0cdb95bd4f0843610653891af8400a56e3b6090b
max
  Fri Sep 18 07:21:52 2026 -0700
jsonParse: a backslash escape no longer doubles the character it escapes

#Preview2 week - bugs introduced now will need a build patch to fix
The default branch of the escape switch appended the escaped character and
then fell through to the shared append, so \/ came back out of the parser as
//, \" as "" and \\ as \\.  A session URL parsed and written back out read
https:////host//s//user//name.  The \u passthrough, which deliberately adds a
backslash before falling through, is unchanged.

diff --git src/lib/jsonParse.c src/lib/jsonParse.c
index f1da344543d..2847d0f6f3a 100644
--- src/lib/jsonParse.c
+++ src/lib/jsonParse.c
@@ -192,32 +192,33 @@
                 break;
             case 'n':
                 c = '\n';
                 break;
             case 'r':
                 c = '\r';
                 break;
             case 't':
                 c = '\t';
                 break;
             case 'u':
 		// Pass through Unicode
 		dyStringAppendC(ds, '\\');
                 break;
             default:
-                // we don't need to convert \,/ or "
-		dyStringAppendC(ds, c);
+                // \\, \/ and \" stand for the character after the backslash, which the
+                // dyStringAppendC below adds.  Adding it here as well doubled it, so a URL
+                // came back out of the parser as "https:////host//path".
                 break;
             }
         dyStringAppendC(ds, c);
         escapeMode = FALSE;
         }
     else if(c == '"')
         break;
     else if(c == '\\')
         escapeMode = TRUE;
     else
         {
         dyStringAppendC(ds, c);
         escapeMode = FALSE;
         }
     }