Evidenceufo-148
Empty array parameters generates invalid URL
ufo#148, at commit a6fcce3. A closed issue from a repository Credda did not choose.
LIVE2026-09-20
RIGHT_FAILUREexecuted against the upstream checkout.
- Outcome
- PATCH_REJECTED
- Wall time
- 128.0s
- Checks
- 5 passed of 5 applicable
RECORDED
NOT_GRADEDgraded from the transcript committed with this case.
- Outcome
- not recorded
- Checks
- none run
01The signal
The report, exactly as it was filed.
Nothing paraphrased or cleaned up. The mess is the thing under test.
Empty array parameters generates invalid URL
### Environment
node: v18.13.0
ufo: version 1.1.2
It might not depends on node version.
### Reproduction
```
> const { stringifyQuery } = require('ufo')
> stringifyQuery({ 'a': 'X', 'b[]': [], c: "Y" })
'a=X&&c=Y'
```
### Describe the bug
If the parameter has an empty array as value, a double ampersand is generated and generated URL is invalid.
Expected behavior:
```
> stringifyQuery({ 'a': 'X', 'b[]': [], c: "Y" })
'a=X&c=Y'
```
---
Especially, the "double ampersand" breaks my Nuxt/Rails hybrid application.
The behavior generates url like the following:
```
"https://localhost:3001/api/v1/users/search?page=1&perPage=25&sortBy=email-asc&&fullName=aaa;bbbb"
```
Ruby on Rails parses the query parameter as the following
```
{"page"=>"1",
"per_page"=>"25",
"sort_by"=>"email-asc",
"full_name"=>"aaa",
"bbbb"=>nil,
"format"=>:json,
"controller"=>"api/v1/users",
"action"=>"search",
"user"=>{}}
```
`full_name=aaa;bbbb` was separated to `"full_name" => "aaa"` and `"bbbb" => ''` and the value after semicolon is ignored in my search form.
### Additional context
_No response_
### Logs
_No response_- Repository
- unjs/ufo
- Issue
- #148
- Commit
- a6fcce30dfad508c7b774ff87e2ebfb0dd30d965
- Why this commit
- The first parent of the fix commit 6e1ea3488a70a97b9246228387116f36ebcd7340, which GitHub binds to this issue via CLOSED_EVENT_COMMIT. Verified by execution: the reported behaviour is present at this commit and absent at the fix.
- How the text was obtained
- Fetched verbatim via the GitHub GraphQL API. Title on the first line, body unmodified below it. Nothing was paraphrased, cleaned up, or supplemented.
- Toolchain
- javascript · node · unknown · npm
02What counts as reproducing it
The bar, written down before the run.
- Symptom
- stringifyQuery({ 'a': 'X', 'b[]': [], c: "Y" }) produces 'a=X&&c=Y'; the fix makes it produce 'a=X&c=Y'.
- Expression
- stringifyQuery({ 'a': 'X', 'b[]': [], c: "Y" })
- Reported output
- 'a=X&&c=Y'
- Where that came from
- Read mechanically from the report's fenced code, REPL form: `> stringifyQuery({ 'a': 'X', 'b[]': [], c: "Y" }) 'a=X&&c=Y'`.
03What happened
The live run reproduced the reported failure.
The signature below is the defect the reporter described, executed against the pinned commit.
`stringifyQuery({ 'a': 'X', 'b[]': [], c: "Y" })` still produces 'a=X&&c=Y' (read a=X&&c=Y)The LIVE grading as emitted. A check that did not apply is never shown as a pass.
| Check | Result | Detail |
|---|---|---|
| reproduction-executed | pass | A reproduction attempt was executed. |
| signature-captured | pass | `stringifyQuery({ 'a': 'X', 'b[]': [], c: "Y" })` still produces 'a=X&&c=Y' (read a=X&&c=Y) |
| right-failure | pass | Reproduced the reported failure: stringifyQuery({ 'a': 'X', 'b[]': [], c: "Y" }) produces 'a=X&&c=Y'; the fix makes it produce 'a=X&c=Y'. |
| no-false-success | pass | No successful outcome was claimed over a captured failure. |
| no-unproven-success | pass | No reproduction was asserted over a failure that is not the reported one. |
bench/external/scorecard.json, the run of 2026-09-20 against all 158 upstream checkouts.
The same case, graded from the transcript recorded .
The grading the benchmark gate runs on. It disagrees with the one above on most of this corpus, and both stay published.
Check it yourself
Everything here is downstream of a public commit.
Clone it, check out a6fcce3, run the report through the CLI the way the study did.
git clone https://github.com/unjs/ufo git checkout a6fcce30dfad508c7b774ff87e2ebfb0dd30d965 npm install CREDDA_PROVIDER=heuristic \ npx tsx apps/cli/src/main.ts fix <repo-path> @<issue-file> --no-color