mirror of
https://github.com/tiennm99/coolify.git
synced 2026-08-22 08:23:49 +00:00
fix: accept underscores in domain hostnames for API URL validation
PHP's FILTER_VALIDATE_URL rejects underscores in the host, so domains like https://myapp_service.example.com were rejected by the API and never got a Let's Encrypt certificate. Add an isValidDomainUrl() helper that validates a copy with underscores replaced by hyphens, and route domain validation in the Applications and Services API controllers through it. Fixes #10597
This commit is contained in:
@@ -1084,7 +1084,7 @@ class ApplicationsController extends Controller
|
||||
|
||||
$errors = [];
|
||||
$urls = $urls->map(function ($url) use (&$errors) {
|
||||
if (! filter_var($url, FILTER_VALIDATE_URL)) {
|
||||
if (! isValidDomainUrl($url)) {
|
||||
$errors[] = "Invalid URL: {$url}";
|
||||
|
||||
return $url;
|
||||
@@ -1325,7 +1325,7 @@ class ApplicationsController extends Controller
|
||||
|
||||
$errors = [];
|
||||
$urls = $urls->map(function ($url) use (&$errors) {
|
||||
if (! filter_var($url, FILTER_VALIDATE_URL)) {
|
||||
if (! isValidDomainUrl($url)) {
|
||||
$errors[] = "Invalid URL: {$url}";
|
||||
|
||||
return $url;
|
||||
@@ -1538,7 +1538,7 @@ class ApplicationsController extends Controller
|
||||
|
||||
$errors = [];
|
||||
$urls = $urls->map(function ($url) use (&$errors) {
|
||||
if (! filter_var($url, FILTER_VALIDATE_URL)) {
|
||||
if (! isValidDomainUrl($url)) {
|
||||
$errors[] = "Invalid URL: {$url}";
|
||||
|
||||
return $url;
|
||||
@@ -2490,7 +2490,7 @@ class ApplicationsController extends Controller
|
||||
return null;
|
||||
}
|
||||
|
||||
if (! filter_var($url, FILTER_VALIDATE_URL)) {
|
||||
if (! isValidDomainUrl($url)) {
|
||||
$errors[] = 'Invalid URL: '.$url;
|
||||
|
||||
return $url;
|
||||
@@ -2553,7 +2553,7 @@ class ApplicationsController extends Controller
|
||||
|
||||
$errors = [];
|
||||
$urls = $urls->map(function ($url) use (&$errors) {
|
||||
if (! filter_var($url, FILTER_VALIDATE_URL)) {
|
||||
if (! isValidDomainUrl($url)) {
|
||||
$errors[] = "Invalid URL: {$url}";
|
||||
|
||||
return $url;
|
||||
@@ -3866,7 +3866,7 @@ class ApplicationsController extends Controller
|
||||
return null;
|
||||
}
|
||||
|
||||
if (! filter_var($url, FILTER_VALIDATE_URL)) {
|
||||
if (! isValidDomainUrl($url)) {
|
||||
$errors[] = 'Invalid URL: '.$url;
|
||||
|
||||
return str($url)->lower();
|
||||
|
||||
@@ -57,7 +57,7 @@ class ServicesController extends Controller
|
||||
});
|
||||
|
||||
$urls = $urls->map(function ($url) use (&$errors) {
|
||||
if (! filter_var($url, FILTER_VALIDATE_URL)) {
|
||||
if (! isValidDomainUrl($url)) {
|
||||
$errors[] = "Invalid URL: {$url}";
|
||||
|
||||
return $url;
|
||||
|
||||
@@ -4,6 +4,16 @@ use App\Models\Application;
|
||||
use App\Models\ServiceApplication;
|
||||
use Illuminate\Support\Collection;
|
||||
|
||||
function isValidDomainUrl(string $url): bool
|
||||
{
|
||||
// PHP's FILTER_VALIDATE_URL rejects underscores in the host, but they are
|
||||
// accepted by browsers, Let's Encrypt, and common Docker service naming
|
||||
// (e.g. https://myapp_service.example.com). Validate against a copy with
|
||||
// underscores replaced by hyphens (a valid host character) so such domains
|
||||
// are not wrongly rejected; URLs without underscores are unaffected.
|
||||
return filter_var(str_replace('_', '-', $url), FILTER_VALIDATE_URL) !== false;
|
||||
}
|
||||
|
||||
function checkDomainUsage(ServiceApplication|Application|null $resource = null, ?string $domain = null)
|
||||
{
|
||||
$conflicts = [];
|
||||
|
||||
@@ -0,0 +1,22 @@
|
||||
<?php
|
||||
|
||||
it('accepts hostnames containing underscores', function () {
|
||||
// Regression: PHP's FILTER_VALIDATE_URL rejects underscores in the host,
|
||||
// which blocked valid service domains (e.g. Docker service naming) from
|
||||
// being saved and getting Let's Encrypt certificates. See issue #10597.
|
||||
expect(isValidDomainUrl('https://myapp_service.example.com'))->toBeTrue();
|
||||
expect(isValidDomainUrl('http://my_app.example.com'))->toBeTrue();
|
||||
expect(isValidDomainUrl('https://a_b_c.example.com/path'))->toBeTrue();
|
||||
});
|
||||
|
||||
it('accepts ordinary domains and URLs', function () {
|
||||
expect(isValidDomainUrl('https://example.com'))->toBeTrue();
|
||||
expect(isValidDomainUrl('http://sub.example.com:8080/path?q=1'))->toBeTrue();
|
||||
expect(isValidDomainUrl('https://example.com/a_b'))->toBeTrue();
|
||||
});
|
||||
|
||||
it('rejects strings that are not valid URLs', function () {
|
||||
expect(isValidDomainUrl('not a url'))->toBeFalse();
|
||||
expect(isValidDomainUrl('example.com'))->toBeFalse();
|
||||
expect(isValidDomainUrl(''))->toBeFalse();
|
||||
});
|
||||
Reference in New Issue
Block a user