Correctly match URL against domain name without killing yourself with regular expressions

By: (plus.google.com) +David Herron; Date: 2017-07-05 21:41

Tags: Node.JS » JavaScript

The Internet relies on domain names as a more user-friendly humane address mechanism than IP addresses. That means we must often write code checking if a URL is "within" domain A or domain B, and to act accordingly. You might think a regular expression is the way to go, but it has failings because while a URL looks like a text string it's actually a data structure. A domain name comparison has to recognize that it's dealing with a data structure, and to compare correctly. Otherwise a URL with domain name "loveamazon.com" might match the regular expression /amazon.com$/i and do the wrong thing.

The task in my hand is scanning website content for links to affiliate partners, make sure the links have rel=nofollow, affiliate tags, and so on. The work is being done for the (akashacms.com) AkashaCMS Affiliate Links plugin which simplifies making affiliate links in an AkashaCMS website.

I had the following loop:

let href = ... the href= attribute of the link to modify
let urlP = url.parse(href, true, true);
[
    { country: "com", domain: /amazon\.com$/i },
    { country: "ca",  domain: /amazon\.ca$/i },
    { country: "co-jp",  domain: /amazon\.co\.jp$/i },
    { country: "co-uk",  domain: /amazon\.co\.uk$/i },
    { country: "de",  domain: /amazon\.de$/i },
    { country: "es",  domain: /amazon\.es$/i },
    { country: "fr",  domain: /amazon\.fr$/i },
    { country: "it",  domain: /amazon\.it$/i }
].forEach(amazonSite => {
    let amazonCode = getAmazonAffiliateCodeForCountry(amazonSite.country);
    if (amazonSite.domain.test(urlP.hostname) && amazonCode) {
        ... operate on the link
    }
});

The code as it stands "works" to a degree. It knows a set of Amazon domains, and uses the regular expression to match against the hostname portion of the URL.

But as I noted in the introduction, this doesn't match the domain name properly. Yes, I've made sure to use the caseless modifier (i) and to escape the . characters so I'm assuredly correctly matching the domain name. But, did I prevent it from matching a domain of iloveamazon.com? Nope.

What's desired is for the match to work like a domain name match should work. While I'm sure the predominant technique for matching domain names is regular expressions, they aren't a good mechanism for matching domain names.

For example you want to match amazon.com and www.amazon.com and any other subdomain of amazon.com. One would possibly encode a more complete match in a more comprehensive regular expression ... e.g. /^amazon\.com$|.*\.amazon\.com$/i might work, or it might not though an expression like that would work. As you start accounting for more corner cases the regular expression starts to be more and more complex. You're on a slippery slope into regular expression hell, and perhaps it's necessary to take a step back and consider the situation.

Wouldn't a match expression like *.amazon.com make more sense? In other words, doesn't rewriting the above loop as so make more sense?

let href = ... the href= attribute of the link to modify
let urlP = url.parse(href, true, true);
[
    { country: "com", domain: '*.amazon.com' },
    { country: "ca",  domain: '*.amazon.ca' },
    { country: "co-jp",  domain: '*.amazon.co.jp' },
    { country: "co-uk",  domain: '*.amazon.co.uk' },
    { country: "de",  domain: '*.amazon.de' },
    { country: "es",  domain: '*.amazon.es' },
    { country: "fr",  domain: '*.amazon.fr' },
    { country: "it",  domain: '*.amazon.it' }
].forEach(amazonSite => {
    let amazonCode = getAmazonAffiliateCodeForCountry(amazonSite.country);
    if (domainMatch(amazonSite.domain, href) && amazonCode) {
        ... operate on the link
    }
});

The question is where to get the domainMatch function.

Try: (www.npmjs.com) https://www.npmjs.com/package/domain-match

USAGE is as above, or:

var domainMatch = require('domain-match');
var matched = domainMatch('*.abc.com/prefix/path', 'http://www.abc.com/prefix/path/filename.ext');
// matched == true

In other words, you don't even have to parse the URL, the domainMatch function does it for you. But more importantly, it does domain name matching the way it's supposed to be done. The matching expression in this case is simple and straight-forward and natural to the task of matching domain names.

$ node
> const domainMatch = require('domain-match');
undefined
> domainMatch('*.abc.com/prefix/path', 'http://www.abc.com/prefix/path/filename.ext');
true
> domainMatch('*.abc.com/prefix/path', 'http://www.abc.com/prefix2/path/filename.ext');
false

Even more interesting is it matches not just the domain name but the other parts of the URL. In this case changing prefix to prefix2 caused the URL comparison to not match.

A related package

The domain-match package is what came up first in my search on npmjs.com. Another package popped up in a broader search:

It's curious why domain-match is so thinly used, and why aren't there more packages of this sort? Or does everyone just use regular expressions or even worse simple string comparison?

« Node.js team adopts the Contributor Code of Conduct, fostering a welcoming environment for contributors In JavaScript (Node.js), how do I read a text file from a different directory and store into a string? »
2016 Election Acer C720 Ad block AkashaCMS Amazon Amazon Kindle Amazon Web Services America Amiga and Jon Pertwee Android Anti-Fascism AntiVirus Software Apple Apple Hardware History Apple iPhone Apple iPhone Hardware April 1st Arduino ARM Compilation Artificial Intelligence Astronomy Astrophotography Asynchronous Programming Authoritarianism Automated Social Posting AWS DynamoDB AWS Lambda Ayo.JS Bells Law Big Brother Big Finish Bitcoin Mining Black Holes Blade Runner Blockchain Blogger Blogging Books Botnets Cassette Tapes Cellphones China China Manufacturing Christopher Eccleston Chrome Chrome Apps Chromebook Chromebox ChromeOS CIA CitiCards Citizen Journalism Civil Liberties Clinton Cluster Computing Command Line Tools Comment Systems Computer Accessories Computer Hardware Computer Repair Computers Cross Compilation Crouton Cryptocurrency Curiosity Rover Currencies Cyber Security Cybermen Daleks Darth Vader Data backup Data Storage Database Database Backup Databases David Tenant DDoS Botnet Detect Adblocker Developers Editors Digital Photography Diskless Booting Disqus DIY DIY Repair DNP3 Do it yourself Docker Docker MAMP Docker Swarm Doctor Who Doctor Who Paradox Doctor Who Review Drobo Drupal Drupal Themes DVD E-Books E-Readers Early Computers Election Hacks Electric Bicycles Electric Vehicles Electron Emdebian Encabulators Energy Efficiency Enterprise Node EPUB ESP8266 Ethical Curation Eurovision Event Driven Asynchronous Express Face Recognition Facebook Fake News Fedora VirtualBox File transfer without iTunes FireFly Flickr Fraud Freedom of Speech Front-end Development Gallifrey git Github GitKraken Gitlab GMAIL Google Google Chrome Google Gnome Google+ Government Spying Great Britain Heat Loss Hibernate Hoax Science Home Automation HTTP Security HTTPS Human ID I2C Protocol Image Analysis Image Conversion Image Processing ImageMagick In-memory Computing InfluxDB Infrared Thermometers Insulation Internet Internet Advertising Internet Law Internet of Things Internet Policy Internet Privacy iOS Devices iPad iPhone iPhone hacking Iron Man iTunes Java JavaScript JavaScript Injection JDBC John Simms Journalism Joyent Kaspersky Labs Kindle Kindle Marketplace Lets Encrypt LibreOffice Linux Linux Hints Linux Single Board Computers Logging Mac Mini Mac OS Mac OS X Machine Learning Machine Readable ID macOS MacOS X setup Make Money Online March For Our Lives MariaDB Mars Mass Violence Matt Lucas MEADS Anti-Missile Mercurial MERN Stack Michele Gomez Micro Apartments Microsoft Military AI Military Hardware Minification Minimized CSS Minimized HTML Minimized JavaScript Missy Mobile Applications Mobile Computers MODBUS Mondas Monetary System MongoDB Mongoose Monty Python MQTT Music Player Music Streaming MySQL NanoPi Nardole NASA Net Neutrality Network Attached Storage Node Web Development Node.js Node.js Database Node.js Testing Node.JS Web Development Node.x North Korea npm NVIDIA NY Times Online advertising Online Community Online Fraud Online Journalism Online Photography Online Video Open Media Vault Open Source Open Source Governance Open Source Licenses Open Source Software OpenAPI OpenVPN Palmtop PDA Patrick Troughton Paywalls Personal Flight Peter Capaldi Phishing Photography PHP Plex Plex Media Server Political Protest Postal Service Power Control Privacy Production use Public Violence Raspberry Pi Raspberry Pi 3 Raspberry Pi Zero ReactJS Recaptcha Recycling Refurbished Computers Remote Desktop Removable Storage Republicans Retro Computing Retro-Technology Reviews RFID Right to Repair River Song Robotics Rocket Ships RSS News Readers rsync Russia Russia Troll Factory Russian Hacking Rust SCADA Scheme Science Fiction SD Cards Search Engine Ranking Season 1 Season 10 Season 11 Security Security Cameras Server-side JavaScript Serverless Framework Servers Shell Scripts Silence Simsimi Skype SmugMug Social Media Social Media Warfare Social Network Management Social Networks Software Development Space Flight Space Ship Reuse Space Ships SpaceX Spear Phishing Spring Spring Boot Spy Satellites SQLite3 SSD Drives SSD upgrade SSH SSH Key SSL Stand For Truth Strange Parts Swagger Synchronizing Files Telescopes Terrorism The Cybermen The Daleks The Master Time-Series Database Tom Baker Torchwood Total Information Awareness Trump Trump Administration Trump Campaign Twitter Ubuntu Udemy UDOO US Department of Defense Virtual Private Networks VirtualBox VLC VNC VOIP Vue.js Web Applications Web Developer Resources Web Development Web Development Tools Web Marketing Webpack Website Advertising Weeping Angels WhatsApp William Hartnell Window Insulation Windows Windows Alternatives Wordpress World Wide Web Yahoo YouTube YouTube Monetization