Skip to content

fix(router): reject non-hex characters in uuid matcher - #144

Open
andrewstellman wants to merge 1 commit into
adonisjs:9.xfrom
andrewstellman:uuid-matcher-hex
Open

andrewstellman wants to merge 1 commit into
adonisjs:9.xfrom
andrewstellman:uuid-matcher-hex

Conversation

@andrewstellman

Copy link
Copy Markdown

Problem

router.matchers.uuid() accepts any lowercase letter, not just a-f, so GET /posts/gggggggg-gggg-gggg-gggg-gggggggggggg reaches a route guarded with .where('id', router.matchers.uuid()). The character class in src/router/matchers.ts is [0-9a-zA-F]; #50 asked for [0-9A-Fa-f] and #53 landed a-z for the lowercase half.

Fix

Use [0-9a-fA-F]. Valid UUIDs in either case still match.

Testing

  • npm run quick:test (661 passed)
  • npm run typecheck
  • npx eslint and prettier --check on the changed files

Found by Quality Playbook, an AI code-review tool, with Claude; I reviewed the change.

The uuid matcher used the character class [0-9a-zA-F], so any letter
a-z (e.g. "zzzzzzzz-zzzz-zzzz-zzzz-zzzzzzzzzzzz") passed as a UUID.
Use [0-9a-fA-F] so only hexadecimal digits are accepted.
@andrewstellman
andrewstellman marked this pull request as ready for review October 1, 2026 03:19

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant