fix: harden UCE runtime and starter
This commit is contained in:
@@ -0,0 +1,29 @@
|
||||
:title
|
||||
request_query_route
|
||||
|
||||
:sig
|
||||
DTree request_query_route(Request& context, String default_path = "index")
|
||||
|
||||
:see
|
||||
request_query_path
|
||||
request_context_params
|
||||
route_path_sanitize
|
||||
request_script_url
|
||||
|
||||
:content
|
||||
Builds a small route tree from the first keyless query-string segment.
|
||||
|
||||
Fields:
|
||||
|
||||
- `raw_path`: normalized but untrusted route input, for diagnostics only
|
||||
- `l_path`: sanitized full route path, or empty string when input was rejected
|
||||
- `page`: first path segment of `l_path`, or empty string when input was rejected
|
||||
- `valid`: boolean; true when `l_path` is safe
|
||||
|
||||
```cpp
|
||||
DTree route = request_query_route(context);
|
||||
if(route["valid"].to_bool())
|
||||
print("route=", route["l_path"].to_string());
|
||||
```
|
||||
|
||||
This supports front-controller apps that use URLs such as `/?dashboard` or `/?workspace/projects` while still allowing ordinary named query parameters alongside the route. The returned `l_path` is already sanitized for composing under an application-controlled route root.
|
||||
Reference in New Issue
Block a user