Bug #76672 [Ana]: Vertical Tab char in the value of DOMElement::setAttribute produces invalid xml

From: Date: Fri, 27 Jul 2018 09:23:32 +0000
Subject: Bug #76672 [Ana]: Vertical Tab char in the value of DOMElement::setAttribute produces invalid xml
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-216490@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=76672&edit=1 ID: 76672 User updated by: mioshchikhes at jobrouter dot de Reported by: mioshchikhes at jobrouter dot de Summary: Vertical Tab char in the value of DOMElement::setAttribute produces invalid xml Status: Analyzed Type: Bug Package: XML related Operating System: Windows PHP Version: 7.1.20 Block user comment: N Private report: N New Comment: In my opinion, it is a bug in libxml. The characters \t \n \r are automatically converted in the method DOMElement::setAttribute correctly to &#9; &#10; &#13; but not \v Previous Comments: ------------------------------------------------------------------------ [2018-07-27 08:42:37] requinix@php.net Vertical tabs aren't allowed in XML 1.0 and need to thus be escaped as &#11; or &#xB;. They are allowed in XML 1.1 but are discouraged as one of the "compatibility characters". Now I'm not sure exactly which rules libxml follows, but at least in this aspect it seems to follow 1.0 when reading. And unfortunately libxml won't automatically escape them when writing. PHP could, but the question is whether it should. At least whether it should *now*. On one hand, this changes the behavior of code people have been relying on for years, but on the other hand (a) the generated XML may not have been valid to begin with and (b) any parser that accepts invalid unescaped characters should accept the escaped versions transparently - even if humans don't realize they're the same. The normal answer to this problem is "you have to escape it yourself" (especially when it comes to the addChild/createTextNode problem) but if there's an opportunity to reduce the number of times that's necessary then I'd like to see if we can. I'm only moving this to Analyzed so someone more familiar with the XML side of PHP can decide what to do. a) Not a bug, libxml follows XML 1.0 and you have to escape it yourself b) Not a bug, libxml follows XML 1.1 and it is the one that can't handle \v not PHP c) Is a bug, PHP should take some measures to escape strings automatically ------------------------------------------------------------------------ [2018-07-27 07:30:44] mioshchikhes at jobrouter dot de Description: ------------ Vertical Tab character \v in the value of DOMElement::setAttribute produces invalid xml. The XML can be saved, but it has an invalid character and cannot be read correctly. The behavior is reproducible. Test script: --------------- <?php $dom = new DOMDocument(); $node = $dom->createElement('my-test'); $node->setAttribute('my-attribute', "vertical\vtabs"); $dom->appendChild($node); $text = $dom->saveXML(); var_dump($text); $dom = new DOMDocument(); $dom->loadXML($text); var_dump($dom->saveXML()); Expected result: ---------------- Either an error or valid XML Actual result: -------------- An invalid xml is produced ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=76672&edit=1

« previous php.bugs (#216490) next »