aboutcode-org / aboutcode-org/purldb

Public purldb API appears to ignore subpaths when submitted as part of a URL

オープン
#536 コメント 2 件 リアクション 0 件 担当者 0 名 GitHub で見る
bug documentation
主要言語
HTML
スター
67
フォーク
69
平均マージ
8日 8時間
マージ済み PR(30日)
1

説明

It looks like the public purldDB API responds to the inclusion of a `#` subpath separator followed by the subpath value by ignoring the subpath. An example: in the public API, `https://public.purldb.io/api/packages/?purl=pkg:maven/org.elasticsearch/elasticsearch@7.17.9#fake/subpath` returns the same 2 records returned by `https://public.purldb.io/api/packages/?purl=pkg:maven/org.elasticsearch/elasticsearch@7.17.9` -- the only difference is the presence or absence of `#fake/subpath`.

I understand that this might be an encoding issue, but note that according to the [purl specification](https://github.com/package-url/purl-spec/blob/master/PURL-SPECIFICATION.rst#character-encoding), "the '#', '?', '@' and ':' characters must NOT be encoded when used as separators. They may need to be encoded elsewhere" and a bullet further below: "the '#' subpath separator must be encoded as %23 elsewhere". Perhaps the documentation needs to be clarified?

コントリビューションガイド

このリポジトリのコントリビューションガイドは索引されていません

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。