Bug #80928 [Com]: htmlspecialchars double-encodes "

From: Date: Fri, 02 Apr 2021 20:18:07 +0000
Subject: Bug #80928 [Com]: htmlspecialchars double-encodes "
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233130@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80928&edit=1 ID: 80928 Comment by: rowan dot collins at gmail dot com Reported by: ASchmidt at Anamera dot net Summary: htmlspecialchars double-encodes &quot; Status: Open Type: Bug Package: Unknown/Other Function Operating System: Windows PHP Version: 7.4.16 Block user comment: N Private report: N New Comment: Your description of the current behaviour is incorrect: the difference in output is for single quote(&apos;) not double quote(&quot;). This matches the documented default behaviour: > ENT_COMPAT Will convert double-quotes and leave single-quotes alone. &apos; is recognised for ENT_XML1, ENT_XHTML or ENT_HTML5 only, since this named entity is not part of the HTML 4 standard. Previous Comments: ------------------------------------------------------------------------ [2021-04-02 19:37:17] ASchmidt at Anamera dot net Description: ------------ According to manual "when double_encode is turned off PHP will not encode existing html entities". No pre-condition is stated. However, &quot; is double-encoded, UNLESS flag ENT_HTML5 is set. Setting either ENT_COMPAT or ENT_NOQUOTES or ENT_QUOTES does NOT alter the outcome, nor is any other entity subject to this bug; it appears to be a unique combination of &quot; and the lack of ENT_HTML5. Test script: --------------- declare(strict_types=1); $text = 'ampersand(&amp;), double quote(&quot;), single quote(&apos;), less than(&lt;), greater than(&gt;), numeric entities(&#x26;&#x22;&#x27;&#x3C;&#x3E;)'; $result1 = htmlspecialchars( $text, ENT_COMPAT | ENT_SUBSTITUTE, 'UTF-8', false ); $result2 = htmlspecialchars( $text, ENT_NOQUOTES | ENT_SUBSTITUTE, 'UTF-8', false ); $result3 = htmlspecialchars( $text, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8', false ); $result4 = htmlspecialchars( $text, ENT_QUOTES | ENT_HTML5 | ENT_SUBSTITUTE, 'UTF-8', false ); echo "<br />\r\n", $result1, "<br />\r\n", $result2, "<br />\r\n", $result3, "<br />\r\n", $result4, "<br />\r\n"; Expected result: ---------------- Four identical rows of: ampersand(&), double quote("), single quote("), less than(<), greater than(>), numeric entities(&"'<>) Actual result: -------------- ampersand(&), double quote("), single quote(&apos;), less than(<), greater than(>), numeric entities(&"'<>) ampersand(&), double quote("), single quote(&apos;), less than(<), greater than(>), numeric entities(&"'<>) ampersand(&), double quote("), single quote(&apos;), less than(<), greater than(>), numeric entities(&"'<>) ampersand(&), double quote("), single quote('), less than(<), greater than(>), numeric entities(&"'<>) Only the LAST line (with ENT_HTML5 set) does NOT double-encode. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=80928&edit=1

« previous php.bugs (#233130) next »