ما هو تشفير URL؟ شرح Percent-Encoding
Quick Answer
تشفير URL = %XX للأحرف غير الآمنة. %20 = مسافة، %E2%82%AC = €. encodeURIComponent للمعاملات، encodeURI لعناوين كاملة. استخدم أداة تشفير URL المجانية في متصفحك.
Introduction
تشفير URL (percent-encoding) يحول الأحرف غير الآمنة في URL إلى %XX حيث XX هو كود الحرف الست عشري. ضروري لأن URL يمكن أن تحتوي فقط على أحرف ASCII. الأحرف غير ASCII (مثل العربية أو €) تشفر كـ UTF-8 multi-byte ثم percent-encoded.
Step by Step
-
Understand which characters need encoding
Unreserved characters (A-Z, a-z, 0-9, -, _, ., ~) do not need encoding. Reserved characters (:, /, ?, #, [, ], @, !, $, &, ', (, ), *, +, ,, ;, =) have special meaning in URLs and should be encoded when used as data. All other characters (spaces, quotes, non-ASCII) must be encoded.
-
Learn the encoding mechanism
Each character that needs encoding is converted to its UTF-8 byte sequence, then each byte is represented as %XX where XX is the hex value. Space (0x20) → %20. The non-ASCII character 'é' (UTF-8: 0xC3 0xA9) → %C3%A9.
-
Distinguish encodeURI vs encodeURIComponent
encodeURI() encodes a full URL but preserves reserved characters (:/?&=) that are part of the URL structure. encodeURIComponent() encodes everything except unreserved characters — use it for query parameter values where reserved characters are data, not structure.
-
Decode percent-encoded URLs
Decoding reverses the encoding: %20 → space, %C3%A9 → é. Use decodeURI() for full URLs and decodeURIComponent() for query parameter values. Invalid escape sequences (like %ZZ) throw errors.
Examples
Encode a space
Input: hello world
Output: hello%20world
Encode non-ASCII text
Input: café
Output: caf%C3%A9
Encode a query parameter value
Input: name=John Doe & Co.
Output: name%3DJohn%20Doe%20%26%20Co.
Common Problems
- Encoding the entire URL when only values need encoding —encode query parameter values, not the URL structure (://?&=).
- Double-encoding —if a URL is already encoded, encoding again produces %2520 instead of %20. Decode first if unsure whether it is already encoded.
- Using encodeURI vs encodeURIComponent incorrectly —encodeURI preserves URL structure characters; encodeURIComponent encodes them. Use the latter for query parameter values.
- Invalid escape sequences —%ZZ or a single % at the end are invalid and will throw errors when decoded.
Tips
- Always encode query parameter values that may contain spaces, special characters, or user input to prevent URL injection.
- Use encodeURIComponent() for query parameter values, and encodeURI() for full URLs that just need unsafe characters encoded.
- URL encoding is not encryption —anyone can decode it. Never use it to hide sensitive data.
- Use our URL Encoder and Decoder for instant, private conversion in your browser.