3 ms·
Great list. I would add - Anchor when possible (^, $)
by zwp 6y ago
Great list. I would add
- Anchor when possible (^, $)
- Y_Y 6y ago(If I understand correctly) This "(^,$)" should be parsed as a list of useful "anchor" symbols (resp. start and end of string) rather than a regexep itself. I wasted some time before I realised this.
- zwp 6y agoYes, that's essentially what I was trying to communicate. Since we are engine agnostic here be careful interpreting ^ or $ as start/end of _string_ though. In some regex engines this means start/end of _line_. If that's the case and if a regex validates input up to $ an attacker might be able to sneak in extra data after a newline. In Python you'd need multiline enabled but Ruby matches by default: irb(main):001:0> /^okay$/ =~ "okay\noops" => 0 # matches from position 0 (Ruby has \A and \Z for start and end of string to address this).