Skip to content

[pull] main from remix-run:main - #320

Merged
pull[bot] merged 4 commits into
code:mainfrom
remix-run:main
Jul 14, 2026
Merged

[pull] main from remix-run:main#320
pull[bot] merged 4 commits into
code:mainfrom
remix-run:main

Conversation

@pull

@pull pull Bot commented Jul 14, 2026

Copy link
Copy Markdown

See Commits and Changes for more details.


Created by pull[bot] (v2.0.0-alpha.4)

Can you help keep this open source service alive? 💖 Please sponsor : )

dfedoryshchev and others added 4 commits July 14, 2026 10:31
…atePath (#15310)

* fix: encode path params per RFC 3986 path-segment rules in href/generatePath

Follow-up to #15277, which fixed `href()` to URL-encode param values to
match `generatePath()`. Both now encode with `encodeURIComponent`, which
implements *query-string* escaping — a stricter rule than URL paths
require. This over-escapes characters that RFC 3986 explicitly allows
literally in a path segment:

    pchar      = unreserved / pct-encoded / sub-delims / ":" / "@"
    sub-delims = "!" / "$" / "&" / "'" / "(" / ")" / "*" / "+" / "," / ";" / "="

https://datatracker.ietf.org/doc/html/rfc3986#section-3.3

`$ & + , ; = : @` only act as delimiters in a query string; in a path
segment they carry no special meaning, and browsers keep them literal in
`location.pathname`. Encoding them needlessly rewrites URLs:

    href("/releases/:v", { v: "1.0.0+1" })
    // before: /releases/1.0.0%2B1
    // after:  /releases/1.0.0+1

which breaks apps that compare generated URLs against
`window.location.pathname` (the browser reports the literal `+`), churns
canonical/shareable URLs, and makes `href()` output disagree with what
users see in the address bar.

Changes:

- Add an internal `encodePathParam()` that escapes structural/unsafe
  characters (`/ ? # %`, whitespace, non-ASCII) exactly as before, but
  restores the RFC 3986 pchar set that `encodeURIComponent` over-escapes
- Use it for named params in `generatePath()` and for named params and
  splat segments in `href()`
- Document path-segment vs query-string encoding semantics (with the RFC
  reference) in the `href()` and `generatePath()` JSDoc
- Update and extend unit tests; add a change file

Behavior is unchanged for every character outside `$ & + , ; = : @`, and
`generatePath()`'s splat values remain un-encoded, as before.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>

* Update docs

---------

Co-authored-by: Claude Fable 5 <noreply@anthropic.com>
Co-authored-by: Matt Brophy <matt@brophy.org>
* Update docs links to v8 API reference

* Generate utility docs from JSDoc

* Remove hidden docs generation
@pull pull Bot locked and limited conversation to collaborators Jul 14, 2026
@pull pull Bot added the ⤵️ pull label Jul 14, 2026
@pull
pull Bot merged commit f75c89f into code:main Jul 14, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants