People paste profile links from chats, browsers, and share sheets. Those links can carry query parameters that are irrelevant to identifying the account. A small parser should extract a handle from the profile path, reject unrelated hosts, and leave the original URL out of the lookup key.
I built TikStories to accept a public TikTok handle or profile URL and show currently active public Stories. The example below is a standalone parsing exercise, not a copy of the site's internal code. It deliberately handles ordinary profile URLs rather than every redirect or link format TikTok may issue.
Parse the host and path
function profileHandle(input) {
const value = input.trim();
if (!value.includes('/')) {
const handle = value.replace(/^@/, '');
return /^[A-Za-z0-9._]+$/.test(handle) ? handle : null;
}
let url;
try {
url = new URL(value);
} catch {
return null;
}
if (url.protocol !== 'https:') return null;
if (!['tiktok.com', 'www.tiktok.com', 'm.tiktok.com'].includes(url.hostname)) {
return null;
}
const match = /^\/@([A-Za-z0-9._]+)\/?$/.exec(url.pathname);
return match ? match[1] : null;
}
The hostname check is exact. A string like tiktok.com.example.org does not pass merely because it contains tiktok.com. The path pattern also avoids treating a video URL or unrelated page as an account profile. new URL() separates the query string, so tracking parameters never enter the returned handle.
Try the cases that matter
const cases = [
['@example.creator', 'example.creator'],
['https://www.tiktok.com/@example.creator?lang=en&share_id=123', 'example.creator'],
['https://m.tiktok.com/@example.creator/', 'example.creator'],
['https://tiktok.com.example.org/@example.creator', null],
['https://www.tiktok.com/@example.creator/video/123', null],
['not a handle', null],
];
for (const [input, expected] of cases) {
const actual = profileHandle(input);
if (actual !== expected) throw new Error(`${input}: ${actual} !== ${expected}`);
}
This approach does not resolve shortened links or prove that a handle exists. After parsing, the application still needs to look up the public account and handle empty results honestly. A private profile cannot be made public by changing the URL. If a product accepts more URL forms, add them as explicit cases with tests rather than weakening the host check.
Top comments (0)