Req #50309 [Opn->Wfx]: Add plain-text sanitizing to filter

From: Date: Thu, 10 Jun 2021 11:58:02 +0000
Subject: Req #50309 [Opn->Wfx]: Add plain-text sanitizing to filter
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-234330@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=50309&edit=1

 ID:                 50309
 Updated by:         cmb@php.net
 Reported by:        marcus at synchromedia dot co dot uk
 Summary:            Add plain-text sanitizing to filter
-Status:             Open
+Status:             Wont fix
 Type:               Feature/Change Request
 Package:            Filter related
 PHP Version:        5.3.1
-Assigned To:        
+Assigned To:        cmb
 Block user comment: N
 Private report:     N

 New Comment:

In my opinion, calling FILTER_FLAG_STRIP_HIGH a bit blunt is a
gross understatement; it is actually unusable for UTF-8[1] (okay,
fortunately that encoding is rarely used for the Web ;)

And that raises the question what should be regarded as
whitespace; Unicode has a lot more whitespace characters than
ASCII.  It's probably best to use regexps which can be tuned for
the application at hand, or a userland library.

Anyhow, given that there has been no feedback on this ticket for
more than ten years, I'm closing as WONTFIX.

If you, or anybody else is still interested in this, please pursue
the RFC process[2].

[1] <https://3v4l.org/VhvYS>
[2] <https://wiki.php.net/rfc/howto>


Previous Comments:
------------------------------------------------------------------------
[2009-11-27 09:52:42] marcus at synchromedia dot co dot uk

Description:
------------
While the FILTER_FLAG_STRIP_LOW and FILTER_FLAG_STRIP_HIGH flags used 
with FILTER_SANITIZE_STRING work fine, They are just a bit blunt to be 
useful in practice. A more normal application would be to remove any 
'funny' characters from plain text, so for example to allow chars 9, 10, 
13, 32-126. This could be called FILTER_FLAG_PLAIN_TEXT. While this 
could be done using regex, it's probably the most common use case, so 
deserves a dedicated filter flag. This could be flipped around and be 
called FILTER_FLAG_ALLOW_WHITESPACE, overriding STRIP_LOW to allow chars 
9, 10, 13 through.

Similarly, a very common need is to normalize line breaks to \n, \r\n or 
\r.



------------------------------------------------------------------------



--
Edit this bug report at https://bugs.php.net/bug.php?id=50309&edit=1


Thread (2 messages)

« previous php.bugs (#234330) next »