# safe-decode-uri-component

> Safely decode URI components, leaving invalid sequences as they are

Latest version **1.2.2-native** (published 2023-10-26) · MIT license · 0 weekly downloads

## Install

```sh
npm install safe-decode-uri-component
pnpm add safe-decode-uri-component
yarn add safe-decode-uri-component
bun add safe-decode-uri-component
```

## Health

**Score 15/100 (F)** — status: abandoned.

Positive: no vulnerabilities.

Warnings: low downloads; no types; no esm support.

Negative: abandoned; low maintenance score.

## Facts

| | |
|---|---|
| Version | 1.2.2-native |
| Published | 2023-10-26 |
| First published | 2017-10-26 |
| Weekly downloads | 0 |
| License | MIT |
| TypeScript types | none |
| Module format | CommonJS |
| Node | >=8.6.0 |
| Dependencies | 3 |
| Unpacked size | 67.5 KB |
| Known vulnerabilities | 0 |
| Install scripts | yes |
| GitHub stars | 7 |
| Author | Justin Ridgewell |
| Maintainers | jridgewell |
| Keywords | decode, uri, component |

## Links

- npm: https://www.npmjs.com/package/safe-decode-uri-component
- Repository: https://github.com/jridgewell/safe-decode-uri-component
- Homepage: https://github.com/jridgewell/safe-decode-uri-component#readme
- Issues: https://github.com/jridgewell/safe-decode-uri-component/issues
- npm.io page: https://npm.io/package/safe-decode-uri-component

## Dependencies (3)

- [bindings](https://npm.io/package/bindings.md) 1.5.0
- [node-gyp](https://npm.io/package/node-gyp.md) 9.4.0
- [prebuild-install](https://npm.io/package/prebuild-install.md) 7.1.1

## Alternatives

- [flatbuffers](https://npm.io/package/flatbuffers.md) — 6.0M weekly downloads
- [jwt-simple](https://npm.io/package/jwt-simple.md) — 259.5K weekly downloads
- [@exodus/patch-broken-hermes-typed-arrays](https://npm.io/package/@exodus/patch-broken-hermes-typed-arrays.md) — 28.5K weekly downloads
- [@native-to-anchor/buffer-layout](https://npm.io/package/@native-to-anchor/buffer-layout.md) — 12.2K weekly downloads
- [binary-parser-encoder](https://npm.io/package/binary-parser-encoder.md) — 5.3K weekly downloads

## Recent versions

- 1.2.2-native (latest) — 2023-10-26
- 1.1.3-native (native) — 2017-11-01
- 1.0.0-n-api (n-api) — 2017-10-26
- 1.2.1 — 2019-06-27
- 1.2.1-native — 2019-06-25
- 1.2.0-native — 2019-06-25
- 1.1.4-native — 2019-05-12
- 1.1.3 — 2017-11-01
- 1.1.1-native — 2017-11-01
- 1.1.1 — 2017-11-01
- 1.1.0 — 2017-11-01
- 1.0.1 — 2017-10-26
- 1.0.0-native — 2017-10-26

## README

# safe-decode-uri-component

[![Build Status](https://travis-ci.org/jridgewell/safe-decode-uri-component.svg?branch=master)](https://travis-ci.org/jridgewell/safe-decode-uri-component)

Decodes strings that were encoded by `encodeURI` and
`encodeURIComponent`, without throwing errors on invalid escapes.

```js
const base = "http://github.com";
const query = `?value=${encodeURIComponent('test ⚡')}`;

let url = base + query; // => "http://github.com?value=test%20%E2%9A%A1"

// Now, something happens and the url gets truncated:
// url = "http://github.com?value=test%20%E2%9A%A"

decodeURIComponent(url); // THROWS ERROR
```

Truncating "useless" characters from a URL happens for any number of
reasons.  Or, maybe your user just typed in a bad URL? Either way, it's
annoying when all you want is the decoded value, treating invalid
escapes as if they were just regular characters.


```js
const decode = require('safe-decode-uri-component');

decode(url); // => "http://github.com?value=test %E2%9A%A"
```

Notice that `%20` was decoded to a space, and the invalid sequence
`%E2%9A%A` remains. This is exactly like `decodeURIComponent`, except we
don't balk at an invalid sequence.

```js
decode("value=test%20%E2%9A%A1"); // => "value=test ⚡"
decode("value=test%20%E2%9A%A");  // => "value=test %E2%9A%A"
decode("value=test%20%E2%9A%");   // => "value=test %E2%9A%"
decode("value=test%20%E2%9A");    // => "value=test %E2%9A"
decode("value=test%20%E2%9");     // => "value=test %E2%9"
decode("value=test%20%E2%");      // => "value=test %E2%"
decode("value=test%20%E2");       // => "value=test %E2"
decode("value=test%20%E");        // => "value=test %E"
decode("value=test%20%");         // => "value=test %"
decode("value=test%20");          // => "value=test "
decode("value=test%2");           // => "value=test%2"
decode("value=test%");            // => "value=test%"
decode("value=test");             // => "value=test"
```

## Installation

```bash
npm install --save safe-decode-uri-component
```

## Node.js

We also provide a native Node.js module, available as the `native` tag:

```bash
npm install --save safe-decode-uri-component@native
```

It's way faster, faster than even native `decodeURIComponent`.

```
$ npm run benchmark

Short String (native) x 1,448,425 ops/sec ±0.97% (85 runs sampled)
Short String (safe) x 3,449,002 ops/sec ±0.73% (88 runs sampled)
Fastest is Short String (safe)

Medium String (native) x 18,491 ops/sec ±0.84% (90 runs sampled)
Medium String (safe) x 22,695 ops/sec ±0.81% (88 runs sampled)
Fastest is Medium String (safe)

Long String (native) x 33.56 ops/sec ±1.01% (58 runs sampled)
Long String (safe) x 41.83 ops/sec ±0.73% (54 runs sampled)
Fastest is Long String (safe)
```

---
_Source: https://npm.io/package/safe-decode-uri-component · Machine-readable twin of the npm.io package page. Health data is recomputed on every publish._
