Documentation
¶
Overview ¶
Package textsafe holds the one predicate for the characters that forge, reorder, or hide text: the C1 control block and the zero-width / bidi "invisible" set. It exists because the 2026-09-05 red-probe round (round 4) proved that every scrub, gate, and canonicalizer in the tree walked the C0 range and stopped there, so a C1 CSI byte or a bidi override rode through headers, log lines, storage keys, page titles, terminal transcripts, and identity canonicalizers untouched. Each sink combines its existing C0/DEL handling with the helpers here; the controlbytes and invisibleident analyzers credit a scrub only once its body reaches this set.
The set is deliberately narrow: combining marks and ordinary diacritics fall through. Only codepoints with no visible glyph of their own, whose sole effect is to rearrange or vanish the surrounding text, are named. It mirrors the list that framework/pagination first enumerated as isUnicodeInvisible.
Index ¶
Constants ¶
This section is empty.
Variables ¶
This section is empty.
Functions ¶
func ContainsInvisible ¶
ContainsInvisible reports whether s carries any invisible/bidi codepoint. Refusal-style gates use it in place of stripping.
func ContainsUnsafe ¶
ContainsUnsafe reports whether s carries any C0/DEL/C1/invisible codepoint.
func IsC1 ¶
IsC1 reports whether r is in the C1 control block (U+0080–U+009F). In UTF-8 each C1 control is a two-byte sequence >= 0x80, so a byte walker keyed on r < 0x20 never sees it; the 8-bit CSI (U+009B) and OSC (U+009D) forms drive terminal escapes exactly as ESC-[ does.
func IsInvisible ¶
IsInvisible reports whether r is a zero-width, joiner, or bidi control codepoint: no glyph of its own, present only to reorder or hide neighbouring text. Trojan-Source (the bidi overrides and isolates) and the zero-width smuggling set both live here.
func IsUnsafe ¶
IsUnsafe reports whether r is a C0 control (U+0000–U+001F), DEL (U+007F), a C1 control, or an invisible/bidi codepoint: the full set no header, key, identity, log line, title, or terminal transcript built from data should carry.
func Recovered ¶
Recovered renders a recover() value for a log sink: fmt.Sprint, then every C0/DEL/C1/invisible codepoint removed, then truncated to 4 KiB. A panic value is whatever the panicking code held at the time, which on a request path is request bytes, so it gets the same scrub a request header does before it reaches the operator's terminal.
Every in-function recover-and-log site uses this instead of logging the raw value (the 2026-09-06 round found nine that did not).
func StripInvisible ¶
StripInvisible removes every invisible/bidi codepoint from s. It leaves C0/C1 controls in place for callers that scrub those separately; use StripUnsafe to remove the whole set at once.
func StripUnsafe ¶
StripUnsafe removes every C0 control, DEL, C1 control, and invisible/bidi codepoint from s. The fast path returns s unchanged when it is already clean.
Types ¶
This section is empty.