Skip to content

fix(repos): escape the path in create_or_update_file - #3429

Open
jayhemnani9910 wants to merge 1 commit into
github:mainfrom
jayhemnani9910:fix/create-file-path-escaping
Open

jayhemnani9910 wants to merge 1 commit into
github:mainfrom
jayhemnani9910:fix/create-file-path-escaping

Conversation

@jayhemnani9910

Copy link
Copy Markdown

Summary

create_or_update_file sent the file path into the request URL unescaped, so a path with # or ? was cut there and the content was written to a different file. The path is now escaped segment by segment before the write.

Why

Fixes #3427

go-github's CreateFile puts path into the URL as is, while GetContents (used for the existence, SHA and symlink checks) escapes it. So docs/C#/intro.md was checked as the right file but written as docs/C.

What changed

  • CreateOrUpdateFile passes escapeGitTreeish(path) to CreateFile.
  • New test Test_CreateOrUpdateFile_EscapesPath: writes docs/C#/intro?.md and checks the PUT goes to .../contents/docs/C%23/intro%3F.md. Without the change the PUT goes to .../contents/docs/C.

MCP impact

  • No tool or API changes
  • Tool schema or behavior changed
    Paths with #, ? or % are written to the file that was asked for. No schema change.
  • New tool added

Prompts tested (tool changes only)

  • Not run against the live API (it would need a write to a real repository); covered by the mock test above.

Security / limits

  • No security or limits impact
  • Auth / permissions considered
  • Data exposure, filtering, or token/size limits considered

Tool renaming

  • I am renaming tools as part of this PR (e.g. a part of a consolidation effort)
    • I have added the new tool aliases in deprecated_tool_aliases.go
  • I am not renaming tools as part of this PR

Lint & tests

  • Linted locally (golangci-lint v2.14.0, the version ./script/lint pins: 0 issues)
  • Tested locally with go test ./...

Docs

  • Not needed
  • Updated (README / docs / examples)

A path containing # or ? was sent unescaped, so the file was written to
the part of the path before that character (docs/C#/intro.md -> docs/C).
Copilot AI balanced review requested due to automatic review settings October 6, 2026 12:42
@jayhemnani9910
jayhemnani9910 requested a review from a team as a code owner October 6, 2026 12:42

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot was unable to review this pull request because the user who requested the review has reached their quota limit.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

create_or_update_file writes to the wrong file when the path contains # or ?

2 participants