Bug #62683 [Com]: FILTER_SANITIZE_SPECIAL_CHARS does not work as declared
| From: | shensiapoost at yahoo dot com | Date: | Mon, 13 Jan 2014 00:51:28 +0000 |
| Subject: | Bug #62683 [Com]: FILTER_SANITIZE_SPECIAL_CHARS does not work as declared | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-183740@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=62683&edit=1
ID: 62683
Comment by: shensiapoost at yahoo dot com
Reported by: admin dot windows at gmail dot com
Summary: FILTER_SANITIZE_SPECIAL_CHARS does not work as
declared
Status: Open
Type: Bug
Package: Filter related
Operating System: Windows/Linux
PHP Version: 5.3.15
Block user comment: N
Private report: N
New Comment:
According to http://www.php.net/manual/en/filter.filters.sanitize.php,
only FILTER_SANITIZE_FULL_SPECIAL_CHARS is equal to htmlspecialchars(). Therefore,
FILTER_SANITIZE_SPECIAL_CHARS is acting like it should.
The reason you are seeing FILTER_SANITIZE_FULL_SPECIAL_CHARS not produce the right results is
because of https://bugs.php.net/bug.php?id=65282. Because of
this bug, if you used the FILTER_SANITIZE_FULL_SPECIAL_CHARS constant, you were essentially calling
FILTER_SANITIZE_SPECIAL_CHARS. Thus, why the two produce the same result.
Previous Comments:
------------------------------------------------------------------------
[2012-07-28 12:22:16] admin dot windows at gmail dot com
Description:
------------
FILTER_SANITIZE_SPECIAL_CHARS and FILTER_SANITIZE_FULL_SPECIAL_CHARS does not work
as documented and produced results does not match htmlspecialchars results at all.
Test script:
---------------
$string = "<a href=\"#\">O'Reilly - PHP Tips & Tricks</a>";
//string '<a href="#">O'Reilly - PHP Tips & Tricks</a>'
(length=44)
var_dump($string);
//string '<a href="#">O'Reilly - PHP Tips &
Tricks</a>' (length=75)
var_dump(htmlspecialchars($string, ENT_QUOTES));
//string '<a href="#">O'Reilly - PHP Tips &
Tricks</a>' (length=76)
var_dump(filter_var($string, FILTER_SANITIZE_SPECIAL_CHARS));
//string '<a href="#">O'Reilly - PHP Tips &
Tricks</a>' (length=76)
var_dump(filter_var($string, FILTER_SANITIZE_FULL_SPECIAL_CHARS));
Expected result:
----------------
//string '<a href="#">O'Reilly - PHP Tips &
Tricks</a>' (length=75)
Actual result:
--------------
//string '<a href="#">O'Reilly - PHP Tips &
Tricks</a>' (length=76)
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=62683&edit=1