PHP 4.0 Bug #6625 Updated: htmlspecialchars should escape "'" character
| From: | Bug Database | Date: | Fri, 08 Sep 2000 12:41:09 +0000 |
| Subject: | PHP 4.0 Bug #6625 Updated: htmlspecialchars should escape "'" character | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-32652@lists.php.net to get a copy of this message | ||
ID: 6625
Updated by: waldschrott
Reported By: jon+php-dev@unequivocal.co.uk
Status: Analyzed
Bug Type: Feature/Change Request
Assigned To:
Comments:
we cannot simply break backwards compatibility, maybe we should add another function or an optional
parameter to this one where *both* are converted
there have never been complaints about this shortcoming as opposed to where scripts broke changing
this function (month ago or so)
Previous Comments:
---------------------------------------------------------------------------
[2000-09-08 06:19:59] jon+php-dev@unequivocal.co.uk
Please first see bug report #5254.
Either this function should not escape '"', or it *should* escape "'".
These characters are equivalent in HTML. For proof, see http://www.w3.org/TR/html4/intro/sgmltut.html#h-3.2.2
.
If you do not escape "'", then the following will not work:
<input type='hidden' name='foo' value='<? echo htmlspecialchars($foo)
?>'>
Please do not tell me that the above HTML is not valid without reading the URL I have given first.
I do not understand the arguments put in #5254 about databases. What has this function got to do
with databases?
---------------------------------------------------------------------------
Full Bug description available at: http://bugs.php.net/?id=6625