Skip to content

Reject leading and trailing label hyphens in DomainValidator unicodeToASCII#424

Merged
garydgregory merged 1 commit into
apache:masterfrom
sahvx655-wq:domain-reject-boundary-hyphen
Jul 17, 2026
Merged

Reject leading and trailing label hyphens in DomainValidator unicodeToASCII#424
garydgregory merged 1 commit into
apache:masterfrom
sahvx655-wq:domain-reject-boundary-hyphen

Conversation

@sahvx655-wq

Copy link
Copy Markdown
Contributor

DomainValidator.isValid accepts a non-ASCII domain label that begins or ends with a hyphen: isValid("-tést.fr") and isValid("tést-.fr") both return true, though the all-ASCII forms "-test.fr" and "test-.fr" are correctly rejected. This is VALIDATOR-501, whose DomainValidatorTest.testInvalidDomains501 has been sitting @disabled. The divergence is in the shared unicodeToASCII helper: for a label carrying a non-ASCII character it defers to IDN.toASCII, which with the default flags does not apply the LDH rule and punycode-encodes the boundary hyphen ("-tést" becomes "xn---tst-cpa"), so the converted label starts and ends alphanumeric, DOMAIN_LABEL_REGEX matches, and the hyphen the ASCII path would have caught slips through. UrlValidator.isValidAuthority and the EmailValidator domain check share unicodeToASCII, so they inherit the same hole.

The fix scans the original input before conversion and, when any label opens or closes with a hyphen, returns it unchanged so the label regex rejects it, matching the format-code-point guard added a few lines above. It splits on the four label separators from RFC 3490 section 3.1 and leaves an interior hyphen alone, so "a-é.fr" keeps validating while "-é.fr" does not. Keeping the check in the shared helper closes the gap for DomainValidator, UrlValidator and EmailValidator in one place rather than in each caller. I enabled testInvalidDomains501 and added the "-é.fr"/"a-é.fr" pair; the full suite stays green.

  • Read the contribution guidelines for this project.
  • Read the ASF Generative Tooling Guidance if you use Artificial Intelligence (AI).
  • I used AI to create any part of, or all of, this pull request. Which AI tool was used to create this pull request, and to what extent did it contribute?
  • Run a successful build using the default Maven goal with mvn; that's mvn on the command line by itself.
  • Write unit tests that match behavioral changes, where the tests fail if the changes to the runtime are not applied. This may not always be possible, but it is a best practice.
  • Write a pull request description that is detailed enough to understand what the pull request does, how, and why.
  • Each commit in the pull request should have a meaningful subject line and body. Note that a maintainer may squash commits during the merge process.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Closes VALIDATOR-501 by making DomainValidator.unicodeToASCII reject domains where any label starts or ends with - even when the label contains non-ASCII characters that would otherwise be punycode-encoded into an ASCII form that slips past the existing label regex checks. This aligns IDN-handling behavior with the existing all-ASCII validation path and fixes the shared behavior for DomainValidator, UrlValidator, and the email domain validation that rely on unicodeToASCII.

Changes:

  • Enable and expand the previously @Disabled regression test for VALIDATOR-501.
  • Add a pre-conversion scan in unicodeToASCII to detect leading/trailing hyphens at label boundaries (using RFC 3490 dot separators) and return the original input so existing regex validation rejects it.

Reviewed changes

Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.

File Description
src/main/java/org/apache/commons/validator/routines/DomainValidator.java Adds label-boundary hyphen detection to prevent IDN punycode from bypassing LDH-style label rules in downstream regex validation.
src/test/java/org/apache/commons/validator/routines/DomainValidatorTest.java Enables and extends a regression test to ensure non-ASCII labels with boundary hyphens are rejected while interior hyphens remain valid.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@garydgregory garydgregory changed the title reject leading and trailing label hyphens in unicodeToASCII Reject leading and trailing label hyphens in unicodeToASCII Jul 17, 2026
@garydgregory
garydgregory merged commit ee9bf32 into apache:master Jul 17, 2026
10 checks passed
@garydgregory garydgregory changed the title Reject leading and trailing label hyphens in unicodeToASCII Reject leading and trailing label hyphens in DomainValidator unicodeToASCII Jul 17, 2026
garydgregory added a commit that referenced this pull request Jul 17, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants