fix(telegram): skip malformed percent escapes in initData instead of throwing (late, carries #15108) - #15121
Merged
Conversation
…throwing parseInitData called decodeURIComponent on every field with no guard, and verifyInitData called it with no try/catch. A Mini App request carrying a field like user=%ZZ raised a URIError that the route did not catch, so the caller got a 500 instead of the 401 a bad signature already returns. Skip the bad pair and let the signature check fail. Signed-off-by: Minxi Hou <houminxi@gmail.com> (cherry picked from commit edbe964)
5 of 6 tasks
diegosouzapw
added a commit
that referenced
this pull request
Sep 29, 2026
…d release date - Every one of the 1972 cycle commits is covered by a bullet (reconcile-changelog vs origin/release/v3.8.50); fragments folded under [3.8.51] with the PR link and the author of the commit that added them. - Re-land credit: #15019/#15020/#15119/#15120/#15121 credit @HouMinXi; #12383 credits its author @kareem-jalal alongside the original credit. - Contributors hall regenerated (301 external contributors). - [3.8.51] dated 2026-09-29 in the root CHANGELOG and the 66 i18n mirrors.
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Carries #15108 into release/v3.8.51. #15108 targets release/v3.8.52 and its head contains the .52 bump, so this cherry-picks (
-x, authorship preserved) only its own commit. A Mini App initData field such asuser=%ZZraised an uncaught URIError (500); the malformed pair is now skipped and the signature check returns 401. Both the verifier andextractInitDataUserIduse the same parser, so no field can be read that was not signed.Evidence on tip 4796624: the new
telegram-init-datacase fails on the tip and passes with the fix (8/8); telegram route/botapi/webhook suites green; typecheck:core, eslint (suppression for the removed unused import dropped) and check-file-size clean.Co-authored-by: Minxi Hou houminxi@gmail.com