Bug #71577 [Opn->Ver]: filter_var / FILTER_SANITIZE_FULL_SPECIAL_CHARS differs from htmlspecialchars

From: Date: Thu, 10 Jun 2021 11:41:26 +0000
Subject: Bug #71577 [Opn->Ver]: filter_var / FILTER_SANITIZE_FULL_SPECIAL_CHARS differs from htmlspecialchars
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234329@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=71577&edit=1

 ID:                 71577
 Updated by:         cmb@php.net
 Reported by:        stheine at arcor dot de
 Summary:            filter_var / FILTER_SANITIZE_FULL_SPECIAL_CHARS
                     differs from htmlspecialchars
-Status:             Open
+Status:             Verified
 Type:               Bug
 Package:            Filter related
 Operating System:   Linux
 PHP Version:        5.6.18
 Block user comment: N
 Private report:     N

 New Comment:

Well, FILTER_SANITIZE_FULL_SPECIAL_CHARS is actually equivalent to

    htmlentities($string, ENT_QUOTES, ini_get('default_charset'), false)

See <https://3v4l.org/PStra>.  Note that $double_encode
is off,
and that it's htmlentities() and not htmspecialchars().

> the FILTER_FLAG_ENCODE_AMP flag (which is not even documented
> for that filter)

Right, that should be added.

But frankly, I don't understand why anybody would want to use that
filter on input.  HTML escaping should be done on output, IMHO.


Previous Comments:
------------------------------------------------------------------------
[2016-02-12 16:08:14] stheine at arcor dot de

Description:
------------
documentation ( http://php.net/manual/en/filter.filters.sanitize.php
) states:

filter_var, option FILTER_SANITIZE_FULL_SPECIAL_CHARS: Equivalent to calling htmlspecialchars() with
ENT_QUOTES set.
but in reality, the two differ.

the FILTER_SANITIZE_FULL_SPECIAL_CHARS is missing the FILTER_FLAG_ENCODE_AMP flag (which is not even
documented for that filter) to actually be equivalent to htmlspecialchars() as documented.

Test script:
---------------
$STRING = "1&nbsp;2";
echo htmlspecialchars($STRING, ENT_QUOTES)."\n".
     filter_var($STRING, FILTER_SANITIZE_FULL_SPECIAL_CHARS)."\n";

1&amp;nbsp;2
1&nbsp;2

Expected result:
----------------
following the documentation, I expect 

filter_var("1&nbsp;2", FILTER_SANITIZE_FULL_SPECIAL_CHARS)

to return

1&amp;nbsp;2

Actual result:
--------------
1&nbsp;2


------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=71577&edit=1


Thread (2 messages)

« previous php.bugs (#234329) next »