Bug #80928 [Com]: htmlspecialchars double-encodes "
| From: | rowan dot collins at gmail dot com | Date: | Fri, 02 Apr 2021 20:18:07 +0000 |
| Subject: | Bug #80928 [Com]: htmlspecialchars double-encodes " | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-233130@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=80928&edit=1
ID: 80928
Comment by: rowan dot collins at gmail dot com
Reported by: ASchmidt at Anamera dot net
Summary: htmlspecialchars double-encodes "
Status: Open
Type: Bug
Package: Unknown/Other Function
Operating System: Windows
PHP Version: 7.4.16
Block user comment: N
Private report: N
New Comment:
Your description of the current behaviour is incorrect: the difference in output is for single
quote(') not double quote(").
This matches the documented default behaviour:
> ENT_COMPAT Will convert double-quotes and leave single-quotes alone.
' is recognised for ENT_XML1, ENT_XHTML or ENT_HTML5 only, since this named entity is not
part of the HTML 4 standard.
Previous Comments:
------------------------------------------------------------------------
[2021-04-02 19:37:17] ASchmidt at Anamera dot net
Description:
------------
According to manual "when double_encode is turned off PHP will not encode existing html
entities". No pre-condition is stated.
However, " is double-encoded, UNLESS flag ENT_HTML5 is set.
Setting either ENT_COMPAT or ENT_NOQUOTES or ENT_QUOTES does NOT alter the outcome, nor is any other
entity subject to this bug; it appears to be a unique combination of " and the lack of
ENT_HTML5.
Test script:
---------------
declare(strict_types=1);
$text = 'ampersand(&), double quote("), single quote('), less
than(<), greater than(>), numeric
entities(&"'<>)';
$result1 = htmlspecialchars( $text, ENT_COMPAT | ENT_SUBSTITUTE, 'UTF-8', false );
$result2 = htmlspecialchars( $text, ENT_NOQUOTES | ENT_SUBSTITUTE, 'UTF-8', false );
$result3 = htmlspecialchars( $text, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8', false );
$result4 = htmlspecialchars( $text, ENT_QUOTES | ENT_HTML5 | ENT_SUBSTITUTE, 'UTF-8',
false );
echo "<br />\r\n", $result1, "<br />\r\n", $result2, "<br
/>\r\n", $result3, "<br />\r\n", $result4, "<br />\r\n";
Expected result:
----------------
Four identical rows of:
ampersand(&), double quote("), single quote("), less than(<), greater than(>),
numeric entities(&"'<>)
Actual result:
--------------
ampersand(&), double quote("), single quote('), less than(<), greater
than(>), numeric entities(&"'<>)
ampersand(&), double quote("), single quote('), less than(<), greater
than(>), numeric entities(&"'<>)
ampersand(&), double quote("), single quote('), less than(<), greater
than(>), numeric entities(&"'<>)
ampersand(&), double quote("), single quote('), less than(<), greater than(>),
numeric entities(&"'<>)
Only the LAST line (with ENT_HTML5 set) does NOT double-encode.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80928&edit=1