Skip to content

fix(bugs): allow mailto urls through the opener validation - #10073

Open
ManoharPaturi wants to merge 1 commit into
npm:latestfrom
ManoharPaturi:bugs-mailto-url
Open

ManoharPaturi wants to merge 1 commit into
npm:latestfrom
ManoharPaturi:bugs-mailto-url

Conversation

@ManoharPaturi

Copy link
Copy Markdown

Problem

npm bugs supports packages that only document an email address by building a mailto: url from bugs.email and passing it to openUrl (lib/commands/bugs.js). The protocol guard in openUrl only accepts http and https, so the command fails before opening anything:

$ npm bugs <pkg>    # package.json: { "bugs": { "email": "hello@example.com" } }
npm error Invalid URL: mailto:hello@example.com

The existing bugs tests mock openUrl itself, so the rejection never surfaced in the suite, and the mailto cases in those tests only assert the url is requested, never that it survives validation.

Solution

Accept mailto alongside http(s) in assertValidUrl. The scheme is inert in browsers and mail clients, unlike the scriptable schemes (javascript, data, file) the guard exists to keep away from the opener, and the explicit isFile carve out for local files is untouched.

Test Evidence

  • A unit test in test/lib/utils/open-url.js asserts a mailto: url is passed through to the opener, next to the existing tests that still reject ftp:, file: and unparseable urls.
  • An end to end regression test in test/lib/commands/bugs.js runs the real openUrl (only the process opener is mocked) for a package with bugs.email and asserts the mailto url reaches the opener.

The regression test fails on the previous code with Invalid URL: mailto:hello@example.com and passes with this change. Both files green: npx tap test/lib/utils/open-url.js test/lib/commands/bugs.js.

References

  • Documented email support in the bugs command: lib/commands/bugs.js getUrl

The bugs command turns a bugs.email manifest field into a mailto url and
hands it to openUrl, whose protocol check only accepts http and https, so
a package documenting only an email address failed with Invalid URL
instead of opening anything. The command tests mock openUrl entirely, so
the rejection never showed up in the suite.

Accept mailto alongside http and https. The scheme is inert in browsers
and mail clients, unlike the scriptable schemes the check exists to keep
away from the opener.
@ManoharPaturi
ManoharPaturi requested a review from a team as a code owner October 4, 2026 02:41
Copilot AI balanced review requested due to automatic review settings October 4, 2026 02:41

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants