1`](cd884c1),
[`9ed38a8`](9ed38a8),
[`53aa049`](53aa049),
[`984e57a`](984e57a),
[`51785be`](51785be),
[`4f6bcbb`](4f6bcbb),
[`78e7137`](78e7137)]:
  - @sveltejs/kit@3.0.0-next.5
## @sveltejs/enhanced-img@1.0.0-next.1

### Major Changes


- breaking: require `vite@^8.0.12`, the first Vite 8 release bundling
stable `rolldown` 1.0.0
([#16134](#16134))
## @sveltejs/kit@3.0.0-next.5

### Major Changes


- breaking: remove `base`, `assets`, and `resolveRoute` from
`$app/paths` ([#15507](#15507))


- breaking: require Svelte config options to be passed through the Vite
plugin ([#16007](#16007))


- breaking: `goto` now rejects when called with a URL that does not
resolve to a route within the app, matching the existing behaviour for
external URLs ([#16164](#16164))


- breaking: add 'error' result type to `preloadData`
([#12579](#12579))


- breaking: require `vite@^8.0.12`, the first Vite 8 release bundling
stable `rolldown` 1.0.0
([#16134](#16134))


### Minor Changes


- feat: expose `submitted` property of remote forms
([#14811](#14811))


### Patch Changes


- fix: clear issues and touched states on form reset
([#16163](#16163))


- fix: return 404 for form actions and remote functions whose name is an
`Object.prototype` member
([#16072](#16072))


- feat: send periodic `keep-alive` SSE comments from `query.live` to
prevent idle-timeout errors
([#16063](#16063))


- fix: render pages over sibling endpoints without GET or HEAD handlers
([#16125](#16125))


- fix: sort directory entries when building the route manifest so node
indices are deterministic across runtimes (e.g. Bun and Node)
([#16074](#16074))


- fix: include hoisted packages in Vite's `server.fs.allow` list
([#15998](#15998))
## @sveltejs/package@3.0.0-next.1

### Patch Changes


- fix: declare typescript as an optional peer dependency so
svelte-package works under strict node-linkers
([#16073](#16073))

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

goto should error if called with an external route

3 participants