RoR应用请求参数被:search_id符号覆盖问题求助
问题描述
我们的应用基于Ruby 2.7.6和Rails 6.1开发,使用rom及rom-http进行API调用。近期发现浏览器URL和服务端API请求的参数值会被代码中用于标识搜索ID的:search_id符号覆盖。例如原本应为https://sampleapi.json?currency=USD&locale=EN的请求,实际会被替换成https://sampleapi.json?currency=%3Asearch_id&locale=EN(%3A是冒号的URL编码)。
:search_id是我们在诸多传递用户搜索唯一ID的请求中使用的参数名,但目前该符号本身竟注入到几乎所有API请求的参数值中,有时甚至多数参数值都被替换。我们怀疑是activeresource或某款rom gem发生了未被察觉的变更导致此问题。部分请求原本会包含&search_id参数,但当前bug是:search_id符号本身出现在其他参数的取值位置上。
有没有人遇到过类似的问题?
相关请求处理代码
def call(dataset) uri = URI(dataset.uri) uri.path += [dataset.name, dataset.path.presence].compact.join('/') + '.json' # recaptcha api endpoint urls Rails.logger.info "api endpoint is #{dataset.name}" if (dataset.name == '/hotels/rooms' && Settings.enable_recaptcha) api_path = dataset.name.split('/') uri = URI(Settings.recaptcha_api_gateway_url) uri.path += ['/', api_path.last, dataset.path.presence].compact.join('/') end if Rails.env == 'test' && dataset.name == '/hotels/rateshopping' dataset.params[:client_ip] = "74.125.228.110" end if dataset.request_method == :get uri.query = URI.encode_www_form(dataset.params.symbolize_keys.to_a.sort) else uri.query = "ip_address=#{$user_ip}" end http = Net::HTTP.new(uri.host, uri.port) http.use_ssl = uri.scheme.to_s == 'https' request_klass = Net::HTTP.const_get(ROM::Inflector.classify(dataset.request_method)) Rails.logger.info "dataset.params: #{dataset.params}" request = request_klass.new(uri.request_uri) dataset.headers.each_with_object(request) do |(header, value), request| request[header.to_s] = value end if dataset.request_method == :post request['Content-Type'] = 'application/json; charset=utf-8' request.body = dataset.params.to_json end with_cache(dataset, uri) do with_logging(dataset, uri) { http.request(request) } end end
内容的提问来源于stack exchange,提问作者JParrilla
相关产品推荐
相关产品推荐

