Bug->Req #49731 [Opn]: Illegal XML characters allowed in (not stripped from) text nodes.
| From: | yohgaki@php.net | Date: | Sun, 13 Jul 2014 02:23:55 +0000 |
| Subject: | Bug->Req #49731 [Opn]: Illegal XML characters allowed in (not stripped from) text nodes. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-186588@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=49731&edit=1
ID: 49731
Updated by: yohgaki@php.net
Reported by: moltendorf at gmail dot com
Summary: Illegal XML characters allowed in (not stripped
from) text nodes.
Status: Open
-Type: Bug
+Type: Feature/Change Request
Package: DOM XML related
Operating System: *
-PHP Version: 5.2.11
+PHP Version: *
Block user comment: N
Private report: N
New Comment:
Numeric Character Reference (NCR) or any conversion breaks apps.
Previous Comments:
------------------------------------------------------------------------
[2009-10-01 07:00:29] moltendorf at gmail dot com
Made title more correct, and the last comment was intended to replace the existing description for
this bug; as invalid characters should be stripped entirely, or an exception should be thrown (and
the text node not be added), and/or some sort of method should be included to strip the illegal
characters from the input without throwing an exception.
------------------------------------------------------------------------
[2009-10-01 06:51:00] moltendorf at gmail dot com
Adding illegal characters to a text node when saved as XML are not stripped. This breaks the XML,
causing it to be "not well-formed" when viewed by standards-compliant browsers, like
Firefox. Even converting them to NCRs breaks the XML in most browsers.
For reference, the NCR of the "illegal character" included in the reproduce code is

------------------------------------------------------------------------
[2009-10-01 06:47:18] moltendorf at gmail dot com
Description:
------------
Adding illegal characters to a text node when saved as XML are not either converted to NCRs, or
stripped. This breaks the XML, causing it to be "not well-formed" when viewed by
standards-compliant browsers, like Firefox.
Reproduce code:
---------------
<?php
header ('Content-Type: text/xml');
$document = new DOMDocument ('1.0', 'utf-8');
$element = $document -> createElement ('element');
$text = $document -> createTextNode (''); // Please copy and paste this line
directly; it contains special characters that may not display correctly; and are invalid in XML
based on the W3C specification.
$element -> appendChild ($text);
$document -> appendChild ($element);
echo $document -> saveXML ( );
Expected result:
----------------
<?xml version="1.0" encoding="utf-8"?>
<element/>
Actual result:
--------------
<?xml version="1.0" encoding="utf-8"?>
<element></element>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=49731&edit=1