From 9d7ad8967ba7af7e8e273655078f6c7690fd1824 Mon Sep 17 00:00:00 2001 From: Teddy Wing Date: Sun, 20 Dec 2020 03:04:28 +0100 Subject: Escape single quotes in URL On Unix, we escape the URL argument by surrounding it with single quotes. This fails if the URL contains single quotes. It also fails if the `BROWSER` command contains `%s` not surrounded by single quotes. Fix this by escaping the single quotes. We might also want to look into passing the `BROWSER` command and arguments into `exec.Command` directly instead of through `/bin/sh` and checking if that has an automatic escaping mechanism we can take advantage of. --- browserenv_unix.go | 1 - 1 file changed, 1 deletion(-) (limited to 'browserenv_unix.go') diff --git a/browserenv_unix.go b/browserenv_unix.go index e09bd10..e6416f8 100644 --- a/browserenv_unix.go +++ b/browserenv_unix.go @@ -21,6 +21,5 @@ func shell() (args []string) { // TODO func fmtBrowserCommand(browser, url string) string { // TODO: handle %s in browser command - // TODO: handle single quotes in URL return fmt.Sprintf("%s '%s'", browser, url) } -- cgit v1.2.3