Skip to content

ClearURLs breaks some links through URL encoding/decoding mischief #86

Description

@spencermathews

ClearURLs works almost flawlessly, but the way it processes some links from Gmail messages breaks links.

I notice this primarily when clicking links in email alerts sent by Google Job Search.

When I hover over links the URL begins with https://notifications.googleapis.com/email/redirect? (call it url A in its entirety). Copying and pasting the link into a new tab works fine.

However, clicking the link doesn't work and leads to "Error 400 (Bad Request)".

Using the log I can see that the link is processed by the "This url is redirected" rule.
Before processing, the URL starts with https://www.google.com/url?q=https://notifications.googleapis.com/email/redirect? (call this URL B).
After processing it again starts with https://notifications.googleapis.com/email/redirect? (call this URL C).

Additionally, URL B contains several query parameters that are not in URL A, namely source, ust, and usg. These also happen to be stripped in URL C. I believe these are part of Google redirection and don't seem important for function.

More notably, I'm observing some issues with the URL encoding that appear to be the problem. ClearURLs seems to be doing some sequence of encoding and decoding that breaks the URL, which seems especially fragile since it is still contains a form of redirect. The % character in many encoded characters becomes itself percent encoded in URL B. After processing, in URL C, they are completely decoded and become invalid query parameters. See https://stackoverflow.com/a/4858211 for an explanation.

For example, what is properly escaped as %3D in a working url becomes doubly encoded to %253D, which is then fully decoded into =. Similarly for &.

My best guess is that during processing the URL is decoded twice, when it should only be decoded once so that it is properly escaped. Either that or ClearURLs performs a possibly unnecessary encoding step before processing.

Activity

  1. xxKeith20xx commented on Jan 2, 2021

    @xxKeith20xx

    I get a similar 400 Response when I click on links from Twitter emails. They take me to a page:

    Something is technically wrong.
    
    Thanks for noticing—we're going to fix it up and have things back to normal soon.
    

    Console shows this response:

    HTTP/2 400 Bad Request
    cache-control: no-cache,no-store,must-revalidate
    content-encoding: gzip
    content-length: 1746
    content-type: text/html; charset=utf-8
    date: Sat, 02 Jan 2021 17:08:07 GMT
    server: tsa_b
    strict-transport-security: max-age=631138519
    x-connection-hash: b1150184e351f8572525e3b42d812368
    x-response-time: 12
    x-xss-protection: 0
    X-Firefox-Spdy: h2
    

    Tried disabling other add-ons but issue seems specific to ClearURLs

    ClearURLs 1.20.0
    Firefox 84.0.1

  2. bersbersbers commented on Mar 8, 2021

    @bersbersbers

    #100 sounds very similar and has another very short reproducible test case.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions