Req #39521 [Opn->Ver]: DOMDocument::createElement() does not escape its parameters properly
Edit report at https://bugs.php.net/bug.php?id=39521&edit=1
ID: 39521
Updated by: cmb@php.net
Reported by: daniel dot oconnor at gmail dot com
-Summary: DomDocument::createElement() should warn you if you
create invalid XML.
+Summary: DOMDocument::createElement() does not escape its
parameters properly
-Status: Open
+Status: Verified
Type: Feature/Change Request
Package: DOM XML related
Operating System: Windows
PHP Version: 5.2.0
-Assigned To:
+Assigned To: cmb
Block user comment: N
Private report: N
New Comment:
> DomDocument::createElement() should warn you if you create
> invalid XML.
That has been fixed in the meantime as demonstrated by Thomas'
script.
> I very much agree with Thomas here: expected result is the node
> being added with all special characters being escaped, including
> ampersand.
I disagree. If ampersands would be escaped, it wouldn't be
possible to have XML entity references in the value, what is
sometimes necessary.
> To be more exact "&" is not escaped, "<" and ">" are.
This is somewhat inconsistent, but escaping the & is not an
option, in my opinion. However, it's totally unclear to me why
double-quotes also don't get escaped.
Anyhow, changing the behavior of DOMDocument::createElement()
would cause a considerable BC break, and as such requires the RFC
process[1]. Feel free to submit such an RFC.
I'm changing this ticket to doc bug, so at least the behavior
will be documented.
[1] <https://wiki.php.net/rfc/howto>
Previous Comments:
------------------------------------------------------------------------
[2015-03-12 10:22:03] njean at quechoisir dot org
I very much agree with Thomas here: expected result is the node being added with all special
characters being escaped, including ampersand.
So I believe the title of this bug is misleading, it should be called something like
"DomDocument::createElement() does not escape its parameters properly".
------------------------------------------------------------------------
[2014-04-09 09:29:07] thomas at weinert dot info
Description:
------------
The second argument ($value) in DOMDocument::createElement()/DOMDocument::createElementNS() is not
escaped properly. To be more exact "&" is not escaped, "<" and
">" are. This result in a warning, and not all content is added to the text node inside
the created element node.
Reproduce code:
---------------
$dom = new DOMDocument;
$dom
->appendChild($dom->createElement('element', 'B & B'));
echo $dom->saveXml();
Expected result:
----------------
<?xml version="1.0"?>
<element>B & B</element>
Actual result:
--------------
Warning: DOMDocument::createElement(): unterminated entity reference B in
/tmp/execpad-c7cffb3796e4/source-c7cffb3796e4 on line 4
<?xml version="1.0"?>
<element>B </element>
Additional Information
----------------------
The bug can be avoided if the text node is created separately and appended to the element node.
$dom = new DOMDocument;
$dom
->appendChild($dom->createElement('element'))
->appendChild($dom->createTextNode('B & B'));
echo $dom->saveXml(), "\n";
------------------------------------------------------------------------
[2006-11-15 06:04:06] daniel dot oconnor at gmail dot com
Description:
------------
DomDocument::createElement() should warn you if you create invalid XML.
Reproduce code:
---------------
<?php
$string = '<tree><branch>Fun Games &</branch></tree>';
$xml = new SimpleXMLElement($string);
$xml->addChild('actor', 'John & Doe');
print $xml->asXML();
$dom = new domDocument;
$dom->loadXML($string);
$dom->appendChild($dom->createTextNode("fish & & chips"));
$node = $dom->createElement('fish', 'ampersand & this, &');
$dom->appendChild($node);
print $dom->saveXML();
Expected result:
----------------
A warning when you do the createElement about the unfinished entity; or at least when you try the
saveXML
Actual result:
--------------
---------- php ----------
Warning: SimpleXMLElement::addChild(): unterminated entity reference Doe in
C:\vx\tests\simplexml.php on line 6
<?xml version="1.0"?>
<tree><branch>Fun Games &</branch><actor>John
</actor></tree>
<?xml version="1.0"?>
<tree><branch>Fun Games &</branch></tree>
fish &amp; & chips
<fish>ampersand & this, &</fish>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=39521&edit=1
Thread (4 messages)