Skip to content

Single quotes in content, headers, or parameters produce unexecutable curl and HTTPie snippets #1055

Description

@hunseonglee

CurlRequestSnippet and HttpieRequestSnippet interpolate raw values into single-quoted shell strings without any escaping — request body content, header values, basic-auth credentials, cookies, form parameters, multipart part content and file names, and the URI itself.

A body containing a single quote, e.g. {"name": "O'Brien"}, produces:

$ curl 'http://localhost/foo' -i -X POST -d '{"name": "O'Brien"}'

which has an unterminated quote — pasting the documented command into a shell fails (or worse, executes something unintended). The same applies to the HTTPie snippet (echo '...' | http ...).

Reproduced on main (3ec9c63, 4.0.2-SNAPSHOT).

Expected: values interpolated into single-quoted shell strings use the standard POSIX escape (' → '\\''), so the documented commands are executable verbatim. I will submit a PR with a fix and tests.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions