[PR #14476] fix: properly escape collectionName in query string parameters #28192

Closed
opened 2026-02-21 20:42:59 -05:00 by yindo · 0 comments
Owner

Original Pull Request: https://github.com/langgenius/dify/pull/14476

State: closed
Merged: Yes


Summary

The collectionName for a tool can be user-generated (e.g., for
custom tools and user-published workflows). It may contain special
characters such as &, which have specific meanings in HTTP
query strings. Directly concatenating collectionName into the
query string without proper escaping can lead to parsing ambiguities.

This PR addresses the issue by using URLSearchParams to ensure
all query string parameters are correctly escaped.

Closes #14119.

Screenshots

Before After
image
image

Checklist

Important

Please review the checklist below before submitting your pull request.

  • This change requires a documentation update, included: Dify Document
  • I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!)
  • I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change.
  • I've updated the documentation accordingly.
  • I ran dev/reformat(backend) and cd web && npx lint-staged(frontend) to appease the lint gods
**Original Pull Request:** https://github.com/langgenius/dify/pull/14476 **State:** closed **Merged:** Yes --- # Summary The `collectionName` for a tool can be user-generated (e.g., for custom tools and user-published workflows). It may contain special characters such as `&`, which have specific meanings in HTTP query strings. Directly concatenating `collectionName` into the query string without proper escaping can lead to parsing ambiguities. This PR addresses the issue by using `URLSearchParams` to ensure all query string parameters are correctly escaped. Closes #14119. # Screenshots | Before | After | |--------|-------| | ![image](https://github.com/user-attachments/assets/1a506c83-1ccd-408b-b195-a57554aec749) | <img width="1137" alt="image" src="https://github.com/user-attachments/assets/bee13cff-b361-4347-8bad-fd2fe360ba29" /> | # Checklist > [!IMPORTANT] > Please review the checklist below before submitting your pull request. - [ ] This change requires a documentation update, included: [Dify Document](https://github.com/langgenius/dify-docs) - [x] I understand that this PR may be closed in case there was no previous discussion or issues. (This doesn't apply to typos!) - [x] I've added a test for each change that was introduced, and I tried as much as possible to make a single atomic change. - [x] I've updated the documentation accordingly. - [x] I ran `dev/reformat`(backend) and `cd web && npx lint-staged`(frontend) to appease the lint gods
yindo added the pull-request label 2026-02-21 20:42:59 -05:00
yindo closed this issue 2026-02-21 20:42:59 -05:00
Sign in to join this conversation.
1 Participants
Notifications
Due Date
No due date set.
Dependencies

No dependencies set.

Reference: langgenius/dify#28192