Bug #76184 [Com]: string beginning with < error

From: Date: Wed, 04 Apr 2018 21:34:56 +0000
Subject: Bug #76184 [Com]: string beginning with < error
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-214600@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76184&edit=1

 ID:                 76184
 Comment by:         rowan dot collins at gmail dot com
 Reported by:        jalesmonteiro at hotmail dot com
 Summary:            string beginning with < error
 Status:             Not a bug
 Type:               Bug
 Package:            Strings related
 Operating System:   UBUNTU 17.10
 PHP Version:        7.1.16
 Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

@rhsoft: Being aggressive and being right aren't mutually exclusive.

@jalesmonteiro: I apologise on behalf of the community for the tone used in previous comments; you
did nothing to deserve such strong language. However, it is true that this is a mistake on your part
rather than a bug in PHP: the < and > signs are displayed by PHP, but are being hidden by your
browser, which interprets anything between those symbols as an HTML tag, even if it has no meaning
in a current version of HTML. You can check this by selecting "view source" or
"inspect element" in your browser. If your whole page of content is actually pain text,
you could tell the browser this using header('Content-Type: text/plain'); more likely, you
want to display some text within an HTML page, in which case you can escape it using
htmlspecialchars() or html_entities(). Search on http://php.net for
documentation and examples of all your functions, and happy programming. :)


Previous Comments:
------------------------------------------------------------------------
[2018-04-04 21:25:38] cmb@php.net

Thank you for taking the time to write to us, but this is not
a bug. Please double-check the documentation available at
http://www.php.net/manual/ and the instructions on how to
report
a bug at http://bugs.php.net/how-to-report.php

As has been said, if you generate HTML, you have to escape special
HTML characters; otherwise the browser may interpret (parts of)
the string as HTML tags (in this case <Hello>).

> as we have enough code in the wild with not the sligtest thoughs
> about security

ACK.  There is still no need to use explicit language. :)

------------------------------------------------------------------------
[2018-04-04 19:47:50] spam2 at rhsoft dot net

> "rhsoft" continues their aggressive behaviour on the bug 
> tracker still too. One recent illustration is
> https://bugs.php.net/bug.php?id=76184&edit=1

what exactly is aggressive here?

"Strings beginning with the '<' char can't be printed" is simply not
true, can be easily proven by run the "sample code" within a shell or just right click in
Firefox and select "show page source" 

the fact that such strings needs to be properly handeled with htmlentities() is security relevant as
we have enough code in the wild with not the sligtest thoughs about security

------------------------------------------------------------------------
[2018-04-04 16:46:23] spam2 at rhsoft dot net

> the function count_chars also return the expected

the output too, open the damned source of the website in yur browser and you see

------------------------------------------------------------------------
[2018-04-04 16:44:13] jalesmonteiro at hotmail dot com

the function count_chars also return the expected.

------------------------------------------------------------------------
[2018-04-04 16:44:01] spam2 at rhsoft dot net

nonsense - they are printed and you wrote perfect sample code how not to do it open for injection by
not care about special chars - look at the source code of the page and you see them

RTFM of basic HTML and use http://php.net/manual/en/function.htmlentities.php

if you come up with something like "Strings beginning with the '<' char can't
be printed" first run your script in a terminal and then spend 2 seconds what the output means
for a HTML renderer

------------------------------------------------------------------------


The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at

    https://bugs.php.net/bug.php?id=76184


--
Edit this bug report at https://bugs.php.net/bug.php?id=76184&edit=1


Thread (12 messages)

« previous php.bugs (#214600) next »