#43896 [NoF->Opn]: htmlspecialchars returns empty string on invalid unicode sequence
| From: | yunosh@php.net | Date: | Thu, 11 Sep 2008 12:52:17 +0000 |
| Subject: | #43896 [NoF->Opn]: htmlspecialchars returns empty string on invalid unicode sequence | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-128873@lists.php.net to get a copy of this message | ||
ID: 43896
Updated by: yunosh@php.net
Reported By: arnaud dot lb at gmail dot com
-Status: No Feedback
+Status: Open
Bug Type: Strings related
Operating System: *
PHP Version: 5.2CVS, 5.3CVS (2008-07-15)
New Comment:
Not considering this as a bug (or rather a regression) is a major flaw
IMO.
htmlspecialchars() is *THE* tool that developers are encouraged to use
when escaping output of data that comes from an unknown source. By
nature you can't always rely on this data to be perfectly valid. People
copy and paste from Word to HTML forms and do all kind of weird stuff to
get data into a website.
Simply discarding the complete data just because it's not a completely
valid character stream is going break all kind of websites with user
generated content.
Previous Comments:
------------------------------------------------------------------------
[2008-08-04 01:00:01] php-bugs at lists dot php dot net
No feedback was provided for this bug for over a week, so it is
being suspended automatically. If you are able to provide the
information that was originally requested, please do so and change
the status of the bug back to "Open".
------------------------------------------------------------------------
[2008-07-18 00:10:45] moriyoshi@php.net
I even don't think this is a valid bug in the first place. You passed a
string that is encoded in ISO-8859-15 to htmlspecialchars() while
specifying UTF-8 to force the string to be treated as "UTF-8". One
should never depend on the past wrond behaviour with which invalid byte
sequences pass through. Besides, you can always work around it by
giving
ISO-8859-15 to the third argument.
------------------------------------------------------------------------
[2008-06-27 17:32:43] sillyxone at yaoo dot com
is also affected in 5.2, for example:
$str = 'Hello' . chr(160) . 'there';
print(htmlentities($str, ENT_COMPAT, 'UTF-8'));
Instead of printing "Hello there", it prints nothing (empty string).
The same for htmlspecialchars().
Both functions work fine in 5.1
------------------------------------------------------------------------
[2008-05-05 21:00:37] heurika at gmail dot com
Hi,
I've got the same Bug, posted on #43740.
Please fix it.
Thanks!
------------------------------------------------------------------------
[2008-02-17 13:25:22] andreas dot ravnestad at gmail dot com
This seems to be breaking PEAR::Text_Wiki completely when using UTF-8:
http://pear.php.net/bugs/bug.php?id=13136
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
http://bugs.php.net/43896
--
Edit this bug report at http://bugs.php.net/?id=43896&edit=1