fix(02-03): scrub PHP-escaped JSON secret values

PHP json_encode writes \/ so captured redirect URLs never matched the fixture body, leaving OAuth codes in client sessions.

Co-authored-by: Cursor <cursoragent@cursor.com>
This commit is contained in:
Jakub Zych
2026-09-17 13:31:58 +02:00
parent 0307510b22
commit 8f94b07986
2 changed files with 39 additions and 4 deletions

View File

@@ -476,15 +476,25 @@ func replaceAll(s string, pairs [][2]string) string {
if p[0] == "" {
continue
}
if len(p[0]) >= 8 {
s = strings.ReplaceAll(s, p[0], p[1])
continue
olds := []string{p[0]}
if esc := phpJSONEscape(p[0]); esc != p[0] {
olds = append(olds, esc)
}
for _, old := range olds {
if len(old) >= 8 {
s = strings.ReplaceAll(s, old, p[1])
continue
}
s = replaceIsolated(s, old, p[1])
}
s = replaceIsolated(s, p[0], p[1])
}
return s
}
func phpJSONEscape(s string) string {
return strings.ReplaceAll(s, "/", `\/`)
}
func replaceIsolated(s, old, neu string) string {
if old == "" || s == "" {
return s