Socket
Book a DemoInstallSign in
Socket

querystringsafe-base64

Package Overview
Dependencies
Maintainers
2
Alerts
File Explorer

Advanced tools

Socket logo

Install Socket

Detect and block malicious and high-risk dependencies

Install

querystringsafe-base64

Encoding and decoding arbitrary strings into strings that are safe to put into a URL query param.

1.2.0
pipPyPI
Maintainers
2

.. image:: https://travis-ci.org/ClearcodeHQ/querystringsafe_base64.svg?branch=v1.2.0 :target: https://travis-ci.org/ClearcodeHQ/querystringsafe_base64 :alt: Tests

.. image:: https://coveralls.io/repos/ClearcodeHQ/querystringsafe_base64/badge.png?branch=v1.2.0 :target: https://coveralls.io/r/ClearcodeHQ/querystringsafe_base64?branch=v1.2.0 :alt: Coverage Status

Query string safe Base64

Encoding and decoding arbitrary strings into strings that are safe to put into a URL query param.

The problem

urlsafe_b64encode and urlsafe_b64decode from base64 are not enough because they leave = used for padding chars unquoted:

.. code-block:: python

import base64

base64.urlsafe_b64encode('a')
'YQ=='

And there are 2 problems with that

I. = sign gets quoted:

.. code-block:: python

import urllib

urllib.quote('=')
'%3D'

II. Some libraries tolerate the = in query string values:

.. code-block:: python

from urlparse import urlsplit, parse_qs

parse_qs(urlsplit('http://aaa.com/asa?q=AAAA=BBBB=CCCC').query)
{'q': ['AAAA=BBBB=CCCC']}

but the RFC 3986 underspecifies the query string so we cannot rely on = chars being handled by all web applications as it is done by urlparse.

Therefore we consider chars: ['+', '/', '='] unsafe and we replace them with ['-', '_', '.']. Characters + and / are already handled by urlsafe_* functions from base64 so only = is left. Since the = is used exclusively for padding, we simply remove it, and re-attach the padding during decoding. Because of that, querystringsafe_base64 is able to decode padded and unpadded string.

The solution

.. code-block:: python

import querystringsafe_base64

querystringsafe_base64.encode(b'foo-bar')
b'Zm9vLWJhcg'

querystringsafe_base64.decode(b'Zm9vLWJhcg..')
b'foo-bar'

querystringsafe_base64.decode(b'Zm9vLWJhcg')
b'foo-bar'

CHANGELOG

1.2.0

  • Remove padding characters from encoded string.

1.1.1

  • Fixed packaging

1.1.0

  • Always expect bytes
  • Add type annotations

1.0.0

  • support for restore missing padding during decode process

0.2.0

  • Support for python3

0.1.5

  • Move querystringsafe_base64 module to the root
  • Use install instead of develop during tests

0.1.4

  • Remove bdist_wheel from distributons

0.1.3

  • Install pandoc (travis)

0.1.2

  • Add setup.cfg and pypandoc to tests

0.1.1

  • add MANIFEST.in file

0.1.0

  • package structure
  • tests

FAQs

Did you know?

Socket

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Install

Related posts

SocketSocket SOC 2 Logo

Product

About

Packages

Stay in touch

Get open source security insights delivered straight into your inbox.

  • Terms
  • Privacy
  • Security

Made with ⚡️ by Socket Inc

U.S. Patent No. 12,346,443 & 12,314,394. Other pending.