Skip to content

Commit 422d3c9

Browse files
pgriessry
authored andcommitted
Get rid of PHP/Rails style parameter munging.
- Handle only the most basic of query string parsing and construction. Leave the rest (e.g. Rails/PHP behaviors) to modules higher up the stack, like Express.
1 parent debf389 commit 422d3c9

File tree

3 files changed

+66
-127
lines changed

3 files changed

+66
-127
lines changed

doc/api.markdown

+4-25
Original file line numberDiff line numberDiff line change
@@ -2988,9 +2988,10 @@ Take a base URL, and a href URL, and resolve them as a browser would for an anch
29882988

29892989
This module provides utilities for dealing with query strings. It provides the following methods:
29902990

2991-
### querystring.stringify(obj, sep='&', eq='=', munge=true)
2991+
### querystring.stringify(obj, sep='&', eq='=')
29922992

29932993
Serialize an object to a query string. Optionally override the default separator and assignment characters.
2994+
29942995
Example:
29952996

29962997
querystring.stringify({foo: 'bar'})
@@ -3001,40 +3002,18 @@ Example:
30013002
// returns
30023003
'foo:bar;baz:bob'
30033004

3004-
By default, this function will perform PHP/Rails-style parameter munging for arrays and objects used as
3005-
values within `obj`.
3006-
Example:
3007-
3008-
querystring.stringify({foo: ['bar', 'baz', 'boz']})
3009-
// returns
3010-
'foo%5B%5D=bar&foo%5B%5D=baz&foo%5B%5D=boz'
3011-
3012-
querystring.stringify({foo: {bar: 'baz'}})
3013-
// returns
3014-
'foo%5Bbar%5D=baz'
3015-
3016-
If you wish to disable the array munging (e.g. when generating parameters for a Java servlet), you
3017-
can set the `munge` argument to `false`.
3018-
Example:
3019-
3020-
querystring.stringify({foo: ['bar', 'baz', 'boz']}, '&', '=', false)
3021-
// returns
3022-
'foo=bar&foo=baz&foo=boz'
3023-
3024-
Note that when `munge` is `false`, parameter names with object values will still be munged.
3025-
30263005
### querystring.parse(str, sep='&', eq='=')
30273006

30283007
Deserialize a query string to an object. Optionally override the default separator and assignment characters.
30293008

3009+
Example:
3010+
30303011
querystring.parse('a=b&b=c')
30313012
// returns
30323013
{ 'a': 'b'
30333014
, 'b': 'c'
30343015
}
30353016

3036-
This function can parse both munged and unmunged query strings (see `stringify` for details).
3037-
30383017
### querystring.escape
30393018

30403019
The escape function used by `querystring.stringify`, provided so that it could be overridden if necessary.

lib/querystring.js

+56-73
Original file line numberDiff line numberDiff line change
@@ -10,8 +10,22 @@ QueryString.escape = function (str) {
1010
return encodeURIComponent(str);
1111
};
1212

13+
var stringifyPrimitive = function(v) {
14+
switch (typeof v) {
15+
case "string":
16+
return v;
17+
18+
case "boolean":
19+
return v ? "true" : "false";
20+
21+
case "number":
22+
return isFinite(v) ? v : "";
23+
24+
default:
25+
return "";
26+
}
27+
};
1328

14-
var stack = [];
1529
/**
1630
* <p>Converts an arbitrary value to a Query String representation.</p>
1731
*
@@ -21,92 +35,61 @@ var stack = [];
2135
* @param obj {Variant} any arbitrary value to convert to query string
2236
* @param sep {String} (optional) Character that should join param k=v pairs together. Default: "&"
2337
* @param eq {String} (optional) Character that should join keys to their values. Default: "="
24-
* @param munge {Boolean} (optional) Indicate whether array/object params should be munged, PHP/Rails-style. Default: true
2538
* @param name {String} (optional) Name of the current key, for handling children recursively.
2639
* @static
2740
*/
28-
QueryString.stringify = QueryString.encode = function (obj, sep, eq, munge, name) {
29-
munge = typeof munge == "undefined" || munge;
41+
QueryString.stringify = QueryString.encode = function (obj, sep, eq, name) {
3042
sep = sep || "&";
3143
eq = eq || "=";
32-
var type = Object.prototype.toString.call(obj);
33-
if (obj == null || type == "[object Function]" || type == "[object Number]" && !isFinite(obj)) {
34-
return name ? QueryString.escape(name) + eq : "";
35-
}
36-
37-
switch (type) {
38-
case '[object Boolean]':
39-
obj = +obj; // fall through
40-
case '[object Number]':
41-
case '[object String]':
42-
return QueryString.escape(name) + eq + QueryString.escape(obj);
43-
case '[object Array]':
44-
name = name + (munge ? "[]" : "");
45-
return obj.map(function (item) {
46-
return QueryString.stringify(item, sep, eq, munge, name);
47-
}).join(sep);
48-
}
49-
// now we know it's an object.
50-
51-
// Check for cyclical references in nested objects
52-
for (var i = stack.length - 1; i >= 0; --i) if (stack[i] === obj) {
53-
throw new Error("querystring.stringify. Cyclical reference");
54-
}
55-
56-
stack.push(obj);
44+
obj = (obj === null) ? undefined : obj;
5745

58-
var begin = name ? name + "[" : "",
59-
end = name ? "]" : "",
60-
keys = Object.keys(obj),
61-
n,
62-
s = Object.keys(obj).map(function (key) {
63-
n = begin + key + end;
64-
return QueryString.stringify(obj[key], sep, eq, munge, n);
46+
switch (typeof obj) {
47+
case "object":
48+
return Object.keys(obj).map(function(k) {
49+
if (Array.isArray(obj[k])) {
50+
return obj[k].map(function(v) {
51+
return QueryString.escape(stringifyPrimitive(k)) +
52+
eq +
53+
QueryString.escape(stringifyPrimitive(v));
54+
}).join(sep);
55+
} else {
56+
return QueryString.escape(stringifyPrimitive(k)) +
57+
eq +
58+
QueryString.escape(stringifyPrimitive(obj[k]));
59+
}
6560
}).join(sep);
6661

67-
stack.pop();
68-
69-
if (!s && name) {
70-
return name + "=";
62+
default:
63+
return (name) ?
64+
QueryString.escape(stringifyPrimitive(name)) + eq +
65+
QueryString.escape(stringifyPrimitive(obj)) :
66+
"";
7167
}
72-
return s;
7368
};
7469

75-
// matches .xxxxx or [xxxxx] or ['xxxxx'] or ["xxxxx"] with optional [] at the end
76-
var chunks = /(?:(?:^|\.)([^\[\(\.]+)(?=\[|\.|$|\()|\[([^"'][^\]]*?)\]|\["([^\]"]*?)"\]|\['([^\]']*?)'\])(\[\])?/g;
7770
// Parse a key=val string.
7871
QueryString.parse = QueryString.decode = function (qs, sep, eq) {
72+
sep = sep || "&";
73+
eq = eq || "=";
7974
var obj = {};
80-
if (qs === undefined) { return {} }
81-
String(qs).split(sep || "&").map(function (keyValue) {
82-
var res = obj,
83-
next,
84-
kv = keyValue.split(eq || "="),
85-
key = QueryString.unescape(kv.shift(), true),
86-
value = QueryString.unescape(kv.join(eq || "="), true);
87-
key.replace(chunks, function (all, name, nameInBrackets, nameIn2Quotes, nameIn1Quotes, isArray, offset) {
88-
var end = offset + all.length == key.length;
89-
name = name || nameInBrackets || nameIn2Quotes || nameIn1Quotes;
90-
next = end ? value : {};
91-
if (Array.isArray(res[name])) {
92-
res[name].push(next);
93-
res = next;
94-
} else {
95-
if (name in res) {
96-
if (isArray || end) {
97-
res = (res[name] = [res[name], next])[1];
98-
} else {
99-
res = res[name];
100-
}
101-
} else {
102-
if (isArray) {
103-
res = (res[name] = [next])[0];
104-
} else {
105-
res = res[name] = next;
106-
}
107-
}
108-
}
109-
});
75+
76+
if (typeof qs !== 'string') {
77+
return obj;
78+
}
79+
80+
qs.split(sep).forEach(function(kvp) {
81+
var x = kvp.split(eq);
82+
var k = QueryString.unescape(x[0], true);
83+
var v = QueryString.unescape(x.slice(1).join(eq), true);
84+
85+
if (!(k in obj)) {
86+
obj[k] = v;
87+
} else if (!Array.isArray(obj[k])) {
88+
obj[k] = [obj[k], v];
89+
} else {
90+
obj[k].push(v);
91+
}
11092
});
93+
11194
return obj;
11295
};

test/simple/test-querystring.js

+6-29
Original file line numberDiff line numberDiff line change
@@ -10,35 +10,17 @@ var qs = require("querystring");
1010
var qsTestCases = [
1111
["foo=918854443121279438895193", "foo=918854443121279438895193", {"foo": "918854443121279438895193"}],
1212
["foo=bar", "foo=bar", {"foo" : "bar"}],
13-
["foo=bar&foo=quux", "foo%5B%5D=bar&foo%5B%5D=quux", {"foo" : ["bar", "quux"]}],
13+
["foo=bar&foo=quux", "foo=bar&foo=quux", {"foo" : ["bar", "quux"]}],
1414
["foo=1&bar=2", "foo=1&bar=2", {"foo" : "1", "bar" : "2"}],
1515
["my+weird+field=q1%212%22%27w%245%267%2Fz8%29%3F", "my%20weird%20field=q1!2%22'w%245%267%2Fz8)%3F", {"my weird field" : "q1!2\"'w$5&7/z8)?" }],
1616
["foo%3Dbaz=bar", "foo%3Dbaz=bar", {"foo=baz" : "bar"}],
1717
["foo=baz=bar", "foo=baz%3Dbar", {"foo" : "baz=bar"}],
18-
[ "str=foo&arr[]=1&arr[]=2&arr[]=3&obj[a]=bar&obj[b][]=4&obj[b][]=5&obj[b][]=6&obj[b][]=&obj[c][]=4&obj[c][]=5&obj[c][][somestr]=baz&obj[objobj][objobjstr]=blerg&somenull=&undef=", "str=foo&arr%5B%5D=1&arr%5B%5D=2&arr%5B%5D=3&obj%5Ba%5D=bar&obj%5Bb%5D%5B%5D=4&obj%5Bb%5D%5B%5D=5&obj%5Bb%5D%5B%5D=6&obj%5Bb%5D%5B%5D=&obj%5Bc%5D%5B%5D=4&obj%5Bc%5D%5B%5D=5&obj%5Bc%5D%5B%5D%5Bsomestr%5D=baz&obj%5Bobjobj%5D%5Bobjobjstr%5D=blerg&somenull=&undef=", {
18+
[ "str=foo&arr=1&arr=2&arr=3&somenull=&undef=", "str=foo&arr=1&arr=2&arr=3&somenull=&undef=", {
1919
"str":"foo",
2020
"arr":["1","2","3"],
21-
"obj":{
22-
"a":"bar",
23-
"b":["4","5","6",""],
24-
"c":["4","5",{"somestr":"baz"}],
25-
"objobj":{"objobjstr":"blerg"}
26-
},
2721
"somenull":"",
2822
"undef":""
2923
}],
30-
["foo[bar][bla]=baz&foo[bar][bla]=blo", "foo%5Bbar%5D%5Bbla%5D%5B%5D=baz&foo%5Bbar%5D%5Bbla%5D%5B%5D=blo", {"foo":{"bar":{"bla":["baz","blo"]}}}],
31-
["foo[bar][][bla]=baz&foo[bar][][bla]=blo", "foo%5Bbar%5D%5B%5D%5Bbla%5D=baz&foo%5Bbar%5D%5B%5D%5Bbla%5D=blo", {"foo":{"bar":[{"bla":"baz"},{"bla":"blo"}]}}],
32-
["foo[bar][bla][]=baz&foo[bar][bla][]=blo", "foo%5Bbar%5D%5Bbla%5D%5B%5D=baz&foo%5Bbar%5D%5Bbla%5D%5B%5D=blo", {"foo":{"bar":{"bla":["baz","blo"]}}}],
33-
34-
["foo.bar.bla=baz&foo.bar.bla=blo", "foo%5Bbar%5D%5Bbla%5D%5B%5D=baz&foo%5Bbar%5D%5Bbla%5D%5B%5D=blo", {"foo":{"bar":{"bla":["baz","blo"]}}}],
35-
["foo.bar[].bla=baz&foo[bar][][bla]=blo", "foo%5Bbar%5D%5B%5D%5Bbla%5D=baz&foo%5Bbar%5D%5B%5D%5Bbla%5D=blo", {"foo":{"bar":[{"bla":"baz"},{"bla":"blo"}]}}],
36-
["foo[bar].bla[]=baz&foo.bar[bla][]=blo", "foo%5Bbar%5D%5Bbla%5D%5B%5D=baz&foo%5Bbar%5D%5Bbla%5D%5B%5D=blo", {"foo":{"bar":{"bla":["baz","blo"]}}}],
37-
38-
["foo['bar']['bla']=baz&foo[\"bar\"][\"bla\"]=blo", "foo%5Bbar%5D%5Bbla%5D%5B%5D=baz&foo%5Bbar%5D%5Bbla%5D%5B%5D=blo", {"foo":{"bar":{"bla":["baz","blo"]}}}],
39-
["foo['bar'][]['bla']=baz&foo['bar'][][\"bla\"]=blo", "foo%5Bbar%5D%5B%5D%5Bbla%5D=baz&foo%5Bbar%5D%5B%5D%5Bbla%5D=blo", {"foo":{"bar":[{"bla":"baz"},{"bla":"blo"}]}}],
40-
["foo[bar][\"bla\"][]=baz&foo[\"bar\"][bla][]=blo", "foo%5Bbar%5D%5Bbla%5D%5B%5D=baz&foo%5Bbar%5D%5Bbla%5D%5B%5D=blo", {"foo":{"bar":{"bla":["baz","blo"]}}}],
41-
4224
[" foo = bar ", "%20foo%20=%20bar%20", {" foo ":" bar "}],
4325
["foo=%zx", "foo=%25zx", {"foo":"%zx"}],
4426
["foo=%EF%BF%BD", "foo=%EF%BF%BD", {"foo" : "\ufffd" }]
@@ -47,7 +29,7 @@ var qsTestCases = [
4729
// [ wonkyQS, canonicalQS, obj ]
4830
var qsColonTestCases = [
4931
["foo:bar", "foo:bar", {"foo":"bar"}],
50-
["foo:bar;foo:quux", "foo%5B%5D:bar;foo%5B%5D:quux", {"foo" : ["bar", "quux"]}],
32+
["foo:bar;foo:quux", "foo:bar;foo:quux", {"foo" : ["bar", "quux"]}],
5133
["foo:1&bar:2;baz:quux", "foo:1%26bar%3A2;baz:quux", {"foo":"1&bar:2", "baz":"quux"}],
5234
["foo%3Abaz:bar", "foo%3Abaz:bar", {"foo:baz":"bar"}],
5335
["foo:baz:bar", "foo:baz%3Abar", {"foo":"baz:bar"}]
@@ -65,8 +47,8 @@ var qsWeirdObjects = [
6547
[ {e:extendedFunction}, "e=", {"e":""} ],
6648
[ {d:new Date()}, "d=", {"d":""} ],
6749
[ {d:Date}, "d=", {"d":""} ],
68-
[ {f:new Boolean(false), t:new Boolean(true)}, "f=0&t=1", {"f":"0", "t":"1"} ],
69-
[ {f:false, t:true}, "f=0&t=1", {"f":"0", "t":"1"} ],
50+
[ {f:new Boolean(false), t:new Boolean(true)}, "f=&t=", {"f":"", "t":""} ],
51+
[ {f:false, t:true}, "f=false&t=true", {"f":"false", "t":"true"} ],
7052
[ {n:null}, "n=", {"n":""} ],
7153
[ {nan:NaN}, "nan=", {"nan":""} ],
7254
[ {inf:Infinity}, "inf=", {"inf":""} ]
@@ -84,7 +66,7 @@ var qsNoMungeTestCases = [
8466
["gragh=1&gragh=3&goo=2", {"gragh": ["1", "3"], "goo": "2"}],
8567
["frappucino=muffin&goat%5B%5D=scone&pond=moose",
8668
{"frappucino": "muffin", "goat[]": "scone", "pond": "moose"}],
87-
["obj%5Btrololol%5D=yes&obj%5Blololo%5D=no", {"obj": {"trololol": "yes", "lololo": "no"}}]
69+
["trololol=yes&lololo=no", {"trololol": "yes", "lololo": "no"}]
8870
];
8971

9072
assert.strictEqual("918854443121279438895193", qs.parse("id=918854443121279438895193").id);
@@ -123,11 +105,6 @@ qsNoMungeTestCases.forEach(function (testCase) {
123105
})();
124106

125107
// now test stringifying
126-
assert.throws(function () {
127-
var f = {};
128-
f.f = f;
129-
qs.stringify(f);
130-
});
131108

132109
// basic
133110
qsTestCases.forEach(function (testCase) {

0 commit comments

Comments
 (0)