#32619 [Opn]: ext/session: Valid XHTML output
| From: | sniper@php.net | Date: | Thu, 07 Apr 2005 15:46:10 +0000 |
| Subject: | #32619 [Opn]: ext/session: Valid XHTML output | ||
| References: | 1 | Groups: | php.bugs |
| Request: | Send a blank email to php-bugs+get-76485@lists.php.net to get a copy of this message | ||
ID: 32619
Updated by: sniper@php.net
-Summary: Valid XHTML output
Reported By: nick at terado dot co dot uk
Status: Open
-Bug Type: Session related
+Bug Type: Feature/Change Request
Operating System: Debian
PHP Version: 4.3.10
New Comment:
reclassified.
Previous Comments:
------------------------------------------------------------------------
[2005-04-07 10:05:13] nick at terado dot co dot uk
Description:
------------
Firstly, this relates to bug #23694
I warrant this being reopened. Upsetting the validity of a webpages
code by using php is a bug. The method to correct this is neither
logical nor sensible. The requirement should not be on the server
administrator to dictate what HTML version should be used to create
webpages.
There are two problems here:
1. first ampersands withing url query strings when modified to append
the session information.
2. Forms, where a hidden session id input tag will be inserted, however
not enclosed by a block level element.
Details and Resolution:
1. The recommended fix so far by the php team is to enable in php.ini
the modifier arg_separator.output="&".
Firstly, modification of the php.ini is restrictive. Secondly, using
& in HTML 4 works also, it is standard practice to encode
ampersands properly and there is no reason at all not to have this
enabled by default. If there is any other reason, then just as you
would output <br> as <br /> then you should output correctly & as &
when using XHTML.
However, I repeat using & should be default practice.
2. The recommended fix given so far is to change to
url_rewriter.tags = "a=href,area=href,frame=src,input=src,fieldset="
therefore, omitting form=fakeentry.
Again, the practice of modifying (if possible) the php.ini to set the
HTML is bad news and restrictive. Also by now omitting the form=
setting of the modifier we now cant guarantee the session variable will
be added, fieldset is not the only choice of block level element within
the form element. Therefore, to complement this often an empty
<fieldset> must be inserted, simply to accommodate the session variable
addition.
There are simple fixes to this. If the HTML version is known then
<fieldset> can be output around the hidden element. This is no way
upset layout, having no content or white space nothing is output and no
shifting on the webpage occurs. Secondly, <div> can be used. This
therefore allows backwards compatibility and can be output as a rule.
However, I wouldnt know how older browsers would deal with the div -
that is whether it would cause spacing issues. However, the point here
is this should be a default or transparent action, the effort to "fix"
this is nothing more than asking the coder to hack there way out of
what exists as a bug.
This may not be a bug in performance or operation of php itself, but
when php itself is outputting HTML and this output is incorrect, this
completely warrants a bug report being opened. The solutions
recommended are both not fixes and have other problems associated with
them. The solution to this seems quite simple however.
Nick
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=32619&edit=1