Req #62745 [NEW]: Extend echo and print possiblity
| From: | kjelkenes at gmail dot com | Date: | Sat, 04 Aug 2012 14:13:56 +0000 |
| Subject: | Req #62745 [NEW]: Extend echo and print possiblity | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-172434@lists.php.net to get a copy of this message | ||
From: kjelkenes at gmail dot com
Operating system: *
PHP version: 5.4.5
Package: Unknown/Other Function
Bug Type: Feature/Change Request
Bug description:Extend echo and print possiblity
Description:
------------
This is a feature request regarding the "echo" and "print" functions used
in PHP. The echo/print statement is used for output. As of today there are
no way of extending these statements, leading to potential security risks.
If we could extend the echo function at a given time with a handler/closure
this could really improve the security of PHP.
Say we have the following security risk (XSS injection):
$data = "<h1><script>alert('hi');</script></h1>"; //
From db.
echo $data;
Today we need custom functions to escape this such as:
function escape($data){
return htmlspecialchars($data, ENT_QUOTES, 'UTF-8');
}
echo escape($data);
What if we could implement a handler for the echo/print statements such as
this:
// Define a handler:
$outputHandler = function escape($data){
return htmlspecialchars($data, ENT_QUOTES, 'UTF-8');
};
/**
* Sets a output handler for php, it's used in echo and print statements.
* @param string $name The identity of this handler ( Unique )
* @param mixed $outputHandler function name or callback closure to use.
* @param mixed $flags What type of satements to use this function.
*/
add_output_handler('xss_filter',$outputHandler, OutputHandler::F_ECHO |
OutputHandler::F_PRINT);
/**
* Removes a given output handler by it's name.
*/
remove_output_handler('xss_filter');
Then we could use normal statements:
echo '<script>alert('This will never be exected.')</script>';
And when we don't need it anymore:
remove_output_handler('xss_filter');
This way, one can be sure that the output of ANY kind is actually stripped,
without implementing a whole new templating system for PHP.
Also this does not break any kind of PHP applications running, it just adds
new functionality that is (let's face it) really needed for PHP.
This is also great for MVC frameworks, just apply it before executing a
view file and remove it after!
--
Edit bug report at https://bugs.php.net/bug.php?id=62745&edit=1
--
Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=62745&r=trysnapshot54
Try a snapshot (PHP 5.3): https://bugs.php.net/fix.php?id=62745&r=trysnapshot53
Try a snapshot (trunk): https://bugs.php.net/fix.php?id=62745&r=trysnapshottrunk
Fixed in SVN: https://bugs.php.net/fix.php?id=62745&r=fixed
Fixed in SVN and need be documented: https://bugs.php.net/fix.php?id=62745&r=needdocs
Fixed in release: https://bugs.php.net/fix.php?id=62745&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=62745&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=62745&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=62745&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=62745&r=support
Expected behavior: https://bugs.php.net/fix.php?id=62745&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=62745&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=62745&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=62745&r=globals
PHP 4 support discontinued: https://bugs.php.net/fix.php?id=62745&r=php4
Daylight Savings: https://bugs.php.net/fix.php?id=62745&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=62745&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=62745&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=62745&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=62745&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=62745&r=mysqlcfg