Wcurl Is Here
daniel.haxx.se
daniel.haxx.se
Is there a reason not to do that? I've always used wget and curl interchangeably, because both meet my moderate needs. Is there a reason I should avoid wget?
Which curl options do they mean? "curl -O URL"?
Without `-f`, it'll happily save the 404 error page if you do `curl -LO https://example.com/index.htmll`
After playing with `wcurl`, I may or may not remember that one.
Also, wcurl puts a lot of effort into making `wcurl url1 url2` work equally predictably.
Finally, wcurl doesn't yet support `wcurl https://example.com` (without a filename at the end of the URL), but it might eventually.
> By default, wcurl will:
> Encode whitespaces in URLs;
> Download multiple URLs in parallel if the installed curl's version is >= 7.66.0;
> Follow redirects;
> Automatically choose a filename as output;
> Avoid overwriting files if the installed curl's version is >= 7.83.0 (--no-clobber);
> Perform retries;
> Set the downloaded file timestamp to the value provided by the server, if available;
> Disable curl's URL globbing parser so {} and [] characters in URLs are not treated specially.
curl wants to be a swiss army knife, and so you'll need to configure everything just right so you don't accidentally get the bottle opener instead of the downloader. wget just downloads, and does it well.
curl -LOCf URL
As for man pages, HTTPie has been shipping them since v3.2 [1].
Try `man http` or `http --manual`.
[0] https://github.com/httpie/cli/blob/master/httpie/internal/up...
[1] https://github.com/httpie/packages.httpie.io/blob/master/lat...
~/.wget-hsts
You can disable creating this file or change its location by adding a config option to ~/.wgetrc (or using args to wget every time)I think it's for disallowing http when an https connection has previously been established?
https://en.wikipedia.org/wiki/HTTP_Strict_Transport_Security
So if you're wget-ing a file from a server that uses HTTPS and HSTS, but you only specify http:// (or no protocol at all), then the next time you wget from that server, it will automatically change the URL to https://
Some suggestions:
- Allow insecure URLs by providing -k option automatically for https URLs
- Auto follow HTTP redirects by providing -L option by default
- Rather than use the curl-options setting, just accept —-user and —-pass as options then pass this to curl
I know people will feel strongly about some of these however it would simplify curl usage for a majority of the download only use cases
Other curl options can be used for the more “advanced” use cases like Headers
Why would you ever do that? This should be a very conscious choice if you decide to ignore the main system keeping the internet traffic trusted.
I know some people feel strongly about this one
But the only time it could lead to a problem is if you pass user/pass and you have a MITM situation.
So maybe only allow it if not passing user and pass
If it’s just a download and we know we aren’t on a TOR node situation then privacy isn’t that great of a concern
My two cents! Open to changing my mind
I mean invest in Smallstep SSH - nope
If software suddenly started accepting invalid certificates, they would have no incentive of rolling it back. HTTPS would make zero sense then.
The script already passes "--location", the non-shortened version of the argument.
For the other things maybe the both safer and more scalable approach is the script should see if it's being run interactively and default to interactively prompting the user for what action to take on detectable things (like missing basic auth or invalid certs for secure domains) or logging an example version of the same command to run as part of the stderr output otherwise. Apart from avoiding debate by taking a stance on what the default should be this will still be allowed by e.g. the Debian repo maintainers.
It does default to https as the proto-default if no scheme is provided - in your example it could default to interactively asking the user however this may fail in automated scenarios and/or hang.
Anyways it’s a good thought exercise. It’s hard to satisfy all use cases equally
I don't want this by default, but for me it's already better than wget since -k is the same thing as --no-check-certificate. Less typing.
The main issue with writing it in shell instead is incorrect error handling. I see a case that's a bit sketchy there. For now maybe don't expose wcurl to user/attacker controlled input.
Wcurl was here.....2 months ago.
Discussion: https://news.ycombinator.com/item?id=40869458