Rejected forms include unsupported schemes (file:, javascript:,
data:, vbscript:, blob:, etc.), protocol-relative URLs
(//host/path), control characters, obvious HTML delimiters, empty
strings, and excessively long values.
Trailing slashes are stripped: the zarr loader appends path components
(metadata, chunks) to this string, and stripping here is what lets the
viewer accept both spellings while storing the canonical no-trailing-slash
form (see CLAUDE.md "Data Source URLs Normalize Trailing Slashes").
Validate and normalize a data-source URL from user-controlled input.
Accepted forms:
https://example.com/data.zarr/datasets/data.zarrdatasets/data.zarrRejected forms include unsupported schemes (
file:,javascript:,data:,vbscript:,blob:, etc.), protocol-relative URLs (//host/path), control characters, obvious HTML delimiters, empty strings, and excessively long values.Trailing slashes are stripped: the zarr loader appends path components (metadata, chunks) to this string, and stripping here is what lets the viewer accept both spellings while storing the canonical no-trailing-slash form (see CLAUDE.md "Data Source URLs Normalize Trailing Slashes").