std/text/escape
std/escape — string escaping for output contexts, in pure Axle.
One escape function per context, each a single byte-level pass over
the input (no compiled regex / DFA, just a per-byte branch). The
special characters are all ASCII, so any byte ≥ 128 — a UTF-8 lead
or continuation byte — passes through verbatim and multi-byte
sequences stay byte-exact.
The contexts covered are the ones with the highest security-bug
rate:
• HTML body / attribute (XSS)
• shell argument (command injection)
• SQL string literal (SQLi — escape only; NOT a substitute for
prepared statements)
The structural ASCII bytes are named in each function (module-levelconst is unsupported) so the branches read in characters, not
decimals.
Free functions
| Type | Method and description |
|---|---|
| __rangeEquals(s : string, start : i64, len : i64, lit : string) : bool true if the len bytes of s starting at start equal the bytesof the ASCII literal lit. |
| __numericEntity(s : string, start : i64, len : i64) : i64 Decode a numeric character reference body (the bytes after &#,len of them starting at start) to a Unicode scalar value. Aleading x/X selects hex, otherwise decimal. Returns -1 when thebody is empty, holds a non-digit, or yields a value that is not a valid scalar (a UTF-16 surrogate or above U+10FFFF) — the caller then emits the reference verbatim, matching the native behaviour. |
| htmlEscape(s : string) : string Escape body content / double-quoted attributes: & → &,< → <, > → >, " → ", ' → '. Everyother byte is copied unchanged. |
| htmlAttrEscape(s : string) : string Looser attribute escaping. Escaping both quote styles is the safe default, so this is the same transform as [ htmlEscape]. |
| htmlUnescape(s : string) : string Inverse of [htmlEscape], plus the general named references( & / < / > / " / ') and numericreferences ( &#NN; decimal, &#xHH; hex). An unterminated orunrecognised reference is copied through verbatim. |
| shellQuotePosix(s : string) : string POSIX shell quoting: wrap in single quotes and rewrite each inner' as '\'' (close-quote, escaped quote, reopen-quote). |
| shellQuoteWindows(s : string) : string cmd.exe quoting: wrap in double quotes and double each inner ".The conservative form (no special handling of \-runs) — enough forthe common case of arguments without embedded backslash sequences. |
| sqlEscapeLiteral(s : string) : string Escape a SQL string-literal body by doubling each ' → ''. Thisescapes the literal only; it is NOT a substitute for prepared statements. |
Method detail
#__rangeEquals
true if the len bytes of s starting at start equal the bytes
of the ASCII literal lit.
s string holding the candidate entity-name bytesstart byte offset where the candidate range beginslen length of the candidate range to matchlit ASCII entity name to compare against (e.g. "amp")#__numericEntity
Decode a numeric character reference body (the bytes after &#,len of them starting at start) to a Unicode scalar value. A
leading x/X selects hex, otherwise decimal. Returns -1 when the
body is empty, holds a non-digit, or yields a value that is not a
valid scalar (a UTF-16 surrogate or above U+10FFFF) — the caller
then emits the reference verbatim, matching the native behaviour.
s string holding the numeric-reference bodystart byte offset of the first digit (after &#)len number of body bytes (the digits, plus a leading x/X)#htmlEscape
Escape body content / double-quoted attributes: & → &,< → <, > → >, " → ", ' → '. Every
other byte is copied unchanged.
s untrusted text to escape for an HTML body / attribute#htmlAttrEscape
Looser attribute escaping. Escaping both quote styles is the safe
default, so this is the same transform as [htmlEscape].
s untrusted text to escape for an HTML attribute value#htmlUnescape
Inverse of [htmlEscape], plus the general named references
(& / < / > / " / ') and numeric
references (&#NN; decimal, &#xHH; hex). An unterminated or
unrecognised reference is copied through verbatim.
s HTML-escaped text whose entity references to decode#shellQuotePosix
POSIX shell quoting: wrap in single quotes and rewrite each inner' as '\'' (close-quote, escaped quote, reopen-quote).
s argument to quote safely for a POSIX shell#shellQuoteWindows
cmd.exe quoting: wrap in double quotes and double each inner ".
The conservative form (no special handling of \-runs) — enough for
the common case of arguments without embedded backslash sequences.
s argument to quote for cmd.exe#sqlEscapeLiteral
Escape a SQL string-literal body by doubling each ' → ''. This
escapes the literal only; it is NOT a substitute for prepared
statements.
s string-literal body whose ' quotes to double