Automattic / Automattic/wp-super-cache

Rejected URL strings case sensitive, created cache directory lowercase

Open
#1,013 1 comment 0 reactions 0 assignees View on GitHub
[Plugin] Super Cache bug
Dominant language
PHP
Stars
436
Forks
130
Avg merge
15h 11m
Merged PRs (30d)
10

Description

### Impacted plugin

Super Cache

### Quick summary

WP Super Cache has "Rejected URL strings" feature, and the description for it is:
Add here strings (not a filename) that forces a page not to be cached. For example, if your URLs include year and you dont want to cache last year posts, it’s enough to specify the year, i.e. ’/2004/’. WP-Cache will search if that string is part of the URI and if so, it will not cache that page.

The problem with this is that it is case sensitive, and created cache directory is lowercased - this makes this feature far less useful (and arguably problematic), because it becomes super easy to bypass it.
For example, adding a string like a "register" in it prevents WPSC from caching domain.com/register/ - however, if someone accesses domain.com/Register/, WPSC will create /register/ cache version.

I think this should be changed to either lowercase all entered reject strings (which makes sense, as WPSC explicitly lowercases created cache directory), or at least changing the description to warn users of this issue.

### Steps to reproduce

1. Enter any lowercase string (example) in Rejected URL strings
2. Visit uppercased version of the string, example: domain.com/EXAMPLE/

domain.com/example/ is now cached, I would not have expected this.

### Site owner impact

More than 60% of the total website/platform users

### Severity

Major

### What other impact(s) does this issue have?

_No response_

### If a workaround is available, please outline it here.

_No response_

### Platform (Simple and/or Atomic)

_No response_

Contributor guide

No contributing guide indexed for this repository

Research direction

No file or test is named. Reproduce the case-sensitive rejection with an uppercase URL, then trace the rejected URL strings handling alongside the lowercase cache-directory creation; done means equivalent URL casing cannot bypass the configured rejection behavior, with the relevant regression coverage updated.

Written by the indexing model from the issue text.

Assessment

Tech stack
php, wordpress
Domain
backend, performance
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.