Checkout and four other handlers take a field from the URL when the posted form leaves it out #205
Open
opened 2026-10-09 16:02:12 +00:00 by cgalo5758
·
0 comments
Labels
Clear labels
accessibility
area/billing
area/catalog
area/discourse
area/domains
area/entitlements
area/fedwiki
area/identity
area/integrations
area/licensing
area/member-ui
area/meta
area/operator-ui
area/ops
area/testing
duplicate
good-first-issue
invalid
privacy
security
upstream
wontfix
A barrier for people using assistive technology or a keyboard alone.
The Stripe mirror, checkout, subscriptions, invoices, fulfillment.
Products, prices, plan ladders, purchasability.
The Discourse integration.
The domains registry, claims, placements, the certificate ask.
Entitlement sets, rules, grants, pools, provisioning.
The Federated Wiki integration and farm sync.
Sign-in, sessions, persons, organizations, workspaces, roles.
The provider registry, outbox and webhooks in general.
Licenses, the contributor agreement, SPDX headers.
Member pages.
The repository itself, its contributing guide, CI, the tracker and the workflow.
Operator pages, forms, lists, the design system.
Deployment, configuration, migrations, workflows, instance settings.
The test stack, screens, lint, walkthroughs.
Closed because another issue already covers it.
Small, self-contained, and explained enough to be a first contribution.
Closed because it is not a ticket for this repository.
Touches what a person's data reveals.
Touches authentication, authorization, secrets or data exposure.
Waits on another repository or project before it can move.
Closed because it will not be done, with the reason in the last comment.
kind
bug
The software does something other than what it promises; closed when it again does what it promises.
kind
debt
Code, tests or tooling to clean up with nothing visible changing; closed when they are cleaner.
kind
design
A question to settle before work can be defined; closed when the decision is written down.
kind
docs
Documentation that is wrong or missing; closed when it says the right thing.
kind
enhancement
Something the software does not do yet; closed when it does.
priority
critical
Blocks the active milestone or harms members now.
priority
high
Next in line inside the active milestone.
priority
low
Inside the active milestone, when nothing else is left.
priority
medium
Inside the active milestone, after the high ones.
Milestone
No items
No Milestone
Projects
Clear projects
No projects
No Assignees
Notifications
Due Date
No due date set.
Dependencies
No dependencies set.
Reference: wiki-cafe/member-console#205
Reference in New Issue
Block a user
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
What a contributor runs into
The rule for reading a request is that a handler never calls
r.FormValueand readsr.PostForminstead, whether or not it uses the forms library (docs/operator-ux-conventions.md, "Server-side validation").r.FormValuereads the posted body and the URL's query string together. When both carry a field, the body's value wins. When the body leaves the field out, the URL's value is used.Five POST handlers still read their fields that way:
HandleCheckout,internal/server/billing.go) readsprice_id. APOST /billing/checkout?price_id=…with an empty body opens a Stripe Checkout for that price. The Products page and the add-ons list both postprice_idin the body.PostKeepandPostCancel,internal/server/member_plan_moves.go) readladder_id. Cancel also readstiming, so?timing=immediatein the URL ends the subscription now instead of at the period end.SyncProductToStripe,internal/server/operator_billing.go) readsprice_id.RevokeGrantAndTransition,internal/server/operator_enrollment.go) readsorg_id.The tests post every one of these fields in the body, so nothing covers the URL as a second source. The console refuses a cross-origin POST before any of these handlers run, so the URL opens no new way in.
Why it costs
Each of these handlers accepts a request its page never sends, and no test says whether it should. A new handler copied from one of them copies the read along with it. Nothing in
make lintrefusesr.FormValue.Where
internal/server/billing.go(HandleCheckout),internal/server/member_plan_moves.go(PostKeep,PostCancel),internal/server/operator_billing.go(SyncProductToStripe),internal/server/operator_enrollment.go(RevokeGrantAndTransition).Done when
r.PostForm. For each handler, a test that posts the field only in the URL gets the same answer as a request with the field missing..golangci.ymlrefusesr.FormValue.parseAddress(internal/integrations/fedwiki/web/requests.go) also calls it, for POST routes and for one DELETE route whose fields htmx sends in the URL, so it reads each field from where its method carries it.docs/operator-ux-conventions.mddescribesr.FormValueaccurately: the posted value wins, and the URL's value is used when the body has none.