3 ms·
Yes, that's essentially what I was trying to communicate. Since we are engine agnostic here be careful interpreting ^ or $ as start/end of _string_ though. In
by zwp 6y ago
Yes, that's essentially what I was trying to communicate.
Since we are engine agnostic here be careful interpreting ^ or $ as start/end of _string_ though. In some regex engines this means start/end of _line_. If that's the case and if a regex validates input up to $ an attacker might be able to sneak in extra data after a newline. In Python you'd need multiline enabled but Ruby matches by default:
irb(main):001:0> /^okay$/ =~ "okay\noops"
=> 0 # matches from position 0
(Ruby has \A and \Z for start and end of string to address this).