Req #62574 [Opn->Sus]: New operator for htmlspecialchars
Edit report at https://bugs.php.net/bug.php?id=62574&edit=1
ID: 62574
Updated by: requinix@php.net
Reported by: thbley at gmail dot com
Summary: New operator for htmlspecialchars
-Status: Open
+Status: Suspended
Type: Feature/Change Request
Package: *General Issues
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
Such a feature would require the RFC process. https://wiki.php.net/rfc/howto
Previous Comments:
------------------------------------------------------------------------
[2016-06-11 05:44:29] michael dot vostrikov at gmail dot com
I also vote for this feature. There are a lot of projects which do not use a templating engine - for
historical reasons or which are written on frameworks without built-in templating engine.
I wanted to suggest the variant like "<?== $str ?>", but I've read the comments
and I like more the variant like "<?~ $str ?>". It is quite easy to type, and there
is a less possibility to write "<?= ?>" instead.
In PHP 7 there are new operators and other changes. I think, new echo operator also can be added.
------------------------------------------------------------------------
[2012-12-05 23:35:11] thbley at gmail dot com
and maybe:
- output htmlspecialchars+basename <?/ $file ?>
------------------------------------------------------------------------
[2012-12-05 23:26:45] thbley at gmail dot com
So we have these use cases:
- output unmodified content <?= $str ?>
- output htmlspecialchars escaped content <?+ $str ?> or <?~ $str ?>
- output strip_tags <?- $str ?>
- output intval <?# $str ?>
------------------------------------------------------------------------
[2012-12-05 23:12:57] chuyu at microsoft dot com
I was thinking the same thing.
One advantage of using some template engines(twig, phptal) is that they automatically escape html
characters during output. Many people use these template engine simply for that due to XSS worries.
However if we have such an operator, then we create a simple php native template engine(which
I'm all for), and in the template always use this operator to prevent XSS.
I would suggest to make the operator like <?~ $var ?>, the reason is that ~ is often located
near the 'ESC' on the keyboard, so it feels more like escape :-)
------------------------------------------------------------------------
[2012-10-26 19:24:31] ajf at ajf dot me
@dagguh: What? I'm just suggesting exporting variables into the global namespace, and escaping
them in the process, for templating purposes.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=62574
--
Edit this bug report at https://bugs.php.net/bug.php?id=62574&edit=1
Thread (10 messages)