Skip to content

fix: expand escape sequences when resolving a route id to a pathname - #16570

Merged
Rich-Harris merged 2 commits into
sveltejs:version-3from
Nic-Polumeyv:fix-resolve-route-escape-sequences
Jul 30, 2026
Merged

fix: expand escape sequences when resolving a route id to a pathname#16570
Rich-Harris merged 2 commits into
sveltejs:version-3from
Nic-Polumeyv:fix-resolve-route-escape-sequences

Conversation

@Nic-Polumeyv

Copy link
Copy Markdown
Contributor

resolve('/[x+2e]well-known') returns the route id verbatim instead of /.well-known, so a pathname built from an escaped route id does not match the route it came from. parse_route_id has expanded [x+nn] and [u+nnnn] since #7644, but resolve_route never has, because basic_param_pattern cannot match x+2e.

The expansion happens in the same pass as the params rather than a second pass over the result, so a param value that itself contains [x+2f] is left alone.

parse_route_id output is unchanged. Its x+ and u+ branches were already equivalent, since splitting a two character code on - is a no-op.

@pkg-svelte-dev

pkg-svelte-dev Bot commented Jul 29, 2026

Copy link
Copy Markdown

Install the latest version of @sveltejs/kit from e66b61e:

pnpm add https://pkg.svelte.dev/@sveltejs/kit/c/e66b61e6a27004853571d45cdf6a53e2125649cb

Open in pkg.svelte.dev: https://pkg.svelte.dev/repos/kit/pr/16570

Note

This PR is from a fork. A maintainer must approve approve each commit before it can be built and installed.

@changeset-bot

changeset-bot Bot commented Jul 29, 2026

Copy link
Copy Markdown

🦋 Changeset detected

Latest commit: e66b61e

The changes in this PR will be included in the next version bump.

This PR includes changesets to release 1 package
Name Type
@sveltejs/kit Patch

Not sure what this means? Click here to learn what changesets are.

Click here if you're a maintainer who wants to add another changeset to this PR

@Nic-Polumeyv

Copy link
Copy Markdown
Contributor Author

[x+5b] and [x+5d] still don't round-trip after this, because escape() double-escapes them; #16569 fixes that. With both, all 94 printable ASCII escape sequences resolve to a pathname their own pattern matches.

@Rich-Harris Rich-Harris left a comment

Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

thank you!

@Rich-Harris
Rich-Harris merged commit f4222ad into sveltejs:version-3 Jul 30, 2026
21 of 22 checks passed
@Nic-Polumeyv
Nic-Polumeyv deleted the fix-resolve-route-escape-sequences branch July 30, 2026 22:53
Rich-Harris added a commit that referenced this pull request Aug 4, 2026
…ams, several params in one segment, or escape sequences (#16577)

`/[[lang]]/about` generates the `Path` member `{string}/about`, a plain
string rather than a template: #16430 appended `.slice(1)` to a branch
whose replacement had already consumed the leading slash, chopping the
`$`. Since `resolve()` is bounded by `Path`, `resolve('en/about')` is
rejected while `resolve('{string}/about')` type checks.

The pathname is now built from the route's segments. An omitted optional
param contributes its own pathname instead of absorbing the following
`/`, so `xyzabout` is no longer admitted, and a second param in one
segment (`/[foo]-[bar]`) no longer leaks in verbatim.

Rest params get the same treatment, since `[...path]` can match zero
segments. Escape sequences are expanded the same way #16570 expands them
in `resolve`, so `/[x+2e]well-known` contributes `.well-known` rather
than the raw route id.

---------

Co-authored-by: Rich Harris <richard.a.harris@gmail.com>
Co-authored-by: Rich Harris <rich.harris@vercel.com>
Rich-Harris pushed a commit that referenced this pull request Aug 4, 2026
This PR was opened by the [Changesets
release](https://github.com/changesets/action) GitHub action. When
you're ready to do a release, you can merge this and the packages will
be published to npm automatically. If you're not ready to do a release
yet, that's fine, whenever you add more changesets to version-3, this PR
will be updated.

⚠️⚠️⚠️⚠️⚠️⚠️

`version-3` is currently in **pre mode** so this branch has prereleases
rather than normal releases. If you want to exit prereleases, run
`changeset pre exit` on `version-3`.

⚠️⚠️⚠️⚠️⚠️⚠️

# Releases
## @sveltejs/kit@3.0.0-next.14

### Major Changes

- breaking: refresh all load functions/queries when clicking a link to
the current URL ([#16572](#16572))

- breaking: only include routes with a `+page` or `+server` in `RouteId`
([#16580](#16580))

- breaking: require Node 22.17
([#16597](#16597))

- breaking: `preloadCode` now takes a route ID (e.g. `/blog/[slug]`)
instead of a pathname. Route IDs are not prefixed with `paths.base`
([#16576](#16576))

- breaking: remove deprecated `.run()` method from live queries
([#16573](#16573))

### Minor Changes

- feat: return the list of compressed files from `builder.compress`
([#16566](#16566))

- feat: add `page` and `endpoint` booleans to `$app/manifest`'s
`routes`, and export a `ManifestRoute` type
([#16594](#16594))

- feat: add `PageRouteId` and `EndpointRouteId` to `$app/types`
([#16594](#16594))

### Patch Changes

- fix: generate valid `Path` types for routes with optional or rest
params, several params in one segment, or escape sequences
([#16577](#16577))

- fix: decode all numeric character references, including above `ffff`,
when crawling prerendered pages
([#16611](#16611))

- chore: deduplicate request hashing for serialized fetch responses
([#16499](#16499))

- fix: don't treat `Object.prototype` members as param matchers during
validation ([#16612](#16612))

- fix: exclude routes without a page or endpoint from `routes` in
`$app/manifest`, and remove directories with no route files from
`LayoutParams` ([#16588](#16588))

- chore: reuse base64 and text decoding helpers
([#16608](#16608))

- fix: record the mime types of prerendered paths in the server manifest
([#16564](#16564))

- chore: only generate each route's resolution module once when
prerendering ([#16576](#16576))

- fix: expand `[x+nn]` and `[u+nnnn]` escape sequences when resolving a
route id to a pathname
([#16570](#16570))

- fix: allow routes to contain `[` and `]` via the `[x+5b]` and `[x+5d]`
escapes ([#16569](#16569))

- chore: remove the dead `SSRState.fallback` field and name the server
state fork semantics
([#16598](#16598))

- fix: import resolved peer dependencies as file URLs so
project-relative resolution works on Windows
([#16618](#16618))

- fix: write generated tsconfig to `node_modules/$app/tsconfig.json` so
that tools with simplified tsconfig resolution can find it
([#16589](#16589))

- fix: prerender and crawl pages whose `content-type` header carries a
`charset` parameter
([#16567](#16567))

- fix: stream promised `read` results lazily instead of eagerly
buffering them ([#16622](#16622))

- fix: correctly decode `[u+nnnn]` escape sequences above `ffff`
([#16611](#16611))
## @sveltejs/adapter-auto@8.0.0-next.2

### Patch Changes

- fix: convert resolved adapter path to a file URL before importing, so
builds work on Windows
([#16618](#16618))
- Updated dependencies
[[`c3f58bb`](c3f58bb),
[`b655dc7`](b655dc7),
[`a70cc4f`](a70cc4f),
[`b325afb`](b325afb),
[`e76b3d7`](e76b3d7),
[`58f47eb`](58f47eb),
[`fe9d8d9`](fe9d8d9),
[`0c7bbd7`](0c7bbd7),
[`08d7e2a`](08d7e2a),
[`f70f679`](f70f679),
[`0624b26`](0624b26),
[`0624b26`](0624b26),
[`f4222ad`](f4222ad),
[`089628b`](089628b),
[`d8617b3`](d8617b3),
[`c7369a1`](c7369a1),
[`5e5e592`](5e5e592),
[`60057c1`](60057c1),
[`f70f679`](f70f679),
[`38f1528`](38f1528),
[`40092f3`](40092f3),
[`ff4247e`](ff4247e),
[`79a5de5`](79a5de5),
[`a70cc4f`](a70cc4f)]:
  - @sveltejs/kit@3.0.0-next.14
## @sveltejs/adapter-cloudflare@8.0.0-next.4

### Patch Changes

- fix: avoid caching immutable asset 404s
([#16627](#16627))
- Updated dependencies
[[`c3f58bb`](c3f58bb),
[`b655dc7`](b655dc7),
[`a70cc4f`](a70cc4f),
[`b325afb`](b325afb),
[`e76b3d7`](e76b3d7),
[`58f47eb`](58f47eb),
[`fe9d8d9`](fe9d8d9),
[`0c7bbd7`](0c7bbd7),
[`08d7e2a`](08d7e2a),
[`f70f679`](f70f679),
[`0624b26`](0624b26),
[`0624b26`](0624b26),
[`f4222ad`](f4222ad),
[`089628b`](089628b),
[`d8617b3`](d8617b3),
[`c7369a1`](c7369a1),
[`5e5e592`](5e5e592),
[`60057c1`](60057c1),
[`f70f679`](f70f679),
[`38f1528`](38f1528),
[`40092f3`](40092f3),
[`ff4247e`](ff4247e),
[`79a5de5`](79a5de5),
[`a70cc4f`](a70cc4f)]:
  - @sveltejs/kit@3.0.0-next.14
## @sveltejs/adapter-node@6.0.0-next.7

### Patch Changes

- fix: serve static files with the Content-Type recorded in the manifest
([#16564](#16564))

- fix: don't send `Vary: Accept-Encoding` for assets that were never
precompressed ([#16566](#16566))
- Updated dependencies
[[`c3f58bb`](c3f58bb),
[`b655dc7`](b655dc7),
[`a70cc4f`](a70cc4f),
[`b325afb`](b325afb),
[`e76b3d7`](e76b3d7),
[`58f47eb`](58f47eb),
[`fe9d8d9`](fe9d8d9),
[`0c7bbd7`](0c7bbd7),
[`08d7e2a`](08d7e2a),
[`f70f679`](f70f679),
[`0624b26`](0624b26),
[`0624b26`](0624b26),
[`f4222ad`](f4222ad),
[`089628b`](089628b),
[`d8617b3`](d8617b3),
[`c7369a1`](c7369a1),
[`5e5e592`](5e5e592),
[`60057c1`](60057c1),
[`f70f679`](f70f679),
[`38f1528`](38f1528),
[`40092f3`](40092f3),
[`ff4247e`](ff4247e),
[`79a5de5`](79a5de5),
[`a70cc4f`](a70cc4f)]:
  - @sveltejs/kit@3.0.0-next.14
## @sveltejs/adapter-static@4.0.0-next.3

### Patch Changes

- fix: avoid caching immutable asset 404s when configuring for Vercel
([#16626](#16626))
- Updated dependencies
[[`c3f58bb`](c3f58bb),
[`b655dc7`](b655dc7),
[`a70cc4f`](a70cc4f),
[`b325afb`](b325afb),
[`e76b3d7`](e76b3d7),
[`58f47eb`](58f47eb),
[`fe9d8d9`](fe9d8d9),
[`0c7bbd7`](0c7bbd7),
[`08d7e2a`](08d7e2a),
[`f70f679`](f70f679),
[`0624b26`](0624b26),
[`0624b26`](0624b26),
[`f4222ad`](f4222ad),
[`089628b`](089628b),
[`d8617b3`](d8617b3),
[`c7369a1`](c7369a1),
[`5e5e592`](5e5e592),
[`60057c1`](60057c1),
[`f70f679`](f70f679),
[`38f1528`](38f1528),
[`40092f3`](40092f3),
[`ff4247e`](ff4247e),
[`79a5de5`](79a5de5),
[`a70cc4f`](a70cc4f)]:
  - @sveltejs/kit@3.0.0-next.14
## @sveltejs/enhanced-img@1.0.0-next.3

### Patch Changes

- chore: bump `vite-imagetools` to v11
([#16630](#16630))
## @sveltejs/package@3.0.0-next.4

### Patch Changes

- chore: remove dependency on sade
([#16619](#16619))

- fix: import resolved peer dependencies as file URLs so
project-relative resolution works on Windows
([#16618](#16618))

- fix: emit declarations when the tsconfig lives above the package root
([#16568](#16568))

Co-authored-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants