Skip to content

Pin generated URLs to the configured domain - #2226

Merged
melroy89 merged 7 commits into
mainfrom
fix/canonical-router-context
Oct 6, 2026
Merged

melroy89 merged 7 commits into
mainfrom
fix/canonical-router-context

Conversation

@melroy89

@melroy89 melroy89 commented Sep 18, 2026 •

Copy link
Copy Markdown
Member

Summary

  • Pin the Symfony router context to the configured instance domain before absolute URLs are generated.
  • Normalize the configured host, scheme, and ports once when the subscriber is constructed.
  • Log structured warnings when a request-derived router context diverges from the configured canonical context.
  • Reapply the canonical context for main requests, sub-requests, and after Symfony restores a parent request on kernel.finish_request.
  • Add focused regression coverage for hostile hosts, custom ports, logging, and sub-request lifecycle resets.

Related to GHSA-v54w-hc3m-68pq.

Testing

  • vendor/bin/phpunit --no-configuration --bootstrap vendor/autoload.php tests/Unit/EventSubscriber/RouterContextHostSubscriberTest.php
  • PHP CS Fixer dry run for the subscriber and its unit test

@melroy89 melroy89 added the security Issues and pull requests that address security concerns label Sep 18, 2026
Comment thread src/EventSubscriber/RouterContextHostSubscriber.php Outdated
Comment thread src/EventSubscriber/RouterContextHostSubscriber.php Outdated
Comment thread src/EventSubscriber/RouterContextHostSubscriber.php Outdated
@melroy89
melroy89 requested a review from blued-gear September 19, 2026 21:55
@melroy89 melroy89 added the backend Backend related issues and pull requests label Oct 6, 2026
@melroy89 melroy89 added this to the v1.10.0 milestone Oct 6, 2026
@melroy89
melroy89 merged commit 534082a into main Oct 6, 2026
8 of 9 checks passed
@melroy89
melroy89 deleted the fix/canonical-router-context branch October 6, 2026 21:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backend Backend related issues and pull requests security Issues and pull requests that address security concerns

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants