Problem
deployComponent canonicalizes project with path.parse(project).name before validating it (components/operations.js:513, utility/componentNames.ts:44-46). That's meant to turn app.tgz into app and @scope/app into app, but it treats any dot as an extension:
project=shop.pr-12 becomes shop.
shop passes PROJECT_NAME_PATTERN.
- The deploy replaces the existing
shop component and reports success for shop.
drop_component doesn't canonicalize, so drop_component project=shop.pr-12 answers 400 and can't undo it.
Present since at least 5.1: path.parse(req.project).name in v5.1.24, and canonicalProjectName in v5.2 and v5.3.
Expected
Strip only archive extensions (such as .tgz) and a scope prefix. Reject any other name that PROJECT_NAME_PATTERN doesn't allow, before anything is written.
Context
Found while planning PR preview names (#3042): a preview named <app>.<pr> would land on production.
Problem
deployComponentcanonicalizesprojectwithpath.parse(project).namebefore validating it (components/operations.js:513,utility/componentNames.ts:44-46). That's meant to turnapp.tgzintoappand@scope/appintoapp, but it treats any dot as an extension:project=shop.pr-12becomesshop.shoppassesPROJECT_NAME_PATTERN.shopcomponent and reports success forshop.drop_componentdoesn't canonicalize, sodrop_component project=shop.pr-12answers 400 and can't undo it.Present since at least 5.1:
path.parse(req.project).namein v5.1.24, andcanonicalProjectNamein v5.2 and v5.3.Expected
Strip only archive extensions (such as
.tgz) and a scope prefix. Reject any other name thatPROJECT_NAME_PATTERNdoesn't allow, before anything is written.Context
Found while planning PR preview names (#3042): a preview named
<app>.<pr>would land on production.