# The strangeness (or not) of \* as string concatenation

**URL:** <https://discourse.julialang.org/t/the-strangeness-or-not-of-as-string-concatenation/131943>\
**Category:** General Usage\
**Created:** [August 26, 2025, 2:14pm UTC](https://discourse.julialang.org/t/the-strangeness-or-not-of-as-string-concatenation/131943 "2025-08-26T14:14:07Z")\
**Posts on this page:** 1\
**Showing post:** 57

<div class="post-metadata">

**Author:** ![tecosaur](https://sea2.discourse-cdn.com/julialang/user_avatar/discourse.julialang.org/tecosaur/32/23206_2.png) [@tecosaur](https://discourse.julialang.org/u/tecosaur)\
**Post date:** [August 29, 2025, 3:17am UTC](https://discourse.julialang.org/t/the-strangeness-or-not-of-as-string-concatenation/131943/57 "2025-08-29T03:17:31Z")

</div>

> [@goerz](#):
>
> Tangentially related, but I was _definitely_ thinking about that thread. I’m not quite sure if those are plans for inclusion in Julia proper, or just a package, but that discussion definitely left me alarmed at over-complicating design decisions. I would consider any implementation not using `/` to join `Path` objects to be a strong heuristic for “this doesn’t have the right mental model for me”.

If I could direct you over to that thread, I’d love to hear more. At this stage, I think I can say that thread will eventually become a _something_, and I’d like that _something_ to be of high enough quality to be worth serious consideration for inclusion in Julia proper (which is somewhat needed for the value of a `Path` type to be realised, given `open`, `read`, etc.).

There are small pile of design compromises that need to be made. More shared thoughts on what the right priorities, trade-offs, and other design elements can only help.\*

**\*** &nbsp;Well, up to a point, but I don’t think we’re anywhere near there yet. Please don’t just comment on `slash / joining` though.

> [@goerz](#):
>
> In Python’s `pathlib`, `Path("user_content/" + untrusted_file)` is simply `PosixPath('user_content/../../../../../../etc/passwd')`, which seems perfectly alright.

I’d describe this as perfectly _dangerous_ not alright. There’s a pile of CVEs across all sorts of software and libraries from exactly this behavior.

---

_[View the full topic](https://discourse.julialang.org/t/the-strangeness-or-not-of-as-string-concatenation/131943)._
