Chrome中链接 apostrophe 被转成%27导致无法访问的技术求助
It makes total sense that this is frustrating—Chrome's automatic URL encoding is overriding your carefully crafted parameter, breaking access to your resource. Let's break down why this happens and how to fix it:
Why the Single Quotes Are Being Encoded
Chrome automatically encodes reserved characters in URLs (like single quotes ') when you paste them, even though JavaScript's encodeURIComponent() doesn't encode single quotes (they’re in the list of allowed unencoded characters for this function). The core problem is that your server isn’t properly decoding the %27 (URL-encoded single quote) back to a literal ', leading to invalid parameter values that block access.
Recommended Fixes (Ordered by Best Practice)
1. Fix Server-Side URL Decoding
The most robust, standards-compliant solution is to update your server code to correctly decode URL-encoded characters, including converting %27 back to '. All modern server-side frameworks have built-in functions for this:
- In JavaScript/Node.js: Use
decodeURIComponent() - In Python: Use
urllib.parse.unquote() - In Java: Use
URLDecoder.decode()
This ensures your app handles URLs consistently across all browsers and aligns with RFC 3986 (the official URL specification).
2. Manually Encode Single Quotes in Client-Side Code
If modifying the server isn’t feasible right now, adjust your client-side code to explicitly encode single quotes to %27 after using encodeURIComponent(). This way, Chrome won’t re-encode them when you paste the URL:
const originalFieldValue = "<>alert('1')>"; // First encode the string normally let encodedValue = encodeURIComponent(originalFieldValue); // Replace remaining single quotes with their URL-encoded form encodedValue = encodedValue.replace(/'/g, "%27"); // Result: "%3C%3Ealert(%271%27)%3E"
When you use this encoded value in your URL, Chrome will leave the %27 intact, and your server should receive the correct parameter once decoded.
3. Switch to Double Quotes (If Server Supports It)
If your server logic accepts double quotes instead of single quotes, replace the single quotes in your original string with double quotes. encodeURIComponent() will encode double quotes to %22, which Chrome won’t modify further. Note: This only works if your server expects double quotes in the field_name parameter.
内容的提问来源于stack exchange,提问作者Cimpoeru Valentin

