Data URI scheme explained

The data URI scheme is a uniform resource identifier (URI) scheme that provides a way to include data in-line in Web pages as if they were external resources. It is a form of file literal or here document. This technique allows normally separate elements such as images and style sheets to be fetched in a single Hypertext Transfer Protocol (HTTP) request, which may be more efficient than multiple HTTP requests,[1] and used by several browser extensions to package images as well as other multimedia content in a single HTML file for page saving.[2] [3], data URIs are fully supported by all major browsers.[4]

Syntax

The syntax of data URIs is defined in Request for Comments (RFC) 2397, published in August 1998,[5] and follows the URI scheme syntax. A data URI consists of:

data:content/type;base64,

Examples of data URIs showing most of the features are:

data:text/vnd-example+xyz;foo=bar;base64,R0lGODdh
data:text/plain;charset=UTF-8;page=21,the%20data:1234,5678
(outputs: "the data:1234,5678")

data:image/svg+xml;utf8,<svg width='10'... </svg>

The minimal data URI is data:,, consisting of thescheme, no media-type, and zero-length data.

Thus, within the overall URI syntax, a data URI consists of a scheme and a path, with no authority part, query string, or fragment. The optional media type, the optional base64 indicator, and the data are all parts of theURI path.

Examples of use

HTML

An HTML fragment embedding a base64 encoded PNG picture of a small red dot:

In this example, the lines are broken for formatting purposes. In actual URIs,including data URIs, control characters (ASCII 0 to 31, and 127) and spaces (ASCII 32) are "excluded characters". This means that whitespace characters are not permitted in data URIs. However, in the context of HTML 4 and HTML 5, linefeeds within an element attribute value (such as the "src" above) are ignored. So the data URI above would be processed ignoring the linefeeds, giving the correct result. But note that this is an HTML feature, not a data URI feature, and in other contexts, it is not possible to rely on whitespace within the URI being ignored.

An HTML fragment embedding a utf8 encoded SVG picture of a small red dot:

Red dot

In this example, the image data is encoded with utf8 and hence the image data can broken into multiple lines for easy reading. Single quote has to be used in the SVG data as double quote is used for encapsulating the image source.

A favicon can also be made with utf8 encoding and SVG data which has to appear in the 'head' section of the HTML:

CSS

A Cascading Style Sheets (CSS) rule that includes a background image:ul.checklist li.complete

In this example, the \ + <linefeed> line terminatorsare a feature of CSS, indicating continuation on the next line. These would be removed by the CSS stylesheet processor, and the data URI would be reconstituted without whitespace, making it correct, since whitespace is not allowed within the data component of a data:URI.

JavaScript

A JavaScript statement that opens an embedded subwindow, as for a footnote link:

window.open('data:text/html;charset=utf-8,' + encodeURIComponent(// Escape for URL formatting ''+ ''+ 'Embedded Window'+ '

42

'+ ''));

SVG

A Scalable Vector Graphic image containing an embedded JPEG image encoded in Base64:

Malware and phishing

The data URI can be utilized to construct attack pages that attempt to obtain usernames and passwords from unsuspecting web users. It can also be used to get around cross-site scripting (XSS) restrictions, embedding the attack payload fully inside the address bar, and hosted via URL shortening services rather than needing a full website that is controlled by a third party.[8] As a result, some browsers now block webpages from navigating to data URIs.[9]

Notes and References

  1. Web site: Using Data URIs to Speed Up Your Website. 27 March 2014. Treehouse Blog.
  2. Web site: SingleFile - Chrome Web Store. Chrome Web Store. 25 August 2018.
  3. Web site: SingleFile – Add-ons for Firefox. Firefox Add-ons. 25 August 2018.
  4. Web site: Can I use.... Alexis. Deveria. July 2015. 31 August 2015.
  5. Web site: RFC 2397 - The "data" URL scheme. Masinter, L. Internet Engineering Task Force. August 1998. 2008-08-12.
  6. Web site: Character Sets. Ned. Freed. Martin. Dürst. Internet Assigned Numbers Authority. 20 December 2013. 31 August 2015.
  7. Web site: Uniform Resource Identifiers (URI): Generic Syntax. Tim. Berners-Lee. Tim Berners-Lee. Roy. Fielding. Roy Fielding. Larry. Masinter. Internet Engineering Task Force. January 2005. 31 August 2015.
  8. Phishing without a webpage – researcher reveals how a link itself can be malicious, Naked Security by Sophos, 31 AUG 2012 https://nakedsecurity.sophos.com/2012/08/31/phishing-without-a-webpage-researcher-reveals-how-a-link-itself-can-be-malicious/
  9. Web site: Data URLs - HTTP | MDN. MDN Web Docs. Mozilla. 11 May 2018.