In internal/cli/fetch.go, the file download URL is constructed via simple string concatenation:
fileURL:=baseURL.String()+f.Path
File paths containing spaces, #, ?, %, or other URL-special characters will produce malformed URLs, causing downloads to fail or fetch the wrong resource.
For example, a manifest entry with path my file.txt would produce URL https://example.com/dir/my file.txt (unencoded space) instead of https://example.com/dir/my%20file.txt.
The codebase already has BaseURL.JoinPath() in mfer/url.go that properly encodes paths, but it is not used in the fetch command.
Fix: Use proper URL path encoding when constructing file download URLs. Could use the existing BaseURL.JoinPath() or url.PathEscape() on individual path segments.
In `internal/cli/fetch.go`, the file download URL is constructed via simple string concatenation:
```go
fileURL := baseURL.String() + f.Path
```
File paths containing spaces, `#`, `?`, `%`, or other URL-special characters will produce malformed URLs, causing downloads to fail or fetch the wrong resource.
For example, a manifest entry with path `my file.txt` would produce URL `https://example.com/dir/my file.txt` (unencoded space) instead of `https://example.com/dir/my%20file.txt`.
The codebase already has `BaseURL.JoinPath()` in `mfer/url.go` that properly encodes paths, but it is not used in the fetch command.
**Fix:** Use proper URL path encoding when constructing file download URLs. Could use the existing `BaseURL.JoinPath()` or `url.PathEscape()` on individual path segments.
clawbot
self-assigned this 2026-02-08 21:01:31 +01:00
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
In
internal/cli/fetch.go, the file download URL is constructed via simple string concatenation:File paths containing spaces,
#,?,%, or other URL-special characters will produce malformed URLs, causing downloads to fail or fetch the wrong resource.For example, a manifest entry with path
my file.txtwould produce URLhttps://example.com/dir/my file.txt(unencoded space) instead ofhttps://example.com/dir/my%20file.txt.The codebase already has
BaseURL.JoinPath()inmfer/url.gothat properly encodes paths, but it is not used in the fetch command.Fix: Use proper URL path encoding when constructing file download URLs. Could use the existing
BaseURL.JoinPath()orurl.PathEscape()on individual path segments.