Filing gate ①, class (a). This is a defect at a named producer, with reach: measured at a public door: the console's share-link landing page (/s/TOKEN), which sends the password in this header since PR objectstack-ai/objectui#11757 (objectui#11649).
Reader: the objectstack-wide triage seat's first touch. It grades the card and routes it, and decides the producer's encoding plus whether a console mint-time guard is wanted meanwhile.
Dedupe: mcp__github__search_issues in objectstack-ai/objectstack, closed included. Two queries ("X-Share-Password header encoding non-Latin-1 share link password ISO-8859-1 charset" and "share link password header presentedPassword unicode emoji CJK password cannot be sent") returned 1 hit each, the same one: #21839 (closed completed). That is this header's parent, the positive control. It moved the password into the header but declared no encoding.
What happens
-
The header carries no declared encoding. At the 17.7.0 tag 4e4e881427, both producers read the password from X-Share-Password as it arrives:
plugin-sharing's presentedPassword;
- the runtime dispatcher's share-links domain, through
headerOf('x-share-password').
Neither declares an encoding, and neither decodes one.
-
A browser cannot send every password the server mints. The Fetch standard's Headers refuses a value with a character above U+00FF. It throws a TypeError before the request leaves.
- This was measured in Chromium for objectui#11649: a CJK or emoji password throws, and
café goes through.
- Node's
Headers also strips leading and trailing whitespace from the value.
-
Such passwords are mintable. createLink (plugin-sharing share-link service) hashes any string, and the console's ShareDialog sends any string, trimmed.
-
The result. A link whose password has a character above U+00FF can no longer be opened from the console. Such links opened through the old ?password= query parameter, which the server still reads, and reads first, for older clients. objectui#11757 does not fall back to the URL: the security ruling on objectui#11649 forbids it. The page says the password cannot be sent, instead of surfacing the TypeError.
Done when
- The header declares one encoding that both producers decode, for example percent-encoded UTF-8, named in the producer's docs. A password with any character the minting doors accept can then be presented from a browser.
- The console encodes once the server decodes. That half follows from this card, in objectui.
- Pins: a CJK password and an emoji password each resolve through the header, on both public routes (
/resolve and /messages). A Latin-1 password keeps resolving unchanged.
Not this card: retiring the ?password= read for older clients. That is the parent's own follow-up, if wanted.
For triage, not a ruling. objectui#11649's dev recommended a console card in the meantime: ShareDialog would refuse a password the header cannot carry until the encoding exists, so no new link is minted that cannot be opened. Whether to add that guard is triage's call on this card.
Dedupe words: X-Share-Password encoding · non-Latin-1 share link password · ISO-8859-1 header value · presentedPassword · headerOf('x-share-password') · share-link password charset
Filed by the domain:ui execution seat 2 (session_01FngvPpdrnhHMdHHq6vwwju), from the open question in objectui#11649's dev report (6030103165). ⛔ Not graded or routed here; ⛔ not a claim.
Generated by Claude Code
Filing gate ①, class (a). This is a defect at a named producer, with
reach:measured at a public door: the console's share-link landing page (/s/TOKEN), which sends the password in this header since PR objectstack-ai/objectui#11757 (objectui#11649).Reader: the objectstack-wide triage seat's first touch. It grades the card and routes it, and decides the producer's encoding plus whether a console mint-time guard is wanted meanwhile.
Dedupe:
mcp__github__search_issuesin objectstack-ai/objectstack, closed included. Two queries ("X-Share-Password header encoding non-Latin-1 share link password ISO-8859-1 charset" and "share link password header presentedPassword unicode emoji CJK password cannot be sent") returned 1 hit each, the same one: #21839 (closedcompleted). That is this header's parent, the positive control. It moved the password into the header but declared no encoding.What happens
The header carries no declared encoding. At the 17.7.0 tag
4e4e881427, both producers read the password fromX-Share-Passwordas it arrives:plugin-sharing'spresentedPassword;headerOf('x-share-password').Neither declares an encoding, and neither decodes one.
A browser cannot send every password the server mints. The Fetch standard's
Headersrefuses a value with a character above U+00FF. It throws aTypeErrorbefore the request leaves.cafégoes through.Headersalso strips leading and trailing whitespace from the value.Such passwords are mintable.
createLink(plugin-sharingshare-link service) hashes any string, and the console'sShareDialogsends any string, trimmed.The result. A link whose password has a character above U+00FF can no longer be opened from the console. Such links opened through the old
?password=query parameter, which the server still reads, and reads first, for older clients. objectui#11757 does not fall back to the URL: the security ruling on objectui#11649 forbids it. The page says the password cannot be sent, instead of surfacing theTypeError.Done when
/resolveand/messages). A Latin-1 password keeps resolving unchanged.Not this card: retiring the
?password=read for older clients. That is the parent's own follow-up, if wanted.For triage, not a ruling. objectui#11649's dev recommended a console card in the meantime:
ShareDialogwould refuse a password the header cannot carry until the encoding exists, so no new link is minted that cannot be opened. Whether to add that guard is triage's call on this card.Dedupe words:
X-Share-Passwordencoding · non-Latin-1 share link password · ISO-8859-1 header value ·presentedPassword·headerOf('x-share-password')· share-link password charsetFiled by the
domain:uiexecution seat 2 (session_01FngvPpdrnhHMdHHq6vwwju), from the open question in objectui#11649's dev report (6030103165). ⛔ Not graded or routed here; ⛔ not a claim.Generated by Claude Code