Req #39521 [Opn->Ver]: DOMDocument::createElement() does not escape its parameters properly

From: Date: Tue, 21 Jun 2016 15:50:14 +0000
Subject: Req #39521 [Opn->Ver]: DOMDocument::createElement() does not escape its parameters properly
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-201774@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=39521&edit=1

 ID:                 39521
 Updated by:         cmb@php.net
 Reported by:        daniel dot oconnor at gmail dot com
-Summary:            DomDocument::createElement() should warn you if you
                     create invalid XML.
+Summary:            DOMDocument::createElement() does not escape its
                     parameters properly
-Status:             Open
+Status:             Verified
 Type:               Feature/Change Request
 Package:            DOM XML related
 Operating System:   Windows
 PHP Version:        5.2.0
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

> DomDocument::createElement() should warn you if you create
> invalid XML.

That has been fixed in the meantime as demonstrated by Thomas'
script.

> I very much agree with Thomas here: expected result is the node
> being added with all special characters being escaped, including
> ampersand.

I disagree. If ampersands would be escaped, it wouldn't be
possible to have XML entity references in the value, what is
sometimes necessary.

> To be more exact "&" is not escaped, "<" and ">" are.

This is somewhat inconsistent, but escaping the & is not an
option, in my opinion. However, it's totally unclear to me why
double-quotes also don't get escaped.

Anyhow, changing the behavior of DOMDocument::createElement()
would cause a considerable BC break, and as such requires the RFC
process[1]. Feel free to submit such an RFC.

I'm changing this ticket to doc bug, so at least the behavior
will be documented.

[1] <https://wiki.php.net/rfc/howto>


Previous Comments:
------------------------------------------------------------------------
[2015-03-12 10:22:03] njean at quechoisir dot org

I very much agree with Thomas here: expected result is the node being added with all special
characters being escaped, including ampersand.

So I believe the title of this bug is misleading, it should be called something like
"DomDocument::createElement() does not escape its parameters properly".

------------------------------------------------------------------------
[2014-04-09 09:29:07] thomas at weinert dot info

Description:
------------
The second argument ($value) in DOMDocument::createElement()/DOMDocument::createElementNS() is not
escaped properly. To be more exact "&" is not escaped, "<" and
">" are. This result in a warning, and not all content is added to the text node inside
the created element node.

Reproduce code:
---------------

$dom = new DOMDocument;
$dom
  ->appendChild($dom->createElement('element', 'B & B'));

echo $dom->saveXml();


Expected result:
----------------

<?xml version="1.0"?>
<element>B &amp; B</element>

Actual result:
--------------

Warning: DOMDocument::createElement(): unterminated entity reference               B in
/tmp/execpad-c7cffb3796e4/source-c7cffb3796e4 on line 4
<?xml version="1.0"?>
<element>B </element>

Additional Information
----------------------

The bug can be avoided if the text node is created separately and appended to the element node. 

$dom = new DOMDocument;
$dom
  ->appendChild($dom->createElement('element'))
  ->appendChild($dom->createTextNode('B & B'));

echo $dom->saveXml(), "\n";

------------------------------------------------------------------------
[2006-11-15 06:04:06] daniel dot oconnor at gmail dot com

Description:
------------
DomDocument::createElement() should warn you if you create invalid XML.



Reproduce code:
---------------
<?php
$string = '<tree><branch>Fun Games &amp;</branch></tree>';

$xml = new SimpleXMLElement($string);

$xml->addChild('actor', 'John & Doe');
print $xml->asXML();

$dom = new domDocument;

$dom->loadXML($string);

$dom->appendChild($dom->createTextNode("fish &amp; & chips"));

$node = $dom->createElement('fish', 'ampersand & this, &amp;');
$dom->appendChild($node);

print $dom->saveXML();

Expected result:
----------------
A warning when you do the createElement about the unfinished entity; or at least when you try the
saveXML

Actual result:
--------------
---------- php ----------

Warning: SimpleXMLElement::addChild(): unterminated entity reference             Doe in
C:\vx\tests\simplexml.php on line 6
<?xml version="1.0"?>
<tree><branch>Fun Games &amp;</branch><actor>John
</actor></tree>
<?xml version="1.0"?>
<tree><branch>Fun Games &amp;</branch></tree>
fish &amp;amp; &amp; chips
<fish>ampersand & this, &amp;</fish>



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=39521&edit=1


Thread (4 messages)

« previous php.bugs (#201774) next »