Skip to content

Use urlsafe variant of base64 #463

Description

@tmatsuo

For a historical reason, all the other samples and client libraries are using the url safe variant of base64 encode/decode.

Is it possible to use the url safe variant?

Activity

  1. stephenplusplus commented on Mar 26, 2015

    @stephenplusplus
    Contributor

    Definitely, if it's important to do that for the API. Do you have any API documentation that I can look at that advises to use url-safe?

    A quick search turned up https://github.com/RGBboy/urlsafe-base64 if we decide to implement.

  2. ryanseys commented on Mar 26, 2015

    @ryanseys
    Contributor

    Some APIs expect base64url (like Task Queues or GMail). The example for pubsub here specifically shows an example using base64 (not url variant) being encoded so that's strange. I'd hope that the url variant would still work. That being said, having a utils#base64urlencode and utils#base64decode used across the library would be great to consolidate this functionality across all libraries, regardless of what variant we use.

  3. tmatsuo commented on Mar 26, 2015

    @tmatsuo
    ContributorAuthor

    Do you have any API documentation that I can look at that advises to use url-safe?

    It's Python, but the implementation is simple (uses '-' instead of '+' and '_' instead of '/'.):

    def b64encode(s, altchars=None):
        """Encode a string using Base64.
    
        s is the string to encode.  Optional altchars must be a string of at least
        length 2 (additional characters are ignored) which specifies an
        alternative alphabet for the '+' and '/' characters.  This allows an
        application to e.g. generate url or filesystem safe Base64 strings.
    
        The encoded string is returned.
        """
        # Strip off the trailing newline
        encoded = binascii.b2a_base64(s)[:-1]
        if altchars is not None:
            return _translate(encoded, {'+': altchars[0], '/': altchars[1]})
        return encoded
    
    def urlsafe_b64encode(s):
        """Encode a string using a url-safe Base64 alphabet.
    
        s is the string to encode.  The encoded string is returned.  The alphabet
        uses '-' instead of '+' and '_' instead of '/'.
        """
        return b64encode(s, '-_')

    The example for pubsub here specifically shows an example using base64 (not url variant) being encoded so that's strange.

    Which part is showing it?

    Java library (pubsubMessage.encodeData) uses the urlsafe variant under the cover, Python uses base64.urlsafe_b64encode.

  4. ryanseys commented on Mar 26, 2015

    @ryanseys
    Contributor

    The = are removed in the url variant as well

  5. ryanseys commented on Mar 26, 2015

    @ryanseys
    Contributor

    so the data field of the example has = leading me to believe it's not the url variant

  6. tmatsuo commented on Mar 26, 2015

    @tmatsuo
    ContributorAuthor

    Aha, I found there is a discrepancy between the Java implementation and the Python implementation.

    Only the Python implementation adds the padding at the end, and I used the value from the Python's base64.urlsafe_b64encode for that protocol example.

    Then I would say, yes, please use the one that @stephenplusplus mentioned.

  7. ryanseys commented on Mar 26, 2015

    @ryanseys
    Contributor

    Oh! it's padding, cool! I didn't know that. :)

  8. tmatsuo commented on Apr 22, 2015

    @tmatsuo
    ContributorAuthor

    It turned out that, we should just use the standard Base64 variant, so I'm just going to close this bug. I'm very sorry if you've already worked on this. Please ask me for more details if you're interested in.

  9. stephenplusplus commented on Apr 22, 2015

    @stephenplusplus
    Contributor

    No problem, thanks for the update!

  10. 27 remaining items

  11. added a commit that references this issue on Feb 23, 2026
  12. added a commit that references this issue on Mar 5, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

🚨This issue needs some love.coretriage meI really want to be triaged.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions