[php-src] Issue #8006: var_dump() function displays certain strings incorrectly

From: Date: Fri, 28 Jan 2022 21:15:17 +0000
Subject: [php-src] Issue #8006: var_dump() function displays certain strings incorrectly
Groups: php.bugs 
Request: Send a blank email to php-bugs+get-239335@lists.php.net to get a copy of this message
Issue: https://github.com/php/php-src/issues/8006 Author: canajun2eh ### Description When the var_dump() function is asked to display the contents of a string that contains possible HTML (the text is enclosed in angle brackets) , no attempt is made to show those angle brackets . This results in the browser's rendering engine trying to execute the HTML. If the string contains HTML entities, no attempt is made to show the actual HTML entity; the browser's rendering engine will then try to display the graphic equivalent of that HTML entity. For example, if the following is executed: ``` $string = "some text <with other text inside angle brackets>"; var_dump($string); ``` we are told that $string is a string with length 49, having the value some text . Note the trailing blank. The missing text is interpreted by the browser's rendering engine as illegal HTML and is therefore discarded. Similarly, if the text inside the angle brackets is legal HTML, the browser's rendering wngine will attempt to execute that HTML. This behaviour is undesirable. The var_dump function should ensure that, when the input is a string, the value of that string is fully printable by replacing the angle brackets with their corresponding HTML entities &lt; and &gt;. In addition to this, any ampersands in the string should be replaced by their HTML entity &amp; so that the value displayed by the var_dump function reflects the actual contents of the string. ### PHP Version not relevant ### Operating System not relevant

« previous php.bugs (#239335) next »