Skip to content

fix(telegram): skip malformed percent escapes in initData instead of throwing - #15108

Open
HouMinXi wants to merge 1 commit into
diegosouzapw:release/v3.8.52from
HouMinXi:fix/telegram-initdata-decode
Open

HouMinXi wants to merge 1 commit into
diegosouzapw:release/v3.8.52from
HouMinXi:fix/telegram-initdata-decode

Conversation

@HouMinXi

Copy link
Copy Markdown
Contributor

Summary

parseInitData called decodeURIComponent on every field with no guard, and verifyInitData called it with no try/catch. A Mini App request carrying a field like user=%ZZ raised a URIError that the route did not catch, so the caller got a 500 instead of the 401 a bad signature already returns. Skip the bad pair and let the signature check fail.

Related Issues

  • None.

Validation

  • Change type: bug fix
  • Focused tests: tests/unit/telegram-init-data.test.ts
  • npm run typecheck:core
  • Prettier and ESLint clean on the changed files
  • Reconciled with the current active release base (release/v3.8.52 at 666ea59b4c)
  • Production-code changes include a new or updated automated test in this PR

The new test was run against the change reverted (it throws) and restored (it passes).

Tests Added Or Updated

  • tests/unit/telegram-init-data.test.ts

Coverage Notes

The new test covers the malformed-percent path in both parseInitData (the bad pair is dropped, the good pairs survive) and verifyInitData (returns false instead of throwing).

Reviewer Notes

A malformed pair is skipped, not rejected wholesale. The remaining fields still go through the HMAC check, which fails because the data-check string no longer matches what was signed. The caller sees the same 401 as any other bad signature.

…throwing

parseInitData called decodeURIComponent on every field with no guard, and
verifyInitData called it with no try/catch. A Mini App request carrying a
field like user=%ZZ raised a URIError that the route did not catch, so the
caller got a 500 instead of the 401 a bad signature already returns. Skip the
bad pair and let the signature check fail.

Signed-off-by: Minxi Hou <houminxi@gmail.com>
@diegosouzapw

Copy link
Copy Markdown
Owner

Thanks @HouMinXi! This fix landed in the frozen release/v3.8.51 via #15121 (your commit cherry-picked with authorship preserved, red->green proven on the tip). I'm leaving this PR open on release/v3.8.52: the change reaches .52 through the post-release sync-back, so it can be closed once that lands.

diegosouzapw added a commit that referenced this pull request Sep 29, 2026
…throwing (#15121)

Carries #15108 into release/v3.8.51 (cherry-picked, red->green proven on the tip). Thanks @HouMinXi!

Co-authored-by: Minxi Hou <houminxi@gmail.com>
@diegosouzapw diegosouzapw mentioned this pull request Sep 29, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants