Bug #77662 [NEW]: htmlspecialchars does not behave as documented regarding its $flags precedence

From: Date: Sun, 24 Feb 2019 16:07:48 +0000
Subject: Bug #77662 [NEW]: htmlspecialchars does not behave as documented regarding its $flags precedence
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-219721@lists.php.net to get a copy of this message
From: nicolas dot roeser at uni-ulm dot de Operating system: Linux, macOS PHP version: 7.3.2 Package: Unknown/Other Function Bug Type: Bug Bug description:htmlspecialchars does not behave as documented regarding its $flags precedence Description: ------------ --- From manual page: https://php.net/function.htmlspecialchars --- I have found function htmlspecialchars to behave differently than its documentation says. I do not know what is the intended behavior. Either the function or the documentation must be fixed. There are two main issues: 1) When neither ENT_COMPAT nor ENT_QUOTES nor ENT_NOQUOTES is set, the function is documented to default to ENT_COMPAT. It seems that it defaults to ENT_NOQUOTES instead. 2) When ENT_HTML401 and ENT_XML1 are set, the function is documented to give precedence to ENT_HTML401. It seems that it gives precedence to ENT_XML1 instead. I have created suitable and readable test scripts and would like to add them to this bug report, but as the test script input is limited to 20 lines, I had to convert my shorter script to a more unreadable version and add it. This bug report is not really related to #61498: this bug report here is about documented vs. actual behavior. Test script: --------------- <?php // The 20-line limit is crap. // Super short test script which only tests the default flags and failing // combinations (and only one per quot/apos group). function hs_expect($test_num, $expected, $str, $flags=null) { if ($flags === null) { $result = htmlspecialchars($str); } else { $result = htmlspecialchars($str, $flags, 'UTF-8', TRUE); } echo "Test number $test_num: "; if ($expected === $result) { echo 'OK'; } else { echo "FAIL: expected: >$expected<, result: >$result<"; } echo "\n"; } // ===== tests for quoting behavior ===== $s = '"'; hs_expect(-1, '&quot;', $s); hs_expect( 0, '&quot;', $s, 0); hs_expect( 8, '&quot;', $s, ENT_HTML401); hs_expect(16, '&quot;', $s, ENT_XML1); hs_expect(32, '&quot;', $s, ENT_XHTML); hs_expect(64, '&quot;', $s, ENT_HTML5); // ===== tests for markup language selection ===== $s = "'"; hs_expect(-1, "'", $s); hs_expect(26, "&#039;", $s, ENT_QUOTES | ENT_HTML401 | ENT_XML1); Expected result: ---------------- I expect documentation and actual behaviour to be in sync. I do not care which one is fixed (or both). Actual result: -------------- See description above. -- Edit bug report at https://bugs.php.net/bug.php?id=77662&edit=1 -- Try a snapshot (PHP 5.4): https://bugs.php.net/fix.php?id=77662&r=trysnapshot54 Try a snapshot (PHP 5.5): https://bugs.php.net/fix.php?id=77662&r=trysnapshot55 Try a snapshot (trunk): https://bugs.php.net/fix.php?id=77662&r=trysnapshottrunk Fixed in SVN: https://bugs.php.net/fix.php?id=77662&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=77662&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=77662&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=77662&r=needscript Try newer version: https://bugs.php.net/fix.php?id=77662&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=77662&r=support Expected behavior: https://bugs.php.net/fix.php?id=77662&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=77662&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=77662&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=77662&r=globals PHP 4 support discontinued: https://bugs.php.net/fix.php?id=77662&r=php4 Daylight Savings: https://bugs.php.net/fix.php?id=77662&r=dst IIS Stability: https://bugs.php.net/fix.php?id=77662&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=77662&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=77662&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=77662&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=77662&r=mysqlcfg

« previous php.bugs (#219721) next »