📎 Webclip
That string concatenation frisson
The page warns that concatenating strings with a delimiter like : can be unsafe when the result is used as an identifier or later split back into parts. Different input pairs can produce the same combined string, and a split cannot always recover the original values.
It says this becomes especially risky when one field may be used to inject a value such as horse:admin. If colons are unavoidable, the text recommends either sending the values separately or using a rigorous escaping and unescaping procedure.
Reading notes#
- Concatenating
applicationandendpointwith:can create collisions such asa:bpluscmatchingaplusb:c. - If the combined string must be split later, the original two strings may no longer be recoverable.
- This is presented as especially worrying for fields like
usernameandrole, where an injected colon can change meaning. - If colons must be allowed, the text advises sending the values separately.
- If concatenation is still used, the delimiter needs proper escaping before joining and unescaping afterward.
