Skip to content

Create link_malformed_url.yml - #5251

Open
keaton-sublime wants to merge 3 commits into
mainfrom
keaton-sublime.fn.esc-24030.link_malformed
Open

Create link_malformed_url.yml#5251
keaton-sublime wants to merge 3 commits into
mainfrom
keaton-sublime.fn.esc-24030.link_malformed

Conversation

@keaton-sublime

@keaton-sublime keaton-sublime commented Sep 2, 2026

Copy link
Copy Markdown
Member

Description

Detects malformed URLs in body links.

Associated samples

Associated hunts

@keaton-sublime keaton-sublime added the in-test-rules PR is in our testing suite to collect telemetry label Sep 2, 2026
github-actions Bot added a commit that referenced this pull request Sep 2, 2026
excluding file scheme from this. Converting UNC paths to forward slashes for web links is causing FPs
github-actions Bot added a commit that referenced this pull request Sep 4, 2026
github-actions Bot added a commit that referenced this pull request Sep 4, 2026
@keaton-sublime keaton-sublime added the review-needed Indicates that a PR is waiting for review label Sep 8, 2026
@keaton-sublime
keaton-sublime marked this pull request as ready for review September 8, 2026 12:41
@keaton-sublime
keaton-sublime requested a review from a team September 8, 2026 12:41
@keaton-sublime
keaton-sublime requested a review from a team as a code owner September 8, 2026 12:41
@keaton-sublime

Copy link
Copy Markdown
Member Author

marking ready for review/review needed - telemetry is looking good and this is an ASR rule

@zoomequipd zoomequipd self-assigned this Sep 8, 2026
@zoomequipd

Copy link
Copy Markdown
Member

I did validate the behavior in the reference samples is correct. the decoded url which appears within body.links is the same as appears within the 302s when accessing the original url.

However it appears that browsers normalize the number of leading / - @keaton-sublime is going to talk to eng and see how to handle this case.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

in-test-rules PR is in our testing suite to collect telemetry review-needed Indicates that a PR is waiting for review

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants