Bug #80095 [Opn->Nab]: dom document parsing inline javascript errors
| From: | requinix@php.net | Date: | Sat, 12 Sep 2020 20:38:16 +0000 |
| Subject: | Bug #80095 [Opn->Nab]: dom document parsing inline javascript errors | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-228990@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80095&edit=1
ID: 80095
Updated by: requinix@php.net
Reported by: shariefjamiel at gmail dot com
Summary: dom document parsing inline javascript errors
-Status: Open
+Status: Not a bug
Type: Bug
Package: DOM XML related
Operating System: ubuntu 20.04
PHP Version: 7.4Git-2020-09-12 (Git)
Block user comment: N
Private report: N
New Comment:
libxml uses HTML 4 rules which say that </ is an ending tag. Even if the tag doesn't match
the last opening tag.
To avoid this problem, write the ending tags in your script as "<\/".
Previous Comments:
------------------------------------------------------------------------
[2020-09-12 11:06:06] shariefjamiel at gmail dot com
Description:
------------
When loading HTML in the DOMDocument with an inline script within a DIV and there is javascript with
DIV html, the ending script tag gets put in the wrong place.
Notice the closing script tag, its been put in the wrong place
.append("<div class=\"d-flex\"><div class=\"column\">" +
item.value + "</script></div>
In this case removing the outer div, fixes the problem or escaping the html within the javascript
append method.
Test script:
---------------
<?php
$html = <<< EOT
<html lang="en">
<head>
<meta charset="utf-8">
<meta name="viewport" content="width=device-width, initial-scale=1,
shrink-to-fit=no">
</head>
<body>
<div class="if-you-remove-me-everything-is-fine">
<script>
function initialize() {
$('#search').autocomplete({
source: '/api/search',
minLength: 2,
autoFocus: true,
}).autocomplete("instance")._renderItem = function(ul, item) {
return $("<li>")
.append("<div class=\"d-flex\"><div
class=\"column\">" + item.value + "</div> <div
class=\"flex-grow-1\">" + item.label + "</div> <div
class=\"column text-right\">" + item.exchange + "</div>
</div>")
.appendTo(ul);
};
}
</script>
</div>
</body>
</html>
EOT;
/**
* Two ways to solve problem
*
* 1. remove outer div
* 2. escape the html contents in javascript
*/
$doc = new DOMDocument();
$doc->loadHTML($html, LIBXML_HTML_NODEFDTD);
echo $doc->saveHTML();
Expected result:
----------------
Expect the ending script tag to be put where it was
Actual result:
--------------
The script tag was placed inside the inline javascript code
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80095&edit=1