aboutcode-org / aboutcode-org/purldb

Public purldb API appears to ignore subpaths when submitted as part of a URL

Ouverte
#536 2 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
bug documentation
Langage dominant
HTML
Étoiles
67
Forks
69
Merge moyen
8 j 8 h
PR mergées (30 j)
1

Description

It looks like the public purldDB API responds to the inclusion of a `#` subpath separator followed by the subpath value by ignoring the subpath. An example: in the public API, `https://public.purldb.io/api/packages/?purl=pkg:maven/org.elasticsearch/elasticsearch@7.17.9#fake/subpath` returns the same 2 records returned by `https://public.purldb.io/api/packages/?purl=pkg:maven/org.elasticsearch/elasticsearch@7.17.9` -- the only difference is the presence or absence of `#fake/subpath`.

I understand that this might be an encoding issue, but note that according to the [purl specification](https://github.com/package-url/purl-spec/blob/master/PURL-SPECIFICATION.rst#character-encoding), "the '#', '?', '@' and ':' characters must NOT be encoded when used as separators. They may need to be encoded elsewhere" and a bullet further below: "the '#' subpath separator must be encoded as %23 elsewhere". Perhaps the documentation needs to be clarified?

Guide de contribution

Aucun guide de contribution indexé pour ce dépôt

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.