fix: accept underscores in domain hostnames for API URL validation - #10663
Merged
andrasbacsai merged 3 commits intoJul 7, 2026
Merged
andrasbacsai merged 3 commits into
andrasbacsai merged 3 commits into
Conversation
PHP's FILTER_VALIDATE_URL rejects underscores in the host, so domains like https://myapp_service.example.com were rejected by the API and never got a Let's Encrypt certificate. Add an isValidDomainUrl() helper that validates a copy with underscores replaced by hyphens, and route domain validation in the Applications and Services API controllers through it. Fixes coollabsio#10597
There was a problem hiding this comment.
Pull request overview
Note
Copilot was unable to run its full agentic suite in this review.
Adds a centralized URL validator that tolerates underscores in hostnames, and updates API controllers to use it while introducing unit coverage for the underscore regression.
Changes:
- Introduced
isValidDomainUrl()helper to validate URLs while allowing underscores in the hostname. - Replaced direct
FILTER_VALIDATE_URLchecks in Services/Applications controllers with the new helper. - Added unit tests covering underscore-host URLs, normal URLs, and invalid inputs.
Reviewed changes
Copilot reviewed 4 out of 4 changed files in this pull request and generated 4 comments.
| File | Description |
|---|---|
| tests/Unit/IsValidDomainUrlTest.php | Adds regression/unit tests for underscore-host URL validation. |
| bootstrap/helpers/domains.php | Introduces isValidDomainUrl() helper used across controllers. |
| app/Http/Controllers/Api/ServicesController.php | Switches URL validation to isValidDomainUrl(). |
| app/Http/Controllers/Api/ApplicationsController.php | Switches multiple URL validation call sites to isValidDomainUrl(). |
5 of 10 tasks
Member
|
Thank you for the PR! 💜 |
Merged
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Changes
PHP's
FILTER_VALIDATE_URLrejects underscores in the host portion of a URL, so a service domain such as https://myapp_service.example.com was rejected with "Invalid URL" by the API. The domain could not be saved, Traefik never generated config for it, and the service fell back to a self-signed certificate instead of requesting Let's Encrypt, leaving it unreachable over HTTPS. Underscores are accepted by browsers and Let's Encrypt and are common in Docker service naming.This adds a small
isValidDomainUrl()helper in bootstrap/helpers/domains.php that validates the URL after replacing underscores with hyphens (a valid host character), and routes the docker_compose_domains and fqdn/domain validation in the Applications and Services API controllers through it. URLs without underscores are unaffected, and the existing http/https scheme checks are left unchanged.Issues
Category
Preview
Not applicable — backend API/validation change, no UI. Behaviour change: a PATCH to /api/v1/applications/{uuid} with a domain containing an underscore is now accepted instead of returning an "Invalid URL" validation error.
AI Assistance
If AI was used:
Testing
Validated with unit tests in tests/Unit/IsValidDomainUrlTest.php covering underscore hostnames, ordinary domains/URLs, and invalid inputs; these run as part of the existing Pest suite in CI. Also verified on a local development instance: a service domain containing an underscore now saves successfully instead of being rejected with "Invalid URL". Underscore-free URLs are unaffected.
Contributor Agreement
Important