Skip to content

URL parser does not validate ipv4 with more than 4 parts #42914

Description

@anonrig

Version

v18.0.0

Platform

Darwin Yagizs-MBP 21.4.0 Darwin Kernel Version 21.4.0: Fri Mar 18 00:46:32 PDT 2022; root:xnu-8020.101.4~15/RELEASE_ARM64_T6000 arm64

Subsystem

No response

What steps will reproduce the bug?

This works well

Welcome to Node.js v18.0.0.
Type ".help" for more information.
> new URL('http://256.256.256.256')
Uncaught TypeError [ERR_INVALID_URL]: Invalid URL
    at __node_internal_captureLargerStackTrace (node:internal/errors:465:5)
    at new NodeError (node:internal/errors:372:5)
    at URL.onParseError (node:internal/url:563:9)
    at new URL (node:internal/url:643:5) {
  input: 'http://256.256.256.256',
  code: 'ERR_INVALID_URL'
}

but this does not throw an error:

> new URL('https://256.256.256.256.256.256.256')
URL {
  href: 'https://256.256.256.256.256.256.256/',
  origin: 'https://256.256.256.256.256.256.256',
  protocol: 'https:',
  username: '',
  password: '',
  host: '256.256.256.256.256.256.256',
  hostname: '256.256.256.256.256.256.256',
  port: '',
  pathname: '/',
  search: '',
  searchParams: URLSearchParams {},
  hash: ''
}

How often does it reproduce? Is there a required condition?

URL specification states that if the parts size is greater than 4, validation error should occur and return failure. Look at https://url.spec.whatwg.org/#concept-ipv4-parser

What is the expected behavior?

It should throw error

What do you see instead?

It continues to parse the input

Additional information

No response

Activity

  1. Trott commented on Apr 29, 2022

    @Trott
    Member

    new URL('https://256.256.256.256.256.256.256') throws in Chrome but works in Firefox similar to Node.js. I wonder if only one or the other is spec compliant or if they are both allowable. @nodejs/url

  2. Trott commented on Apr 29, 2022

    @Trott
    Member

    new URL('https://256.256.256.256.256.256.256') throws in Chrome but works in Firefox similar to Node.js. I wonder if only one or the other is spec compliant or if they are both allowable. @nodejs/url

    Sure looks to me like Firefox and Node.js do the wrong thing here and the issue is valid.

  3. anonrig commented on Apr 29, 2022

    @anonrig
    MemberAuthor

    I've opened another issue to update the tests for the whatwg-url, since we're using a pretty old test suite. #42920

  4. added
    urlIssues and PRs related to the legacy built-in url module.
    on Apr 30, 2022
  5. added a commit that references this issue on May 1, 2022
  6. added a commit that references this issue on Jun 11, 2022
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    urlIssues and PRs related to the legacy built-in url module.

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions