0cdb95bd4f0843610653891af8400a56e3b6090b max Fri Sep 18 07:21:52 2026 -0700 jsonParse: a backslash escape no longer doubles the character it escapes #Preview2 week - bugs introduced now will need a build patch to fix The default branch of the escape switch appended the escaped character and then fell through to the shared append, so \/ came back out of the parser as //, \" as "" and \\ as \\. A session URL parsed and written back out read https:////host//s//user//name. The \u passthrough, which deliberately adds a backslash before falling through, is unchanged. diff --git src/lib/jsonParse.c src/lib/jsonParse.c index f1da344543d..2847d0f6f3a 100644 --- src/lib/jsonParse.c +++ src/lib/jsonParse.c @@ -192,32 +192,33 @@ break; case 'n': c = '\n'; break; case 'r': c = '\r'; break; case 't': c = '\t'; break; case 'u': // Pass through Unicode dyStringAppendC(ds, '\\'); break; default: - // we don't need to convert \,/ or " - dyStringAppendC(ds, c); + // \\, \/ and \" stand for the character after the backslash, which the + // dyStringAppendC below adds. Adding it here as well doubled it, so a URL + // came back out of the parser as "https:////host//path". break; } dyStringAppendC(ds, c); escapeMode = FALSE; } else if(c == '"') break; else if(c == '\\') escapeMode = TRUE; else { dyStringAppendC(ds, c); escapeMode = FALSE; } }