Req #32619 [Asn->Wfx]: ext/session: Valid XHTML output
| From: | yohgaki@php.net | Date: | Mon, 02 Feb 2015 09:02:18 +0000 |
| Subject: | Req #32619 [Asn->Wfx]: ext/session: Valid XHTML output | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-190401@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=32619&edit=1
ID: 32619
Updated by: yohgaki@php.net
Reported by: nick at terado dot co dot uk
Summary: ext/session: Valid XHTML output
-Status: Assigned
+Status: Wont fix
Type: Feature/Change Request
Package: Session related
Operating System: *
PHP Version: *
Assigned To: yohgaki
Block user comment: N
Private report: N
New Comment:
I think we are OK now. If you think there is issue with HTML5, please open new bug for HTML5.
Previous Comments:
------------------------------------------------------------------------
[2005-04-07 10:05:13] nick at terado dot co dot uk
Description:
------------
Firstly, this relates to bug #23694
I warrant this being reopened. Upsetting the validity of a webpages code by using php is a bug.
The method to correct this is neither logical nor sensible. The requirement should not be on the
server administrator to dictate what HTML version should be used to create webpages.
There are two problems here:
1. first ampersands withing url query strings when modified to append the session information.
2. Forms, where a hidden session id input tag will be inserted, however not enclosed by a block
level element.
Details and Resolution:
1. The recommended fix so far by the php team is to enable in php.ini the modifier
arg_separator.output="&".
Firstly, modification of the php.ini is restrictive. Secondly, using & in HTML 4 works
also, it is standard practice to encode ampersands properly and there is no reason at all not to
have this enabled by default. If there is any other reason, then just as you would output
<br> as <br /> then you should output correctly & as & when using XHTML.
However, I repeat using & should be default practice.
2. The recommended fix given so far is to change to
url_rewriter.tags = "a=href,area=href,frame=src,input=src,fieldset="
therefore, omitting form=fakeentry.
Again, the practice of modifying (if possible) the php.ini to set the HTML is bad news and
restrictive. Also by now omitting the form= setting of the modifier we now cant guarantee the
session variable will be added, fieldset is not the only choice of block level element within the
form element. Therefore, to complement this often an empty <fieldset> must be inserted,
simply to accommodate the session variable addition.
There are simple fixes to this. If the HTML version is known then <fieldset> can be output
around the hidden element. This is no way upset layout, having no content or white space nothing is
output and no shifting on the webpage occurs. Secondly, <div> can be used. This therefore
allows backwards compatibility and can be output as a rule. However, I wouldnt know how older
browsers would deal with the div - that is whether it would cause spacing issues. However, the
point here is this should be a default or transparent action, the effort to "fix" this is
nothing more than asking the coder to hack there way out of what exists as a bug.
This may not be a bug in performance or operation of php itself, but when php itself is outputting
HTML and this output is incorrect, this completely warrants a bug report being opened. The
solutions recommended are both not fixes and have other problems associated with them. The solution
to this seems quite simple however.
Nick
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=32619&edit=1