Bug #80095 [NEW]: dom document parsing inline javascript errors

From: Date: Sat, 12 Sep 2020 11:06:06 +0000
Subject: Bug #80095 [NEW]: dom document parsing inline javascript errors
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-228983@lists.php.net to get a copy of this message
From: shariefjamiel at gmail dot com Operating system: ubuntu 20.04 PHP version: 7.4Git-2020-09-12 (Git) Package: DOM XML related Bug Type: Bug Bug description:dom document parsing inline javascript errors Description: ------------ When loading HTML in the DOMDocument with an inline script within a DIV and there is javascript with DIV html, the ending script tag gets put in the wrong place. Notice the closing script tag, its been put in the wrong place .append("<div class=\"d-flex\"><div class=\"column\">" + item.value + "</script></div> In this case removing the outer div, fixes the problem or escaping the html within the javascript append method. Test script: --------------- <?php $html = <<< EOT <html lang="en"> <head> <meta charset="utf-8"> <meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no"> </head> <body> <div class="if-you-remove-me-everything-is-fine"> <script> function initialize() { $('#search').autocomplete({ source: '/api/search', minLength: 2, autoFocus: true, }).autocomplete("instance")._renderItem = function(ul, item) { return $("<li>") .append("<div class=\"d-flex\"><div class=\"column\">" + item.value + "</div> <div class=\"flex-grow-1\">" + item.label + "</div> <div class=\"column text-right\">" + item.exchange + "</div> </div>") .appendTo(ul); }; } </script> </div> </body> </html> EOT; /** * Two ways to solve problem * * 1. remove outer div * 2. escape the html contents in javascript */ $doc = new DOMDocument(); $doc->loadHTML($html, LIBXML_HTML_NODEFDTD); echo $doc->saveHTML(); Expected result: ---------------- Expect the ending script tag to be put where it was Actual result: -------------- The script tag was placed inside the inline javascript code -- Edit bug report at https://bugs.php.net/bug.php?id=80095&edit=1 -- Fix committed: https://bugs.php.net/fix.php?id=80095&r=fixed Fixed in release: https://bugs.php.net/fix.php?id=80095&r=alreadyfixed Need backtrace: https://bugs.php.net/fix.php?id=80095&r=needtrace Need Reproduce Script: https://bugs.php.net/fix.php?id=80095&r=needscript Try newer version: https://bugs.php.net/fix.php?id=80095&r=oldversion Not developer issue: https://bugs.php.net/fix.php?id=80095&r=support Expected behavior: https://bugs.php.net/fix.php?id=80095&r=notwrong Not enough info: https://bugs.php.net/fix.php?id=80095&r=notenoughinfo Submitted twice: https://bugs.php.net/fix.php?id=80095&r=submittedtwice register_globals: https://bugs.php.net/fix.php?id=80095&r=globals PHP version support discontinued: https://bugs.php.net/fix.php?id=80095&r=phptooold Daylight Savings: https://bugs.php.net/fix.php?id=80095&r=dst IIS Stability: https://bugs.php.net/fix.php?id=80095&r=isapi Install GNU Sed: https://bugs.php.net/fix.php?id=80095&r=gnused Floating point limitations: https://bugs.php.net/fix.php?id=80095&r=float No Zend Extensions: https://bugs.php.net/fix.php?id=80095&r=nozend MySQL Configuration Error: https://bugs.php.net/fix.php?id=80095&r=mysqlcfg

« previous php.bugs (#228983) next »