4 ms·
Thank you for you feedback, does adding double quotes solve the problem?
by tuxone 11y ago
Thank you for you feedback, does adding double quotes solve the problem?
- deleted 11y ago[deleted]
- Tiksi 11y agoSingle quotes would be better, you can still run into trouble with things getting parsed in double quotes. Edit: Example of this in zsh: # tiksi@layla ~ $ echo "http://example.com/uid=${thisisgone}-$(date)`pwd`\n\x00\x00nulletc\x0a" [09:38:50] http://example.com/uid=-Thu Apr 23 09:38:53 EDT 2015/home/tiksi nulletc # tiksi@layla ~ $ curl -vv -s "http://example.com/uid=${thisisgone}-$(date)`pwd`\n\x00\x00nulletc\0xb" 2>&1|egrep GET [09:47:26] > GET /uid=-Thu Apr 23 09:47:41 EDT 2015/home/tiksi\n\x00\x00nulletc\0xb HTTP/1.1
- vog 11y agoEven single quotes need some additional escaping, see my other comment: https://news.ycombinator.com/item?id=9427820 https://news.ycombinator.com/item?id=9427820
- vog 11y agoAdding double quotes is risky with regard to "`", "$" and other special shell characters. Adding single quotes is safer, but will fail if the argument itself contains single quotes. To my knowledge, the correct shell escaping is to surround your argument with single quotes, and before doing that, replace each contained single quote ' with the following sequence (1): '\'' Alternatively, you can use (2): '"'"' Both sequences work the same way: First, terminate the single-quoted string. Then, add an escaped single quote, either with backslash (1) or by encapsulating into double quotes (2). Finally, start an new single-quoted string.
- Tiksi 11y agoAs far as I know, escaping single quotes inside single quotes doesn't work in bash: tiksi@emperor:~$ curl 'http://\'test' > > > >^C tiksi@emperor:~$ curl 'http://\'test'' curl: (6) Could not resolve host: \test tiksi@emperor:~$ Anything inside single quotes is treated literally, so no escapes work.( Unless you're doing $'.stuffhere', but that's a whole other can of worms). The double quotes around single quotes does work though.
- vog 11y ago> escaping single quotes inside single quotes That's why you have to escape single quotes with '\'' rather than just \' As I said, you first have to terminate the single-quoted string, then add the single quote, then start a new single-quoted string. In your example, my variant (1) leads to: curl 'http://'\''test' And my variant (2) leads to: curl 'http://'"'"'test'
- Tiksi 11y agoAh, I misread your first post as meaning '...\'...' instead of literally '\''. I've always used the '"'"' method, or "$(sed -r 's/([allthespecialchars])/\\\1/g')" , but '\'' is much cleaner. I have found the terminate and escape quite useful for color codes though 'string'\e[31m'red'"$var"'morestring', not sure how I never thought to use it for '\'', but thats getting added to my toolbox :)