ASKMECODE

The Encoding and Escaping Kit

Move data through text without surprises: size Base64 in bytes before it hits a cookie, header or URL limit, decide when not to use it, pick the alphabet a URL survives, escape each value once for the place it lands, and stop trusting an encoding or a fast hash to keep a secret

AskMeCode's Base64 Converter encodes and decodes one value, the JSON Formatter lays out one payload and the Hash Generator fingerprints one string. A system asks different questions: how big a value is once it is encoded, whether it still fits the cookie, header or URL it has to pass through, which alphabet survives a query string, what it must become when it lands in HTML, JSON, SQL or a shell, and whether the thing protecting it is protection at all. The Encoding and Escaping Kit works those questions with the same code the tools run. A JWT whose claims are 107 bytes of JSON is 224 characters long, and a 4,048-character cookie value holds claims of 2,975 bytes, not 4,048. A random 18-byte token in standard Base64 put in a query string comes back from the parser with a space where its + was, and decodes, without an error, to 17 bytes. Gzip takes a data URI's overhead on the wire back to 1.7%, but a Base64 column keeps all 33%. One string is escaped for HTML text, an HTML attribute, JSON, a URL and a regex side by side, and the kit shows why SQL and shell commands take bound parameters and argument arrays instead. Every figure is computed by code and every limit and rule is quoted from its source: RFC 4648, 2045, 7515, 8259, 6265 and 9110, the URL Standard, the nginx documentation and the OWASP cheat sheets on password storage, SQL injection and cross-site scripting. Tokens, secrets and traffic numbers are examples; it is not a security review. Included: 7 steps, a payload size sheet, a boundary map, a test vector card for your own test suite, a protection audit, a size reference and a quickstart, plus a personalised sheet worked from the sizes the Base64 Converter and JSON Formatter publish (never your text).

Look inside

Two full pages from the kit, exactly as printed. Click either to read it at full size before you decide.

The full contents of The Encoding and Escaping Kit: size it, place it, and the working pagesStep 1, The Byte Rule: characters, string length and UTF-8 bytes for six strings, their Base64, and where btoa throws or silently encodes Latin-1

What is in it

$15.00one-time · no subscription
Get the kit: $15.00

Price includes any taxes. Sold by GrabURL, who handle checkout and support. The charge appears on your statement as GrabURL.

The kit picks up where the free Base64 Converter leaves off. The converter encodes and decodes one value and tells you its size in bytes and characters. The kit works out what that size means for a system: the cookie, header and URL limits a token has to pass, when a data URI or a Base64 column costs more than the file, which alphabet survives a query string, and how one value is escaped for HTML, JSON, URLs, regex, SQL and the shell. It uses the JSON Formatter for the number boundary and the Hash Generator to show why encoding and fast hashes protect nothing. Every token, secret and traffic figure in it is an example; the limits are quoted from the RFCs and documentation they come from, and your own stack's documentation is the final word. It is not a security review, and no outcome is promised.