Validate subdomain input to prevent a crash - #130
Merged
Conversation
A subdomain containing characters such as spaces, colons, %, or newlines makes URL(string:) return nil in Region.webBaseURL, which force-unwraps and crashes the app when opening the right-click menu links. Filter the Subdomain field to alphanumerics and hyphens so the constructed URL is always valid. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com> Claude-Session: https://claude.ai/code/session_01KvQ1BLHNVbshkwL2qTosFa
Contributor
There was a problem hiding this comment.
Pull request overview
This PR prevents a macOS app crash caused by force-unwrapping URL(string:) after interpolating an unvalidated, user-entered PagerDuty subdomain into a URL.
Changes:
- Adds live input filtering on the Settings “Subdomain” field to strip characters that can make
URL(string:)returnnil. - Introduces a shared
Constants.subdomainAllowedCharactersCharacterSet(ASCII alphanumerics +-) used by the new filter.
Reviewed changes
Copilot reviewed 2 out of 2 changed files in this pull request and generated no comments.
| File | Description |
|---|---|
| PagerCall/SettingsView.swift | Filters subdomain text as it changes so the stored value can’t contain URL-breaking characters. |
| PagerCall/Constants.swift | Defines the allowed character set for PagerDuty subdomains and documents why it exists. |
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Problem
Region.webBaseURL(subdomain:)interpolates the user-entered subdomain into a URL string and force-unwraps it:The
Subdomainfield (SettingsView) is free-form text with no validation. If it contains characters that makeURL(string:)returnnil— a space,%,:, a newline (easy to paste in accidentally) — the force-unwrap crashes the app the moment the user opens “My Incidents” / “My On-Call Shifts” from the right-click menu.Verified crashing inputs:
"foo bar"," leadingspace","%","foo:80","a\nb".Fix
Filter the
Subdomainfield to alphanumerics and hyphens (valid PagerDuty subdomain characters) via.onChange, mirroring the existing clamp on the interval field. Invalid characters are stripped as they are entered, so the constructed URL is always valid.🤖 Generated with Claude Code