Bug #80928 [Opn]: htmlspecialchars double-encodes '

From: Date: Fri, 02 Apr 2021 21:03:25 +0000
Subject: Bug #80928 [Opn]: htmlspecialchars double-encodes '
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-233131@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=80928&edit=1

 ID:                 80928
 User updated by:    ASchmidt at Anamera dot net
 Reported by:        ASchmidt at Anamera dot net
-Summary:            htmlspecialchars double-encodes "
+Summary:            htmlspecialchars double-encodes '
 Status:             Open
 Type:               Bug
 Package:            Unknown/Other Function
 Operating System:   Windows
 PHP Version:        7.4.16
 Block user comment: N
 Private report:     N

 New Comment:

Correct - the title of my bug report was misstated as well as the description. (Rats... I tested too
many combinations with too many different quotes until my eyes were corossed...)

I'll to correct the bug report title to:
htmlspecialchars double-encodes '

>> This matches the documented default behaviour <<

I fully understand the relevance of &apos; vs. HTML 4 - and why a numeric entity is used for
HTML 4, whenever a single quote IS actually encoded.

However, THAT is not a factor in THIS case. The "double-encoding" is set FALSE,
consequently NO double-encoding of any AMPERSAND-entity should take place. The user expressly opted
AGAINST double-encoding because he did NOT want '&...;' strings to be displayed on his
page.

Very importantly, the documentation does NOT imply that the double_encode option will also perform
HTML-entity validation, e.g., it does not qualify:

"when double_encode is turned off PHP will not encode existing html entities ***as long as they
are valid for the chosen document type***."


Previous Comments:
------------------------------------------------------------------------
[2021-04-02 20:18:07] rowan dot collins at gmail dot com

Your description of the current behaviour is incorrect: the difference in output is for single
quote(&apos;) not double quote(&quot;).

This matches the documented default behaviour:

> ENT_COMPAT 	Will convert double-quotes and leave single-quotes alone.

&apos; is recognised for ENT_XML1, ENT_XHTML or ENT_HTML5 only, since this named entity is not
part of the HTML 4 standard.

------------------------------------------------------------------------
[2021-04-02 19:37:17] ASchmidt at Anamera dot net

Description:
------------
According to manual "when double_encode is turned off PHP will not encode existing html
entities". No pre-condition is stated.

However, &quot; is double-encoded, UNLESS flag ENT_HTML5 is set.

Setting either ENT_COMPAT or ENT_NOQUOTES or ENT_QUOTES does NOT alter the outcome, nor is any other
entity subject to this bug; it appears to be a unique combination of &quot; and the lack of
ENT_HTML5.

Test script:
---------------
declare(strict_types=1);
$text = 'ampersand(&amp;), double quote(&quot;), single quote(&apos;), less
than(&lt;), greater than(&gt;), numeric
entities(&#x26;&#x22;&#x27;&#x3C;&#x3E;)';
$result1 = htmlspecialchars( $text, ENT_COMPAT | ENT_SUBSTITUTE, 'UTF-8', false );
$result2 = htmlspecialchars( $text, ENT_NOQUOTES | ENT_SUBSTITUTE, 'UTF-8', false );
$result3 = htmlspecialchars( $text, ENT_QUOTES | ENT_SUBSTITUTE, 'UTF-8', false );
$result4 = htmlspecialchars( $text, ENT_QUOTES | ENT_HTML5 | ENT_SUBSTITUTE, 'UTF-8',
false );

echo "<br />\r\n", $result1, "<br />\r\n", $result2, "<br
/>\r\n", $result3, "<br />\r\n", $result4, "<br />\r\n";


Expected result:
----------------
Four identical rows of:

ampersand(&), double quote("), single quote("), less than(<), greater than(>),
numeric entities(&"'<>)


Actual result:
--------------
ampersand(&), double quote("), single quote(&apos;), less than(<), greater
than(>), numeric entities(&"'<>)
ampersand(&), double quote("), single quote(&apos;), less than(<), greater
than(>), numeric entities(&"'<>)
ampersand(&), double quote("), single quote(&apos;), less than(<), greater
than(>), numeric entities(&"'<>)
ampersand(&), double quote("), single quote('), less than(<), greater than(>),
numeric entities(&"'<>)

Only the LAST line (with ENT_HTML5 set) does NOT double-encode.


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=80928&edit=1


Thread (5 messages)

« previous php.bugs (#233131) next »