Req #67734 [Opn->Sus]: Add output escaping specifiers to sprintf etc.
| From: | cmb@php.net | Date: | Fri, 13 Nov 2020 10:42:44 +0000 |
| Subject: | Req #67734 [Opn->Sus]: Add output escaping specifiers to sprintf etc. | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-230316@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=67734&edit=1
ID: 67734
Updated by: cmb@php.net
Reported by: marcus at synchromedia dot co dot uk
Summary: Add output escaping specifiers to sprintf etc.
-Status: Open
+Status: Suspended
Type: Feature/Change Request
Package: Strings related
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
In my opinion, this is best left to userland (libraries), because
there may just be too many (slightly) different
requirements/demands. If you feel strongly that this should be
part of PHP core, please forward your request to the internals
mailing list for discussion. For the time being, I'm suspending
this ticket.
Previous Comments:
------------------------------------------------------------------------
[2014-08-01 08:16:57] marcus at synchromedia dot co dot uk
Description:
------------
sprintf, vsprintf etc have numerous different specifiers for numbers, but only a single generic
'string' option for strings with %s. It would be useful to have additional options for
escaping values, for example with URL encoding or HTML escaping. You might say that you can achieve
this by applying escaping functions to the variables you pass in, which is correct, but in the
interests of DRY, it's much tidier if the printing function can do this itself - and after all
there is a clear precedent in the form of all the numeric options for which you could say the same.
It might be interesting to provide SQL escaping specifiers, since PDO doesn't provide a
complete implementation for this, thoughit may be difficult to pass in a connection reference in a
clean way.
Test script:
---------------
The current implementation looks like this:
echo sprintf('<a href="%s?linkname=%s">%s</a>',
'myscript.php', rawurlencode('> my link'), htmlentities('> my
link', ENT_QUOTES));
Assuming the %h specifier applies URL-encoding, and the %H specifier applies HTML escaping:
echo sprintf('<a href="%1$s?linkname=%2$h">%2$H</a>',
'myscript.php', '> my link');
Result:
<a href="myscript.php?linkname=%3E%20my%20link">> my link</a>
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=67734&edit=1