This project is archived and is in readonly mode.
params in functional tests not sent to controller encoded
-
Andrew White
- Assigned user set to Andrew White
- Importance changed from to Low
-
Andrew White
- State changed from new to open
- Milestone set to 3.0.2
You're right that the params in controller functional tests are never at the HTTP level which is why your param is still escaped. If you look at the code which processes the request then all that happens to the params is that they are merged into to @controller.params.
The problem is that slashes aren't allowed in path parameters so you get the route not matching error. There are two things you can do to workaround the problem. The first one is to customise the path parameter regexp (e.g: :number => /.+/). The second escape the parameter manually (as you've done) - which you'd have to do in your app as well as only query params are automatically escaped.
I think there's definitely something that needs to be addressed here the question is how - do we automatically escape the params on the way in or automatically unescape the params on the way out.
-
Xavier Noria
Param values in functional tests are raw, whatever you put goes.
I am not sure Rails can do the escaping automatically because values may not be strings. They should in your tests generally speaking as a best practice, because the controller expects them to be strings. But in practice sometimes they aren't, eg a model's ID passed directly as an integer, nested hashes.... In particular Rails cannot assume they are strings.
Converting values to strings should be done before considering this patch in my view. That has been sometimes discussed, I don't remember why isn't done off the top of my head. Anyone?
That is, either values are raw, or else they fully emulate HTTP params. A mix of both could be confusing IMO.
-
Ryan Bigg
Automatic cleanup of spam.
-
johnjosephbachir (at gmail)
Since submitting this ticket I've realized/concluded that in the scenario described, we actually should not expect rails to do the decoding. The whole point of url encoding something is that so that url syntax can be used within a url variable. So, there is in fact no way for the application stack to inherently know when part of a url is encoded.
Sorry for confusing the issue -- this ticket can be closed.
Cheers,
John -
Rohit Arondekar
- State changed from open to invalid