Bug #74036 [Opn]: createTextNode() does not handle binary data
| From: | requinix@php.net | Date: | Thu, 02 Feb 2017 17:55:03 +0000 |
| Subject: | Bug #74036 [Opn]: createTextNode() does not handle binary data | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-207132@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=74036&edit=1
ID: 74036
Updated by: requinix@php.net
Reported by: judge2005 at gmail dot com
Summary: createTextNode() does not handle binary data
Status: Open
Type: Bug
Package: DOM XML related
Operating System: RHEL 7
PHP Version: 7.0.15
Block user comment: N
Private report: N
New Comment:
I don't think this is a bug. Though DOM 3 doesn't say much, from what I can gather
createTextNode should not try to sanitize the text input. And though &"'<> will
be escaped during serialization, according to context, that's all and it's up to the
developer to not do things like use control characters.
Testing with Javascript in Chrome does the same thing: the characters are left as-is and not
escaped. Adding it to an XML document, serializing to a string, then parsing the string results in a
parse error.
And the bug system didn't strip them. The characters are there, your browser is just not
rendering them as anything.
Previous Comments:
------------------------------------------------------------------------
[2017-02-02 17:10:36] judge2005 at gmail dot com
Looks like your bug report system strips out the binary. The additional characters were ETX, EOT and
DC4
------------------------------------------------------------------------
[2017-02-02 17:08:20] judge2005 at gmail dot com
Description:
------------
If binary data is passed to createTextNode() it can cause invalid XML to be generated.
Test script:
---------------
<?php
$document = new DOMDocument('1.0', 'UTF-8');
$document->formatOutput = true;
$root = $document->createElement('example');
$document->appendChild($root);
$example = $document->createTextNode("PK");
$root->appendChild($example);
echo $document->saveXML();
Actual result:
--------------
<?xml version="1.0" encoding="UTF-8"?>
<example>PK</example>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=74036&edit=1