Bug #25248 [Com]: SESSION encoding in urls should use HTML entities not ampersands

From: Date: Wed, 01 Sep 2021 18:52:16 +0000
Subject: Bug #25248 [Com]: SESSION encoding in urls should use HTML entities not ampersands
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-236319@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=25248&edit=1 ID: 25248 Comment by: lildurk25248 at gmail dot com Reported by: js at nomensa dot com Summary: SESSION encoding in urls should use HTML entities not ampersands Status: Not a bug Type: Bug Package: Output Control Operating System: all PHP Version: 4.3.2 Block user comment: N Private report: N New Comment: Lil Durk is a private agency dedicated to providing responsible access to legal cannabis for adults aged 19 and older. We’re an exclusively online retailer and wholesaler for recreational cannabis and a trusted source for information about cannabis and cannabis-related issues. We believe our work is meaningful and we take pride in our mandate to promote the socially responsible use of legal cannabis. https://lildurk.com/ Previous Comments: ------------------------------------------------------------------------ [2003-08-26 06:31:22] derick@php.net Thank you for taking the time to write to us, but this is not a bug. Please double-check the documentation available at http://www.php.net/manual/ and the instructions on how to report a bug at http://bugs.php.net/how-to-report.php See the php.ini setting arg_separator.output ------------------------------------------------------------------------ [2003-08-26 06:06:13] js at nomensa dot com Description: ------------ When cookies are disabled php encodes a session id in the output urls. It currently uses single ampersands '&' but this is illegal in XHTML (and slightly illegal in HTML), the ampersand character in <a> links etc should be encoded as the entity '&amp;'. Additionally semi-colons could also be used to get around this whole mess. Actually, I prefer semi-colons. It would be good if PHP supported this. Reproduce code: --------------- Go to this link with cookies off: http://alastc.homeip.net/alastairc/page.php Expected result: ---------------- Url should be encoded properly: Should be written as: <li><a href="page.php?domain=&amp;type=news&amp;PHPSESSID=ef38d5d3bc286f6e1de5581003d710d5">News</a></li> Actual result: -------------- Links are written illegally: <li><a href="page.php?domain=&amp;type=news&PHPSESSID=ef38d5d3bc286f6e1de5581003d710d5">News</a></li> This fails the DTD check under XHTML 1.0 (strict) ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=25248&edit=1

« previous php.bugs (#236319) next »