You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
{{ message }}
Repository navigation
Commit deb218c
Browse filesBrowse the repository at this point in the historyBrowse files
P A M O D
and
Matteo
authored
Fix#788: Fix quadratic ReDoS in cURL/Postman import placeholder regexes (#789)
* Fix#788: Fix quadratic ReDoS in cURL/Postman import placeholder regexes
* Fix#788: address review feedback - use linear regex shape everywhere
- Replace all {{\s*([^{}\s]+)\s*}} with {{([^{}]+)\}} for linear-time matching
- Add .trim() where variable names are captured
- Revert package-lock.json change
- Add ReDoS regression tests for env-interpolation, curl.parser, postman.parser
* Review follow-up: keep package-lock as on main, CI-safe timing bounds, last loose placeholder regex
- package-lock.json back to main's version (the libc removals came from a
different npm, not from the fix).
- The ReDoS specs allow 250 ms instead of 100: the fixed patterns take ~1 ms,
the old ones take seconds at 50k chars, so the test still catches a
regression without flaking on a slow CI runner.
- adapters.service.ts hasUsableValue() had the same /\{\{[^}]+\}\}/ shape:
3.2 s on 50k '{' against 1 ms now.
---------
Co-authored-by: Matteo <keysersoft@gmail.com>
0 commit comments