PHP 4.0 Bug #6625 Updated: htmlspecialchars should escape "'" character

From: Date: Fri, 08 Sep 2000 12:49:25 +0000
Subject: PHP 4.0 Bug #6625 Updated: htmlspecialchars should escape "'" character
Groups: php.dev 
Request: Send a blank email to php-dev+get-32654@lists.php.net to get a copy of this message
ID: 6625 User Update by: jon+php-dev@unequivocal.co.uk Old-Status: Analyzed Status: Feedback Bug Type: Feature/Change Request Description: htmlspecialchars should escape "'" character I will add a note to the manual. I am mystified as to what code could be broken by escaping additional characters, however. Could one of the people who had some code which broke give us an excerpt so we can understand the problem? Previous Comments: --------------------------------------------------------------------------- [2000-09-08 08:41:09] waldschrott@php.net we cannot simply break backwards compatibility, maybe we should add another function or an optional parameter to this one where *both* are converted there have never been complaints about this shortcoming as opposed to where scripts broke changing this function (month ago or so) --------------------------------------------------------------------------- [2000-09-08 06:19:59] jon+php-dev@unequivocal.co.uk Please first see bug report #5254. Either this function should not escape '"', or it *should* escape "'". These characters are equivalent in HTML. For proof, see http://www.w3.org/TR/html4/intro/sgmltut.html#h-3.2.2 . If you do not escape "'", then the following will not work: <input type='hidden' name='foo' value='<? echo htmlspecialchars($foo) ?>'> Please do not tell me that the above HTML is not valid without reading the URL I have given first. I do not understand the arguments put in #5254 about databases. What has this function got to do with databases? --------------------------------------------------------------------------- Full Bug description available at: http://bugs.php.net/?id=6625

« previous php.dev (#32654) next »