Axle v0.14.1
Package

std/text/escape

std/escape — string escaping for output contexts, in pure Axle.

One escape function per context, each a single byte-level pass over
the input (no compiled regex / DFA, just a per-byte branch). The
special characters are all ASCII, so any byte ≥ 128 — a UTF-8 lead
or continuation byte — passes through verbatim and multi-byte
sequences stay byte-exact.

The contexts covered are the ones with the highest security-bug
rate:

• HTML body / attribute (XSS)
• shell argument (command injection)
• SQL string literal (SQLi — escape only; NOT a substitute for
prepared statements)

The structural ASCII bytes are named in each function (module-level
const is unsupported) so the branches read in characters, not
decimals.

Free functions

TypeMethod and description
bool
__rangeEquals(s : string, start : i64, len : i64, lit : string) : bool true if the len bytes of s starting at start equal the bytes
of the ASCII literal lit.
i64
__numericEntity(s : string, start : i64, len : i64) : i64 Decode a numeric character reference body (the bytes after &#,
len of them starting at start) to a Unicode scalar value. A
leading x/X selects hex, otherwise decimal. Returns -1 when the
body is empty, holds a non-digit, or yields a value that is not a
valid scalar (a UTF-16 surrogate or above U+10FFFF) — the caller
then emits the reference verbatim, matching the native behaviour.
string
htmlEscape(s : string) : string Escape body content / double-quoted attributes: & → &,
< → &lt;, > → &gt;, " → &quot;, ' → &#39;. Every
other byte is copied unchanged.
string
htmlAttrEscape(s : string) : string Looser attribute escaping. Escaping both quote styles is the safe
default, so this is the same transform as [htmlEscape].
string
htmlUnescape(s : string) : string Inverse of [htmlEscape], plus the general named references
(&amp; / &lt; / &gt; / &quot; / &apos;) and numeric
references (&#NN; decimal, &#xHH; hex). An unterminated or
unrecognised reference is copied through verbatim.
string
shellQuotePosix(s : string) : string POSIX shell quoting: wrap in single quotes and rewrite each inner
' as '\'' (close-quote, escaped quote, reopen-quote).
string
shellQuoteWindows(s : string) : string cmd.exe quoting: wrap in double quotes and double each inner ".
The conservative form (no special handling of \-runs) — enough for
the common case of arguments without embedded backslash sequences.
string
sqlEscapeLiteral(s : string) : string Escape a SQL string-literal body by doubling each ' → ''. This
escapes the literal only; it is NOT a substitute for prepared
statements.

Method detail

#__rangeEquals

__rangeEquals(s : string, start : i64, len : i64, lit : string) : bool

true if the len bytes of s starting at start equal the bytes
of the ASCII literal lit.

Parameters
s string holding the candidate entity-name bytes
start byte offset where the candidate range begins
len length of the candidate range to match
lit ASCII entity name to compare against (e.g. "amp")

#__numericEntity

__numericEntity(s : string, start : i64, len : i64) : i64

Decode a numeric character reference body (the bytes after &#,
len of them starting at start) to a Unicode scalar value. A
leading x/X selects hex, otherwise decimal. Returns -1 when the
body is empty, holds a non-digit, or yields a value that is not a
valid scalar (a UTF-16 surrogate or above U+10FFFF) — the caller
then emits the reference verbatim, matching the native behaviour.

Parameters
s string holding the numeric-reference body
start byte offset of the first digit (after &#)
len number of body bytes (the digits, plus a leading x/X)

#htmlEscape

htmlEscape(s : string) : string

Escape body content / double-quoted attributes: & → &amp;,
< → &lt;, > → &gt;, " → &quot;, ' → &#39;. Every
other byte is copied unchanged.

Parameters
s untrusted text to escape for an HTML body / attribute

#htmlAttrEscape

htmlAttrEscape(s : string) : string

Looser attribute escaping. Escaping both quote styles is the safe
default, so this is the same transform as [htmlEscape].

Parameters
s untrusted text to escape for an HTML attribute value

#htmlUnescape

htmlUnescape(s : string) : string

Inverse of [htmlEscape], plus the general named references
(&amp; / &lt; / &gt; / &quot; / &apos;) and numeric
references (&#NN; decimal, &#xHH; hex). An unterminated or
unrecognised reference is copied through verbatim.

Parameters
s HTML-escaped text whose entity references to decode

#shellQuotePosix

shellQuotePosix(s : string) : string

POSIX shell quoting: wrap in single quotes and rewrite each inner
' as '\'' (close-quote, escaped quote, reopen-quote).

Parameters
s argument to quote safely for a POSIX shell

#shellQuoteWindows

shellQuoteWindows(s : string) : string

cmd.exe quoting: wrap in double quotes and double each inner ".
The conservative form (no special handling of \-runs) — enough for
the common case of arguments without embedded backslash sequences.

Parameters
s argument to quote for cmd.exe

#sqlEscapeLiteral

sqlEscapeLiteral(s : string) : string

Escape a SQL string-literal body by doubling each ' → ''. This
escapes the literal only; it is NOT a substitute for prepared
statements.

Parameters
s string-literal body whose ' quotes to double