Skip to content

Commit 157cfde

Browse files
styflenodejs-github-bot
authored andcommitted
doc: provide alternative to url.parse() using WHATWG URL
PR-URL: #59736 Reviewed-By: Yagiz Nizipli <yagiz@nizipli.com> Reviewed-By: Rich Trott <rtrott@gmail.com> Reviewed-By: Gerhard Stöbich <deb2001-github@yahoo.de> Reviewed-By: Trivikram Kamat <trivikr.dev@gmail.com>
1 parent ce72fcc commit 157cfde

File tree

1 file changed

+9
-1
lines changed

1 file changed

+9
-1
lines changed

doc/api/url.md

Lines changed: 9 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1847,7 +1847,15 @@ A `URIError` is thrown if the `auth` property is present but cannot be decoded.
18471847
strings. It is prone to security issues such as [host name spoofing][]
18481848
and incorrect handling of usernames and passwords. Do not use with untrusted
18491849
input. CVEs are not issued for `url.parse()` vulnerabilities. Use the
1850-
[WHATWG URL][] API instead.
1850+
[WHATWG URL][] API instead, for example:
1851+
1852+
```js
1853+
function getURL(req) {
1854+
const proto = req.headers['x-forwarded-proto'] || 'https';
1855+
const host = req.headers['x-forwarded-host'] || req.headers.host || 'example.com';
1856+
return new URL(req.url || '/', `${proto}://${host}`);
1857+
}
1858+
```
18511859
18521860
### `url.resolve(from, to)`
18531861

0 commit comments

Comments
 (0)