PHP 4.0 Bug #6625 Updated: htmlspecialchars should escape "'" character

From: Date: Fri, 08 Sep 2000 12:41:09 +0000
Subject: PHP 4.0 Bug #6625 Updated: htmlspecialchars should escape "'" character
Groups: php.dev 
Request: Send a blank email to php-dev+get-32652@lists.php.net to get a copy of this message
ID: 6625 Updated by: waldschrott Reported By: jon+php-dev@unequivocal.co.uk Status: Analyzed Bug Type: Feature/Change Request Assigned To: Comments: we cannot simply break backwards compatibility, maybe we should add another function or an optional parameter to this one where *both* are converted there have never been complaints about this shortcoming as opposed to where scripts broke changing this function (month ago or so) Previous Comments: --------------------------------------------------------------------------- [2000-09-08 06:19:59] jon+php-dev@unequivocal.co.uk Please first see bug report #5254. Either this function should not escape '"', or it *should* escape "'". These characters are equivalent in HTML. For proof, see http://www.w3.org/TR/html4/intro/sgmltut.html#h-3.2.2 . If you do not escape "'", then the following will not work: <input type='hidden' name='foo' value='<? echo htmlspecialchars($foo) ?>'> Please do not tell me that the above HTML is not valid without reading the URL I have given first. I do not understand the arguments put in #5254 about databases. What has this function got to do with databases? --------------------------------------------------------------------------- Full Bug description available at: http://bugs.php.net/?id=6625

« previous php.dev (#32652) next »