From: ASchmidt at Anamera dot net
Operating system: Windows
PHP version: 7.4.16
Package: Unknown/Other Function
Bug Type: Bug
Bug description:htmlspecialchars double-encodes "
Description:
------------
According to manual "when double_encode is turned off PHP will not
encode existing html entities". No pre-condition is stated.
However, " is double-encoded, UNLESS flag ENT_HTML5 is set.
Setting either ENT_COMPAT or ENT_NOQUOTES or ENT_QUOTES does NOT alter
the outcome, nor is any other entity subject to this bug; it appears to
be a unique combination of " and the lack of ENT_HTML5.
Test script:
---------------
declare(strict_types=1);
$text = 'ampersand(&), double quote("), single quote('),
less than(<), greater than(>), numeric
entities(&"'<>)';
$result1 = htmlspecialchars( $text, ENT_COMPAT | ENT_SUBSTITUTE,
'UTF-8', false );
$result2 = htmlspecialchars( $text, ENT_NOQUOTES | ENT_SUBSTITUTE,
'UTF-8', false );
$result3 = htmlspecialchars( $text, ENT_QUOTES | ENT_SUBSTITUTE,
'UTF-8', false );
$result4 = htmlspecialchars( $text, ENT_QUOTES | ENT_HTML5 |
ENT_SUBSTITUTE, 'UTF-8', false );
echo "<br />\r\n", $result1, "<br />\r\n", $result2, "<br
/>\r\n",
$result3, "<br />\r\n", $result4, "<br />\r\n";
Expected result:
----------------
Four identical rows of:
ampersand(&), double quote("), single quote("), less than(<), greater
than(>), numeric entities(&"'<>)
Actual result:
--------------
ampersand(&), double quote("), single quote('), less than(<),
greater than(>), numeric entities(&"'<>)
ampersand(&), double quote("), single quote('), less than(<),
greater than(>), numeric entities(&"'<>)
ampersand(&), double quote("), single quote('), less than(<),
greater than(>), numeric entities(&"'<>)
ampersand(&), double quote("), single quote('), less than(<), greater
than(>), numeric entities(&"'<>)
Only the LAST line (with ENT_HTML5 set) does NOT double-encode.
--
Edit bug report at https://bugs.php.net/bug.php?id=80928&edit=1
--
Fix committed: https://bugs.php.net/fix.php?id=80928&r=fixed
Fixed in release: https://bugs.php.net/fix.php?id=80928&r=alreadyfixed
Need backtrace: https://bugs.php.net/fix.php?id=80928&r=needtrace
Need Reproduce Script: https://bugs.php.net/fix.php?id=80928&r=needscript
Try newer version: https://bugs.php.net/fix.php?id=80928&r=oldversion
Not developer issue: https://bugs.php.net/fix.php?id=80928&r=support
Expected behavior: https://bugs.php.net/fix.php?id=80928&r=notwrong
Not enough info: https://bugs.php.net/fix.php?id=80928&r=notenoughinfo
Submitted twice: https://bugs.php.net/fix.php?id=80928&r=submittedtwice
register_globals: https://bugs.php.net/fix.php?id=80928&r=globals
PHP version support discontinued: https://bugs.php.net/fix.php?id=80928&r=phptooold
Daylight Savings: https://bugs.php.net/fix.php?id=80928&r=dst
IIS Stability: https://bugs.php.net/fix.php?id=80928&r=isapi
Install GNU Sed: https://bugs.php.net/fix.php?id=80928&r=gnused
Floating point limitations: https://bugs.php.net/fix.php?id=80928&r=float
No Zend Extensions: https://bugs.php.net/fix.php?id=80928&r=nozend
MySQL Configuration Error: https://bugs.php.net/fix.php?id=80928&r=mysqlcfg