3 ms·
As a security dude I spend way too much of my time fixing missing anchors or unescaped wildcards in regex. The good news is that it's trivial to detect with sta
by bink 9mo ago
As a security dude I spend way too much of my time fixing missing anchors or unescaped wildcards in regex. The good news is that it's trivial to detect with static analysis tooling. The bad news is that broken regex is often used for security checks.
- edoceo 9mo agohttps://xkcd.com/1171/ https://xkcd.com/1171/
- SkiFire13 9mo agoSometimes I wish regexes were full matches by default and required prefixing and postfixing with `.*` to get the current behaviour
- ruined 9mo agoa match isn't boolean, it's substring. the original (and more common) use-cases would become excessively verbose
- chuckadams 9mo agoJava's Pattern.match() method works that way. Python has two separate methods: re.match auto-anchors, re.search does not.