RepoPartsFromNWO parses a raw "owner/repo" string and returns the owner and name unescaped. It returns an error unless nwo contains exactly one slash with a non-empty owner and name, so a value carrying extra slashes cannot smuggle additional path segments through as the owner or name. This intenti
(nwo string)
| 19 | // "[HOST/]OWNER/REPO" form. The call sites here only ever handle a bare "OWNER/REPO", |
| 20 | // so a stricter parse that rejects an unexpected host component is the safer fit. |
| 21 | func RepoPartsFromNWO(nwo string) (owner, name string, err error) { |
| 22 | parts := strings.Split(nwo, "/") |
| 23 | if len(parts) != 2 || parts[0] == "" || parts[1] == "" { |
| 24 | return "", "", fmt.Errorf("expected the \"OWNER/REPO\" format, got %q", nwo) |
| 25 | } |
| 26 | return parts[0], parts[1], nil |
| 27 | } |
| 28 | |
| 29 | // SafeURL is the sealed interface implemented by the URL types in this package. |
| 30 | // It exists so that a value known to address a safe REST API URL can be passed |