cloudinary / cloudinary/cloudinary_gem
Transformation params not properly URL escaped
- Vorherrschende Sprache
- Ruby
- Sterne
- 420
- Forks
- 285
- PR-Merge-Kennzahlen
- Keine gemergten PRs in 30 T.
Beschreibung
## Bug report for Cloudinary Ruby SDK
Before proceeding, please update to latest version and test if the issue persists - DONE
## Describe the bug in a sentence or two.
If the parameters passed to transformation contain a double quote, they are not properly escaped when formulating cloudinary URL, causing invalid URL to be generated
## Issue Type (Can be multiple)
- [ ] Build - Cannot install or import the SDK
- [ ] Performance - Performance issues
- [x] Behaviour - Functions are not working as expected (such as generate URL)
- [ ] Documentation - Inconsistency between the docs and behaviour
- [ ] Other (Specify)
## Steps to reproduce
Run
`Cloudinary::Utils.cloudinary_url(VIDEO_ID_HERE,{ resource_type: "video", transformation: [{color: '"abc', overlay: { font_family: "Times", font_size: 12, font_weight: "bold", text: "..." }}])`
note the '"abc' for the color
## Error screenshots or Stack Trace (if applicable)
## Operating System
- [ ] Linux
- [ ] Windows
- [x] macOS
- [ ] All
## Environment and Libraries (fill in the version numbers)
- Cloudinary Ruby SDK version - cloudinary (1.29.0)
- Ruby Version - ruby 3.3.0
- Rails Version - Rails 7.1.3.2
Beitragsleitfaden
Rechercherichtung
Beginnen Sie bei Cloudinary::Utils.cloudinary_url und reproduzieren Sie das Problem mit den gezeigten Transformationsparametern, insbesondere mit dem Farbwert, der ein doppeltes Anführungszeichen enthält. Verfolgen Sie, wie die URL formuliert wird, und überprüfen Sie, dass die resultierende URL das Anführungszeichen ordnungsgemäß maskiert und gültig ist.
Vom Indexierungsmodell aus dem Issue-Text verfasst.
Bewertung
- Tech-Stack
- ruby
- Bereich
- backend
- Issue-Typ
- Bug
- Schwierigkeit
- 3/5
- Geschätzter Aufwand
- 1-2 Tage
- Aktivitätsstatus
- Veraltet
- Klarheit
- Größtenteils klar
- Anfängerfreundlichkeit
- 45/100