Req #64137 [Ver->Csd]: XSLTProcessor::setParameter() should allow both quotes to be used

From: Date: Sat, 30 Sep 2023 19:45:04 +0000
Subject: Req #64137 [Ver->Csd]: XSLTProcessor::setParameter() should allow both quotes to be used
References: 1  Groups: php.bugs 
Request: Send a blank email to php-bugs+get-245468@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=64137&edit=1 ID: 64137 Updated by: nielsdos@php.net Reported by: phpwnd at gmail dot com Summary: XSLTProcessor::setParameter() should allow both quotes to be used -Status: Verified +Status: Closed Type: Feature/Change Request Package: XSLT related PHP Version: 5.4.11 -Assigned To: +Assigned To: nielsdos Block user comment: N Private report: N New Comment: The fix for this bug has been committed. If you are still experiencing this bug, try to check out latest source from https://github.com/php/php-src and re-test. Thank you for the report, and for helping us make PHP better. Implemented in master. Previous Comments: ------------------------------------------------------------------------ [2013-02-02 20:12:52] phpwnd at gmail dot com Description: ------------ XSLTProcessor::setParameter() does not currently allow values that contain both single quotes and double quotes. This appears to be intentional, as per php_xsl_xslt_string_to_xpathexpr() located in ext/xsl/xsltprocessor.c line 119. (https://github.com/php/php-src/blob/master/ext/xsl/xsltprocessor.c#L119) This shortcoming comes from the fact that XPath 1.0 does not provide a mechanism to escape characters, so PHP does not have a straightforward way to express a string that contains both types of quotes. XPath 1.0 does, however, provide a function to concatenate strings. Using concat(), a string composed of the two characters "' can be expressed as concat('"',"'"). concat() takes 2 or more arguments so as long as you alternate the quoting style, you can express a string containing any number of quotes of both types. This is the proposed change: use XPath's concat() function to express strings that contain both types of quotes. Test script: --------------- <?php $xml = new DOMDocument; $xml->loadXML('<X/>'); $xsl = new DOMDocument; $xsl->loadXML('<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform"><xsl:output method="text"/><xsl:param name="foo"/><xsl:template match="/"><xsl:value-of select="$foo"/></xsl:template></xsl:stylesheet>'); $xslt = new XSLTProcessor; $xslt->importStylesheet($xsl); $xslt->setParameter('', 'foo', "\"'"); echo $xslt->transformToXml($xml); Expected result: ---------------- "' Actual result: -------------- PHP Warning: XSLTProcessor::transformToXml(): Cannot create XPath expression (string contains both quote and double-quotes) in %s on line %d ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=64137&edit=1

« previous php.bugs (#245468) next »