adnanhemani opened a new pull request, #1604:
URL: https://github.com/apache/polaris/pull/1604

   <!--
       Possible security vulnerabilities: STOP here and contact 
secur...@apache.org instead!
   
       Please update the title of the PR with a meaningful message - do not 
leave it "empty" or "generated"
       Please update this summary field:
   
       The summary should cover these topics, if applicable:
       * the motivation for the change
       * a description of the status quo, for example the current behavior
       * the desired behavior
       * etc
   
       PR checklist:
       - Do a self-review of your code before opening a pull request
       - Make sure that there's good test coverage for the changes included in 
this PR
       - Run tests locally before pushing a PR (./gradlew check)
       - Code should have comments where applicable. Particularly 
hard-to-understand
         areas deserve good in-line documentation.
       - Include changes and enhancements to the documentation (in 
site/content/in-dev/unreleased)
       - For Work In Progress Pull Requests, please use the Draft PR feature.
   
       Make sure to add the information BELOW this comment.
       Everything in this comment will NOT be added to the PR description.
   -->
   
   This is a retry at #1586, which I'll close if this PR is on the right 
direction instead. 
   
   Java URI does not actually apply any normalization to URIs if we do not call 
`URI.normalize()` (which we currently do not). Additionally, blob storage 
providers like S3 and GCS can provide ".." and "." as valid fragments in URLs - 
which Java URI would attempt to normalize incorrectly. As a result, attempting 
to validate and/or normalize URIs for blob storage providers is the incorrect 
behavior. While we may want to add location validation via regex later, 
removing it first should at least unblock the bug we see in #1545.
   


-- 
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.

To unsubscribe, e-mail: issues-unsubscr...@polaris.apache.org

For queries about this service, please contact Infrastructure at:
us...@infra.apache.org

Reply via email to