Skip to content

fix: accept underscores in domain hostnames for API URL validation - #10663

Merged
andrasbacsai merged 3 commits into
coollabsio:nextfrom
Osamaali313:fix/url-validator-underscore-hostnames
Jul 7, 2026
Merged

andrasbacsai merged 3 commits into
coollabsio:nextfrom
Osamaali313:fix/url-validator-underscore-hostnames

Conversation

@Osamaali313

Copy link
Copy Markdown
Contributor

Changes

PHP's FILTER_VALIDATE_URL rejects underscores in the host portion of a URL, so a service domain such as https://myapp_service.example.com was rejected with "Invalid URL" by the API. The domain could not be saved, Traefik never generated config for it, and the service fell back to a self-signed certificate instead of requesting Let's Encrypt, leaving it unreachable over HTTPS. Underscores are accepted by browsers and Let's Encrypt and are common in Docker service naming.

This adds a small isValidDomainUrl() helper in bootstrap/helpers/domains.php that validates the URL after replacing underscores with hyphens (a valid host character), and routes the docker_compose_domains and fqdn/domain validation in the Applications and Services API controllers through it. URLs without underscores are unaffected, and the existing http/https scheme checks are left unchanged.

Issues

Category

  • Bug fix
  • Improvement
  • New feature
  • Adding new one click service
  • Fixing or updating existing one click service

Preview

Not applicable — backend API/validation change, no UI. Behaviour change: a PATCH to /api/v1/applications/{uuid} with a domain containing an underscore is now accepted instead of returning an "Invalid URL" validation error.

AI Assistance

  • AI was NOT used to create this PR
  • AI was used (please describe below)

If AI was used:

  • Tools used:
  • How extensively:

Testing

Validated with unit tests in tests/Unit/IsValidDomainUrlTest.php covering underscore hostnames, ordinary domains/URLs, and invalid inputs; these run as part of the existing Pest suite in CI. Also verified on a local development instance: a service domain containing an underscore now saves successfully instead of being rejected with "Invalid URL". Underscore-free URLs are unaffected.

Contributor Agreement

Important

  • I have read and understood the contributor guidelines. If I have failed to follow any guideline, I understand that this PR may be closed without review.
  • I have searched existing issues and pull requests (including closed ones) to ensure this isn't a duplicate.
  • I have tested all the changes thoroughly with a local development instance of Coolify and I am confident that they will work as expected when a maintainer tests them.

PHP's FILTER_VALIDATE_URL rejects underscores in the host, so domains
like https://myapp_service.example.com were rejected by the API and
never got a Let's Encrypt certificate. Add an isValidDomainUrl() helper
that validates a copy with underscores replaced by hyphens, and route
domain validation in the Applications and Services API controllers
through it.

Fixes coollabsio#10597
Copilot AI review requested due to automatic review settings June 13, 2026 20:11

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Note

Copilot was unable to run its full agentic suite in this review.

Adds a centralized URL validator that tolerates underscores in hostnames, and updates API controllers to use it while introducing unit coverage for the underscore regression.

Changes:

  • Introduced isValidDomainUrl() helper to validate URLs while allowing underscores in the hostname.
  • Replaced direct FILTER_VALIDATE_URL checks in Services/Applications controllers with the new helper.
  • Added unit tests covering underscore-host URLs, normal URLs, and invalid inputs.

Reviewed changes

Copilot reviewed 4 out of 4 changed files in this pull request and generated 4 comments.

File Description
tests/Unit/IsValidDomainUrlTest.php Adds regression/unit tests for underscore-host URL validation.
bootstrap/helpers/domains.php Introduces isValidDomainUrl() helper used across controllers.
app/Http/Controllers/Api/ServicesController.php Switches URL validation to isValidDomainUrl().
app/Http/Controllers/Api/ApplicationsController.php Switches multiple URL validation call sites to isValidDomainUrl().

Comment thread bootstrap/helpers/domains.php
Comment thread bootstrap/helpers/domains.php
Comment thread bootstrap/helpers/domains.php Outdated
Comment thread tests/Unit/IsValidDomainUrlTest.php
@andrasbacsai

Copy link
Copy Markdown
Member

Thank you for the PR! 💜

@andrasbacsai
andrasbacsai merged commit f3ca349 into coollabsio:next Jul 7, 2026
1 check passed
@andrasbacsai andrasbacsai mentioned this pull request Jul 14, 2026
@github-actions github-actions Bot locked as resolved and limited conversation to collaborators Aug 13, 2026
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants