Edit report at https://bugs.php.net/bug.php?id=80928&edit=1
ID: 80928
User updated by: ASchmidt at Anamera dot net
Reported by: ASchmidt at Anamera dot net
-Summary: htmlspecialchars double-encodes "
+Summary: htmlspecialchars double-encodes '
Status: Open
Type: Bug
Package: Unknown/Other Function
Operating System: Windows
PHP Version: 7.4.16
Block user comment: N
Private report: N
New Comment:
Correct - the title of my bug report was misstated as well as the description. (Rats... I tested too
many combinations with too many different quotes until my eyes were corossed...)
I'll to correct the bug report title to:
htmlspecialchars double-encodes '
>> This matches the documented default behaviour <<
I fully understand the relevance of ' vs. HTML 4 - and why a numeric entity is used for
HTML 4, whenever a single quote IS actually encoded.
However, THAT is not a factor in THIS case. The "double-encoding" is set FALSE,
consequently NO double-encoding of any AMPERSAND-entity should take place. The user expressly opted
AGAINST double-encoding because he did NOT want '&...;' strings to be displayed on his
page.
Very importantly, the documentation does NOT imply that the double_encode option will also perform
HTML-entity validation, e.g., it does not qualify:
"when double_encode is turned off PHP will not encode existing html entities ***as long as they
are valid for the chosen document type***."
Previous Comments:
------------------------------------------------------------------------
[2021-04-02 20:18:07] rowan dot collins at gmail dot com
Your description of the current behaviour is incorrect: the difference in output is for single
quote(') not double quote(").
This matches the documented default behaviour:
> ENT_COMPAT Will convert double-quotes and leave single-quotes alone.
' is recognised for ENT_XML1, ENT_XHTML or ENT_HTML5 only, since this named entity is not
part of the HTML 4 standard.
------------------------------------------------------------------------
[2021-04-02 19:37:17] ASchmidt at Anamera dot net
Description:
------------
According to manual "when double_encode is turned off PHP will not encode existing html
entities". No pre-condition is stated.
However, " is double-encoded, UNLESS flag ENT_HTML5 is set.
Setting either ENT_COMPAT or ENT_NOQUOTES or ENT_QUOTES does NOT alter the outcome, nor is any other
entity subject to this bug; it appears to be a unique combination of " and the lack of
ENT_HTML5.
Test script:
---------------
declare(strict_types=1);
$text = 'ampersand(&), double quote("), single quote('), less
than(<), greater than(>), numeric
entities(&"'<>)';
$result1 = htmlspecialchars( $text, ENT_COMPAT | ENT_SUBSTITUTE, 'UTF-8', false );
$result2 = htmlspecialchars( $text, ENT_NOQUOTES | ENT_SUBSTITUTE, 'UTF-8', false );
$result3 = htmlspecialchars( $text, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8', false );
$result4 = htmlspecialchars( $text, ENT_QUOTES | ENT_HTML5 | ENT_SUBSTITUTE, 'UTF-8',
false );
echo "<br />\r\n", $result1, "<br />\r\n", $result2, "<br
/>\r\n", $result3, "<br />\r\n", $result4, "<br />\r\n";
Expected result:
----------------
Four identical rows of:
ampersand(&), double quote("), single quote("), less than(<), greater than(>),
numeric entities(&"'<>)
Actual result:
--------------
ampersand(&), double quote("), single quote('), less than(<), greater
than(>), numeric entities(&"'<>)
ampersand(&), double quote("), single quote('), less than(<), greater
than(>), numeric entities(&"'<>)
ampersand(&), double quote("), single quote('), less than(<), greater
than(>), numeric entities(&"'<>)
ampersand(&), double quote("), single quote('), less than(<), greater than(>),
numeric entities(&"'<>)
Only the LAST line (with ENT_HTML5 set) does NOT double-encode.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=80928&edit=1