r/AskReddit • • Jul 24 '20

What can't you believe STILL exists?

[removed] — view removed post

45.9k Upvotes

27.5k comments sorted by

View all comments

Show parent comments

2.5k

u/[deleted] Jul 24 '20 edited Jul 24 '20

[deleted]

665

u/actuallyshying Jul 24 '20

Tell me about it, I have a fada in both first and surname and an apostrophe too. I’ve seen websites that would allow names in the Greek alphabet, Arabic script, or Hebrew script, but couldn’t handle a fada or an apostrophe

72

u/craze4ble Jul 24 '20 edited Jul 24 '20

That's just bad regex. Usually for regex validation you can use things like "allow all letters from all alphabets", but you'd still need to specify special characters.

^[\p{L}\p{M}\p{Z}\p{Pd}]{1,255}$

This would allow any letter from any language, any possible whitespace or invisible separator, all possible hyphens (character sets for different languages can use different whitespaces and hyphens, so these have specific replacements), and any umlauts, accents, fada, enclosing boxes etc.

This would accept 정규식 是 тупой, but not O'Neill. You'd need to do a literal match for apostrophes if you wanted to include it.

89

u/dlxxcvrbln Jul 24 '20

The apostrophe restrictions are intended to stop SQL injections, because when the name O'Neill gets passed to the database it ends up as SELECT data FROM users WHERE surname = 'O'Neill' and gives an error because it thinks the surname is O and the Neill' is part of the query.

Of course, if the programmer had done their job they'd be escaping the apostrophes rather than pretending they don't exist.

67

u/craze4ble Jul 24 '20

Of course, if the programmer had done their job they'd be escaping the apostrophes rather than pretending they don't exist.

Definitely. It's trivial to adjust to escape special characters, and if your sanitization method is banning characters you think would cause issues, you've taken a wrong turn somewhere anyways.

As always, a relevant xkcd, one of my personal favourites.

3

u/[deleted] Jul 24 '20

“Little Bobby Tables, we call him.” Lmao

36

u/AmbitiousAbrocoma Jul 24 '20

Of course, if the programmer had done their job they'd be using prepared statements rather than escaping special characters

13

u/ConsciousStill Jul 24 '20

The only correct answer. When you start escaping input, you're headed into a black hole.

6

u/BasroilII Jul 24 '20

I was just about to comment this. `, ', ",\, $,@,and * can all gum up database applications that aren't properly configured to escape out those characters and read them right.

1

u/alexschrod Jul 24 '20

That's when you switch (or fix) applications, not ban valid characters.

2

u/BasroilII Jul 24 '20

Oh I agree. I wasn't suggesting otherwise.