Bug #76672 [Ana]: Vertical Tab char in the value of DOMElement::setAttribute produces invalid xml
| From: | mioshchikhes at jobrouter dot de | Date: | Fri, 27 Jul 2018 09:23:32 +0000 |
| Subject: | Bug #76672 [Ana]: Vertical Tab char in the value of DOMElement::setAttribute produces invalid xml | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-216490@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=76672&edit=1
ID: 76672
User updated by: mioshchikhes at jobrouter dot de
Reported by: mioshchikhes at jobrouter dot de
Summary: Vertical Tab char in the value of
DOMElement::setAttribute produces invalid xml
Status: Analyzed
Type: Bug
Package: XML related
Operating System: Windows
PHP Version: 7.1.20
Block user comment: N
Private report: N
New Comment:
In my opinion, it is a bug in libxml.
The characters \t \n \r are automatically converted in the method DOMElement::setAttribute correctly
to 	
but not \v
Previous Comments:
------------------------------------------------------------------------
[2018-07-27 08:42:37] requinix@php.net
Vertical tabs aren't allowed in XML 1.0 and need to thus be escaped as  or .
They are allowed in XML 1.1 but are discouraged as one of the "compatibility characters".
Now I'm not sure exactly which rules libxml follows, but at least in this aspect it seems to
follow 1.0 when reading. And unfortunately libxml won't automatically escape them when writing.
PHP could, but the question is whether it should. At least whether it should *now*. On one hand,
this changes the behavior of code people have been relying on for years, but on the other hand (a)
the generated XML may not have been valid to begin with and (b) any parser that accepts invalid
unescaped characters should accept the escaped versions transparently - even if humans don't
realize they're the same.
The normal answer to this problem is "you have to escape it yourself" (especially when it
comes to the addChild/createTextNode problem) but if there's an opportunity to reduce the
number of times that's necessary then I'd like to see if we can.
I'm only moving this to Analyzed so someone more familiar with the XML side of PHP can decide
what to do.
a) Not a bug, libxml follows XML 1.0 and you have to escape it yourself
b) Not a bug, libxml follows XML 1.1 and it is the one that can't handle \v not PHP
c) Is a bug, PHP should take some measures to escape strings automatically
------------------------------------------------------------------------
[2018-07-27 07:30:44] mioshchikhes at jobrouter dot de
Description:
------------
Vertical Tab character \v in the value of DOMElement::setAttribute produces invalid xml.
The XML can be saved, but it has an invalid character and cannot be read correctly. The behavior is
reproducible.
Test script:
---------------
<?php
$dom = new DOMDocument();
$node = $dom->createElement('my-test');
$node->setAttribute('my-attribute', "vertical\vtabs");
$dom->appendChild($node);
$text = $dom->saveXML();
var_dump($text);
$dom = new DOMDocument();
$dom->loadXML($text);
var_dump($dom->saveXML());
Expected result:
----------------
Either an error or valid XML
Actual result:
--------------
An invalid xml is produced
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=76672&edit=1