Le 26/11/2019 à 12:56, William Dauchy a écrit :
we were decoding all substring and then parsing; this could lead to
consider & and = in decoding result as delimiters where it should not.
this patch reverses the order by first parsing and then decoding each key
and value separately.
we also stop parsing after number sign (#).
This patch should be backported to 2.0
It was merged. I amended your patch to fix 2 issues. The fixes were minor, so I
preferred to not bother you with that. First, when the scope value is tested, we
must first be sure it is defined to not dereference a null pointer. For
instance, the URI "/metric?scope" throws an error now. The second issue was
about the detection of the number sign (#).