Req #64137 [Ver->Csd]: XSLTProcessor::setParameter() should allow both quotes to be used
| From: | nielsdos@php.net | Date: | Sat, 30 Sep 2023 19:45:04 +0000 |
| Subject: | Req #64137 [Ver->Csd]: XSLTProcessor::setParameter() should allow both quotes to be used | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-245468@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=64137&edit=1
ID: 64137
Updated by: nielsdos@php.net
Reported by: phpwnd at gmail dot com
Summary: XSLTProcessor::setParameter() should allow both
quotes to be used
-Status: Verified
+Status: Closed
Type: Feature/Change Request
Package: XSLT related
PHP Version: 5.4.11
-Assigned To:
+Assigned To: nielsdos
Block user comment: N
Private report: N
New Comment:
The fix for this bug has been committed.
If you are still experiencing this bug, try to check out latest source from https://github.com/php/php-src and re-test.
Thank you for the report, and for helping us make PHP better.
Implemented in master.
Previous Comments:
------------------------------------------------------------------------
[2013-02-02 20:12:52] phpwnd at gmail dot com
Description:
------------
XSLTProcessor::setParameter() does not currently allow values that contain both single quotes and
double quotes. This appears to be intentional, as per php_xsl_xslt_string_to_xpathexpr() located in
ext/xsl/xsltprocessor.c line 119.
(https://github.com/php/php-src/blob/master/ext/xsl/xsltprocessor.c#L119)
This shortcoming comes from the fact that XPath 1.0 does not provide a mechanism to escape
characters, so PHP does not have a straightforward way to express a string that contains both types
of quotes. XPath 1.0 does, however, provide a function to concatenate strings. Using concat(), a
string composed of the two characters "' can be expressed as
concat('"',"'"). concat() takes 2 or more arguments so as long as you
alternate the quoting style, you can express a string containing any number of quotes of both types.
This is the proposed change: use XPath's concat() function to express strings that contain both
types of quotes.
Test script:
---------------
<?php
$xml = new DOMDocument;
$xml->loadXML('<X/>');
$xsl = new DOMDocument;
$xsl->loadXML('<xsl:stylesheet version="1.0" xmlns:xsl="http://www.w3.org/1999/XSL/Transform"><xsl:output
method="text"/><xsl:param name="foo"/><xsl:template
match="/"><xsl:value-of
select="$foo"/></xsl:template></xsl:stylesheet>');
$xslt = new XSLTProcessor;
$xslt->importStylesheet($xsl);
$xslt->setParameter('', 'foo', "\"'");
echo $xslt->transformToXml($xml);
Expected result:
----------------
"'
Actual result:
--------------
PHP Warning: XSLTProcessor::transformToXml(): Cannot create XPath expression (string contains both
quote and double-quotes) in %s on line %d
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=64137&edit=1