MM-11895: Don't crush user-provided GET parameters on slash command URLs (#9372)
Этот коммит содержится в:
коммит произвёл
Jesse Hallam
родитель
14928ceb74
Коммит
d585f9d9a3
@@ -491,6 +491,7 @@ func TestExecuteGetCommand(t *testing.T) {
|
||||
|
||||
require.Equal(t, token, values.Get("token"))
|
||||
require.Equal(t, th.BasicTeam.Name, values.Get("team_domain"))
|
||||
require.Equal(t, "ourCommand", values.Get("cmd"))
|
||||
|
||||
w.Header().Set("Content-Type", "application/json")
|
||||
w.Write([]byte(expectedCommandResponse.ToJson()))
|
||||
@@ -500,7 +501,7 @@ func TestExecuteGetCommand(t *testing.T) {
|
||||
getCmd := &model.Command{
|
||||
CreatorId: th.BasicUser.Id,
|
||||
TeamId: th.BasicTeam.Id,
|
||||
URL: ts.URL,
|
||||
URL: ts.URL + "/?cmd=ourCommand",
|
||||
Method: model.COMMAND_METHOD_GET,
|
||||
Trigger: "getcommand",
|
||||
Token: token,
|
||||
|
||||
@@ -233,7 +233,11 @@ func (a *App) ExecuteCommand(args *model.CommandArgs) (*model.CommandResponse, *
|
||||
var req *http.Request
|
||||
if cmd.Method == model.COMMAND_METHOD_GET {
|
||||
req, _ = http.NewRequest(http.MethodGet, cmd.URL, nil)
|
||||
req.URL.RawQuery = p.Encode()
|
||||
|
||||
if req.URL.RawQuery != "" {
|
||||
req.URL.RawQuery += "&"
|
||||
}
|
||||
req.URL.RawQuery += p.Encode()
|
||||
} else {
|
||||
req, _ = http.NewRequest(http.MethodPost, cmd.URL, strings.NewReader(p.Encode()))
|
||||
}
|
||||
|
||||
Ссылка в новой задаче
Block a user