Skip to content

Canonicalize the request path before tripwire matching (#57) - #58

Merged
cport1 merged 1 commit into
mainfrom
fix/tripwire-path-normalize-57
Sep 30, 2026
Merged

cport1 merged 1 commit into
mainfrom
fix/tripwire-path-normalize-57

Conversation

@cport1

@cport1 cport1 commented Sep 30, 2026

Copy link
Copy Markdown
Contributor

Closes #57.

The bug

TripwireRule matched the raw request path, stripping only the query and fragment. A scan for a decoy path could dress it up and still resolve, at the origin, to the file it was hunting for — while the tripwire matched nothing:

  • //.env (duplicate slash)
  • /%2Eenv, /%252Eenv (percent- and double-encoded dot)
  • /static/..%2f.git/config, /x/../.env (traversal)

Missing that scan defeats the tripwire's whole purpose.

The fix

canonicalizeTripwirePath reduces the path the way a webserver would before matching: drop query/fragment, ASCII percent-decode (bounded, so double-encoding resolves), collapse duplicate slashes, resolve . and .. (keeping a single trailing slash). The configured decoy paths are canonicalized the same way, so both sides of the match line up. Done in the rule, so it holds regardless of how a given adapter or server passes the path.

Legitimate lookalikes (/environment, /env/config, /assets/env.js) are unaffected — added as a guard test.

Full package suite green (489), Express adapter green (15).

Note: ASCII-only percent-decode leaves high bytes encoded (so a null-byte or overlong-UTF-8 truncation trick is out of scope here); those are origin-specific and can be a follow-up if seen.

A hidden-path tripwire matched the raw path, so a scan could dress a decoy path
up and slip past while a webserver still resolved it to the file being hunted:
//.env, /%2Eenv, /%252Eenv, /static/..%2f.git/config, /x/../.env. Missing the
scan defeats the point of the tripwire.

canonicalizeTripwirePath now reduces the path the way a server would before
matching — drop query/fragment, ASCII percent-decode (bounded, so double
encoding resolves), collapse duplicate slashes, resolve . and .. keeping one
trailing slash — and the configured decoy paths are canonicalized the same way
so both sides line up. Legitimate lookalikes (/environment, /env/config) are
unaffected. Full suite green.
@cport1
cport1 merged commit 9c67728 into main Sep 30, 2026
2 checks passed
@cport1
cport1 deleted the fix/tripwire-path-normalize-57 branch September 30, 2026 04:11
@cport1 cport1 mentioned this pull request Sep 30, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Verify: tripwire path matching may be evadable by traversal/double-encoding/double-slash (adaptive self-test)

1 participant