fix: require exact pairing deep link route (#4282)

This commit is contained in:
Neil
2026-05-31 10:55:36 -07:00
committed by GitHub
parent 93bba155de
commit 58f10fa2da
4 changed files with 55 additions and 27 deletions
+9
View File
@@ -32,6 +32,15 @@ describe('pairing offer', () => {
expect(() => decodePairingOffer('https://example.com#abc')).toThrow('Invalid pairing URL')
})
it('rejects orca URLs outside the exact pairing route', () => {
const url = encodePairingOffer(offer)
const code = new URLSearchParams(url.slice(url.indexOf('?') + 1)).get('code')!
expect(parsePairingCode(`orca://pairing?code=${code}`)).toBeNull()
expect(parsePairingCode(`orca://pair-extra?code=${code}`)).toBeNull()
expect(() => decodePairingOffer(`orca://pairing?code=${code}`)).toThrow('Invalid pairing URL')
})
it('rejects URLs without a pairing code', () => {
expect(() => decodePairingOffer('orca://pair')).toThrow('Invalid pairing URL')
})
+16 -14
View File
@@ -34,23 +34,25 @@ export function decodePairingOffer(url: string): PairingOffer {
}
function extractPairingCodeFromUrl(url: string): string | null {
if (!url.startsWith('orca://pair')) {
let parsed: URL
try {
parsed = new URL(url)
} catch {
return null
}
const queryIndex = url.indexOf('?')
if (queryIndex !== -1) {
const query = url.slice(queryIndex + 1).split('#')[0] ?? ''
const params = new URLSearchParams(query)
const code = params.get('code')
if (code) {
return code
}
// Why: prefix checks accepted routes like `orca://pairing?...`; only the
// pairing deep-link host may carry runtime auth material.
if (parsed.protocol !== 'orca:' || parsed.hostname !== 'pair') {
return null
}
const hashIndex = url.indexOf('#')
if (hashIndex !== -1) {
return url.slice(hashIndex + 1) || null
if (parsed.pathname !== '' && parsed.pathname !== '/') {
return null
}
return null
const code = parsed.searchParams.get('code')
if (code) {
return code
}
return parsed.hash ? parsed.hash.slice(1) || null : null
}
// Why: accept either an `orca://pair?...` URL or the bare base64
@@ -62,7 +64,7 @@ export function parsePairingCode(input: string): PairingOffer | null {
return null
}
try {
if (trimmed.startsWith('orca://pair')) {
if (trimmed.toLowerCase().startsWith('orca://')) {
return decodePairingOffer(trimmed)
}
return decodePairingBase64(trimmed)