Skip to content

Escape ~ and / in JSONPointer.toURIFragment() - #1083

Open
DarkLight606 wants to merge 1 commit into
stleary:masterfrom
DarkLight606:fix/1082
Open

DarkLight606 wants to merge 1 commit into
stleary:masterfrom
DarkLight606:fix/1082

Conversation

@DarkLight606

Copy link
Copy Markdown

Fixes #1082.

toURIFragment() now applies the RFC 6901 escaping (~ to ~0, / to ~1) to each token before URL-encoding it, matching what toString() does. Before this, a pointer to the key "/" became "#/%2F", which the constructor decodes and splits into two empty tokens, and a pointer to "~1" came back as a pointer to "/".

Tests: added toURIFragmentEscaping and toURIFragmentRoundTrip. The existing toURIFragment assertion for "/m~n" changes from "#/m%7En" to "#/m%7E0n", since the old value was the unescaped form.

mvn clean test passes on JDK 8 and 11.

toURIFragment() URL-encoded each reference token but skipped the ~0/~1
escaping from RFC 6901. Tokens are stored as literal key names, so a key
containing / or ~ produced a fragment that parsed back to a different
pointer. Apply escape() before encoding, as toString() already does.

Fixes stleary#1082
@sonarqubecloud

Copy link
Copy Markdown

@stleary

stleary commented Sep 26, 2026

Copy link
Copy Markdown
Owner

What problem does this code solve?
Addresses a bug exposed while fixing JSONPointer. JSONPointer.toURIFragment() was URL-encoding each token without first applying the RFC 6901 ~0/~1 escaping.

Risks
Low

Changes to the Existing Behavior
toURIFragment() now escapes ~ as ~0 and / as ~1, so the output changes for keys containing those characters. This is an acceptable change.

Changes to the API
No

Will this require a new release?
No

Should the documentation be updated?
No

Unit Tests
New unit tests were added. One unit test was updated because it was looking for the incorrect result

Refactoring
None

Review status
APPROVED

Starting 3-day comment window

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

JSONPointer pre-existing bug in toURIFragment()

2 participants