Download the PHP package automattic/tracks-shared-utils without Composer
On this page you can find all versions of the php package automattic/tracks-shared-utils. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download automattic/tracks-shared-utils
More information about automattic/tracks-shared-utils
Files in automattic/tracks-shared-utils
Package tracks-shared-utils
Short Description Shared allowlist and sanitization for URLs sent to Tracks.
License GPL-2.0-or-later
Homepage https://github.com/Automattic/tracks-shared-utils
Informations about the package tracks-shared-utils
tracks-shared-utils
One shared allowlist and one sanitization algorithm for URLs sent to Tracks, published as matching JS and PHP packages.
sanitizeUrl removes query params that aren't on the allowlist, sanitizes URLs nested in param values (like redirect_to), and removes fragments and userinfo (name:extra@):
The full behavior is defined in shared/test-cases.json.
Usage
JavaScript / TypeScript
Both ESM and CommonJS builds are included, along with TypeScript types. ALLOWED_PARAMS is also exported.
PHP (7.2+)
allowed_params() is also available.
Development
Repo layout
JS
Requires Node 22.12+ (or 24+).
PHP
Requires PHP 7.2+ and Composer. Run these from the repo root:
JS/PHP parity
CI runs both ports over the same fuzzed inputs and fails on any difference. To run it locally, build the JS package first:
Changing behavior or the allowlist
- Edit
shared/url-sanitization.jsonand/or add cases toshared/test-cases.json. For a behavior change, updateSPEC.mdtoo. - If you edited the JSON, run
composer build:configand commit the regeneratedphp/generated/url-sanitization.php. - Update both ports until
npm testandcomposer testpass.
CI runs both suites on every pull request.
Releasing
The two packages share one version. Bump version in js/package.json, tag the commit vX.Y.Z, then publish:
- Composer: Packagist picks up the tag.
- npm: run
npm publishfromjs/. This runs typecheck, tests and build first.
License
GPL-2.0-or-later