Edit history

Earlier versions of Received value of X-Audit-Log-Reason header is not url-decoded, newest first.

Current version | Edited by Rex
Changes
[image](https://feedback.fluxer.com/p/301#f-280)Removed: ### ChecksRemoved: Removed: - ☑ I searched for existing issues and didn't find a duplicate.Removed:
Show

Received value of X-Audit-Log-Reason header is not url-decoded

Summary

I wanted to make an action and provide an audit log reason that contains a Unicode character (✰ to be exact). Since the header value cannot contain non-ISO-8859-1 characters (or, realistically, characters outside the US-ASCII charset), I provided a URL-encoded UTF-8 value to the X-Audit-Log-Reason header, expecting the API to decode it before storing. Instead, the value was stored as is. FYI, this works fine on Discord.

Steps to reproduce

  1. Make the following API request:
    POST /v1/guilds/{guild.id}/roles HTTP/1.1
    Authorization: Bot {token}
    X-Audit-Log-Reason: %28example%29 %E2%9C%B0
    Content-Type: application/json
    Host: api.fluxer.app
    Content-Length: 17
    
    {"name": "repro"}
    
  2. Look at the audit log in the client to see the issue. You can also verify the value of the "reason" field for the audit log entry in DevTools to see that the reason was not decoded before storing.
FYI, the value of the reason before encoding in the above request is:
(example) ✰

Environment (optional)

N/A

Logs or screenshots (optional)

image
Original by Rex
Show

Received value of X-Audit-Log-Reason header is not url-decoded

Summary

I wanted to make an action and provide an audit log reason that contains a Unicode character (✰ to be exact). Since the header value cannot contain non-ISO-8859-1 characters (or, realistically, characters outside the US-ASCII charset), I provided a URL-encoded UTF-8 value to the X-Audit-Log-Reason header, expecting the API to decode it before storing. Instead, the value was stored as is. FYI, this works fine on Discord.

Steps to reproduce

  1. Make the following API request:
    POST /v1/guilds/{guild.id}/roles HTTP/1.1
    Authorization: Bot {token}
    X-Audit-Log-Reason: %28example%29 %E2%9C%B0
    Content-Type: application/json
    Host: api.fluxer.app
    Content-Length: 17
    
    {"name": "repro"}
    
  2. Look at the audit log in the client to see the issue. You can also verify the value of the "reason" field for the audit log entry in DevTools to see that the reason was not decoded before storing.
FYI, the value of the reason before encoding in the above request is:
(example) ✰

Environment (optional)

N/A

Logs or screenshots (optional)

image

Checks

  • ☑ I searched for existing issues and didn't find a duplicate.