[php-src] Issue #8006: var_dump() function displays certain strings incorrectly
| From: | canajun2eh | Date: | Fri, 28 Jan 2022 21:15:17 +0000 |
| Subject: | [php-src] Issue #8006: var_dump() function displays certain strings incorrectly | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-239335@lists.php.net to get a copy of this message | ||
Issue: https://github.com/php/php-src/issues/8006
Author: canajun2eh
### Description
When the
var_dump() function is asked to display the contents of a string that contains
possible HTML (the text is enclosed in angle brackets) , no attempt is made to show those angle
brackets . This results in the browser's rendering engine trying to execute the HTML. If the
string contains HTML entities, no attempt is made to show the actual HTML entity; the browser's
rendering engine will then try to display the graphic equivalent of that HTML entity.
For example, if the following is executed:
```
$string = "some text <with other text inside angle brackets>";
var_dump($string);
```
we are told that $string is a string with length 49, having the value some text
. Note the trailing blank. The missing text is interpreted by the browser's rendering
engine as illegal HTML and is therefore discarded. Similarly, if the text inside the angle brackets
is legal HTML, the browser's rendering wngine will attempt to execute that HTML. This behaviour
is undesirable.
The var_dump function should ensure that, when the input is a string, the value of that
string is fully printable by replacing the angle brackets with their corresponding HTML entities
< and >.
In addition to this, any ampersands in the string should be replaced by their HTML entity
& so that the value displayed by the var_dump function reflects
the actual contents of the string.
### PHP Version
not relevant
### Operating System
not relevant