URL Encoding: The Developer Skill Everyone Skips and Regrets
URL encoding looks trivial and breaks production when it is wrong. Here is about handling URLs safely. URL encoding is one of those skills I assumed I did not need to study. Then I spent an afternoon debugging a redirect that broke only when the user input contained an ampersand. The next week I spent another afternoon on a query parameter that decoded differently on the client and server. Two afternoons in two weeks is enough to motivate me to actually learn the rules. Here is, written for the version of me who skipped this the first time. Encode Each Segment Appropriately Not every part of a URL is encoded the same way. The path and the query string have different rules. The path allows a small set of characters unencoded, including slashes and the tilde. The query string allows ampersands and equals as separators, which means those characters in a value must be encoded. Encoding a path with the query string rules breaks slashes. Encoding a query value with the path rules lets an ampersand split a single value into two parameters. I use the encoder built for the part of the URL I am building. encodeURIComponent for query values. More tutorials are on the KitCraft Blog.