Req #69450 [Com]: Default to ENT_SUBSTITUTE for htmlspecialchars()
| From: | nikic@php.net | Date: | Tue, 14 Apr 2015 20:28:13 +0000 |
| Subject: | Req #69450 [Com]: Default to ENT_SUBSTITUTE for htmlspecialchars() | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-192063@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=69450&edit=1
ID: 69450
Comment by: nikic@php.net
Reported by: olafvdspek at gmail dot com
Summary: Default to ENT_SUBSTITUTE for htmlspecialchars()
Status: Wont fix
Type: Feature/Change Request
Package: Output Control
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
I also think that ENT_SUBSTITUTE is a more reasonable default behavior. Could you elaborate in which
circumstances it will cause broken output?
Previous Comments:
------------------------------------------------------------------------
[2015-04-14 20:13:15] olafvdspek at gmail dot com
If that's the case wouldn't it be even better to halt the script?
Returning empty strings ALSO has the risk of broken output. Even worse, broken output is basically
guaranteed.
------------------------------------------------------------------------
[2015-04-14 19:52:03] yohgaki@php.net
Replacing any invalid byte sequence in string has risk of broken output. i.e. Broken html
structures, etc.
If you would not want to have empty outputs from htmlspecialchars, validate all of your inputs. You
can replace invalid multibyte sequence optionally. i.e. Use mb_convert_encoding().
This is the optimal way to handle text.
------------------------------------------------------------------------
[2015-04-14 17:50:31] olafvdspek at gmail dot com
Description:
------------
Could you default to ENT_SUBSTITUTE for htmlspecialchars()?
Returning an empty string seems sub-optimal.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=69450&edit=1