Conversation
…ity (CVE-2026-45822) query-string@7 depends on decode-uri-component@0.2.2, which is vulnerable to a DoS (GHSA-vcc3-ghjq-m6fr). query-string@8+ is ESM-only and cannot be used by the ra-core CJS build, so replace it with an internal helper that reproduces the query-string@7 default output. Packages outside ra-core use the existing fetchUtils.queryParameters to stay compatible with older ra-core 5.x peers. Fixes marmelab#11380 Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
I'm a bit uncomfortable replacing this dep with a custom solution. We'll probably need more tests to check corner cases. Also, if we're heading in this direction, why not use the latest version of query-string as a base instead of v7? |
|
Thanks for the review! I started from v7 because query-string v8+ and decode-uri-component 0.4+ are ESM-only, so ra-core's CJS build can't require them directly. But I agree that hand-written parsing code is riskier than proven code. Proposal: vendor the latest query-string (9.5.1) and decode-uri-component (0.5.0) sources into ra-core (both MIT, with license headers kept), limited to the parse/stringify code we use, and port their upstream test suites so the corner cases are covered by the same tests upstream relies on. This would also keep the I'd re-run my comparison against the current output to confirm the URLs react-admin generates don't change, and list any differences in the PR. Does that sound like the right direction? |
|
Yes, let's try that |
… custom parser Co-Authored-By: Claude Opus 5.5 <noreply@anthropic.com>
|
Updated as discussed: query-string@9.5.1 and decode-uri-component@0.5.0 are now vendored with their upstream test suites ported (275 tests). Compared with query-string@7, stringify and parse of valid input are 100% identical on 40,000 random cases; the only differences are on malformed input, where the old decoder had known bugs. Details are in the description. |

Problem
Fixes #11380
ra-core,ra-ui-materialui,ra-data-json-serverandra-data-simple-restdepend onquery-string@^7.1.3, which pulls indecode-uri-component@0.2.2. That version is affected by CVE-2026-45822 / GHSA-vcc3-ghjq-m6fr (DoS via malformed percent-encoded input), and it's reachable through URL query parsing (useListParams,useRecordFromLocation).Upgrading isn't an option:
query-string@8+(which uses the patcheddecode-uri-component@^0.5.0) is ESM-only, andra-coreships a CJS build.Solution
Vendor
query-string@9.5.1intora-core, together with its dependenciesdecode-uri-component@0.5.0andsplit-on-first@3.0.0, underpackages/ra-core/src/util/vendor/.parse()/stringify()and the helpers they use,replaceAll()replaced for the ES2020 target, and Prettier formatting.ra-core/src/util/queryString.tsexposesparseQueryString()andstringifyQueryString(), and all internal usages now go through it.fetchUtils.queryParametersnow points tostringifyQueryString, so its signature is unchanged and it still accepts thequery-stringStringifyOptions. There's no API change, unlike theURLSearchParamsapproach suggested in the issue, which would have dropped that parameter.ra-ui-materialui,ra-data-json-server,ra-data-simple-restand the demo usefetchUtils.queryParametersinstead of importingquery-stringdirectly. That keeps them compatible with olderra-core5.x peers, wherequeryParametersis still the originalquery-stringstringify.query-stringis removed from everypackage.json.query-string,decode-uri-component,filter-obj,split-on-firstandstrict-uri-encodeare gone fromyarn.lock.I chose vendoring over a custom parser because it keeps the exact upstream behavior (key sorting,
null/undefinedhandling, array formats,+decoding, malformed input) instead of reimplementing it. The upstream test suites are ported alongside the code.Compatibility with query-string@7
stringify()andparse()of valid input: 100% identical on 40,000 random cases.%E0%A4%A,%,%zz): never throws. The only differences come from known bugs in the olddecode-uri-component@0.2.2.How To Test
yarn test-unit packages/ra-core/src/utilruns the ported upstream tests forparse/stringify/decodeUriComponentplus new tests for the wrapper.yarn test-unit packages/ra-core/src/controller/list packages/ra-core/src/form packages/ra-data-simple-rest packages/ra-ui-materialui/src/list/filter packages/ra-ui-materialui/src/buttoncovers the call sites.yarn why decode-uri-componentshould return nothing.Additional Checks
masterfor a bugfix or a documentation fix, ornextfor a featureuseSavedQueriesstory is updated to use the new helper.import { stringify } from 'query-string'in user-land examples (DataProviderWriting.md,ListTutorial.md,Tutorial.md). Happy to switch them tofetchUtils.queryParametersif you'd like.