PHP 4.0 Bug #6625 Updated: htmlspecialchars should escape "'" character

From: Date: Tue, 12 Sep 2000 03:53:38 +0000
Subject: PHP 4.0 Bug #6625 Updated: htmlspecialchars should escape "'" character
Groups: php.dev 
Request: Send a blank email to php-dev+get-32928@lists.php.net to get a copy of this message
ID: 6625 Updated by: cmv Reported By: jon+php-dev@unequivocal.co.uk Status: Feedback Bug Type: Feature/Change Request Assigned To: cmv Comments: Change the quotes around your PHP code to double quotes, and it works just fine. As for escaping neither, I hope you agree that would just be silly. Again, the reason this function was (erroneously) changed in the first place was because of this comment: > Because a ' is used for db queries and I think it's pretty > standard behaviour to escape it as well. > For example if you use PHP together with Javascript, > it's much easier if it's escaped. In the first case (DB), use addslashes() or turn magic quotes on. In the second case (JS), you can use addslashes() also, or urlencode() or strtr(). Besides, if you want an apostrophe in your database field, you should be using "\'", not "&#039;". Otherwise, you're going to get the 6-character string "&#039;" out of the database, not the one-character single quote. Then what function do you use to convert it back to single-quotes? Previous Comments: --------------------------------------------------------------------------- [2000-09-08 08:49:25] jon+php-dev@unequivocal.co.uk I will add a note to the manual. I am mystified as to what code could be broken by escaping additional characters, however. Could one of the people who had some code which broke give us an excerpt so we can understand the problem? --------------------------------------------------------------------------- [2000-09-08 08:41:09] waldschrott@php.net we cannot simply break backwards compatibility, maybe we should add another function or an optional parameter to this one where *both* are converted there have never been complaints about this shortcoming as opposed to where scripts broke changing this function (month ago or so) --------------------------------------------------------------------------- [2000-09-08 06:19:59] jon+php-dev@unequivocal.co.uk Please first see bug report #5254. Either this function should not escape '"', or it *should* escape "'". These characters are equivalent in HTML. For proof, see http://www.w3.org/TR/html4/intro/sgmltut.html#h-3.2.2 . If you do not escape "'", then the following will not work: <input type='hidden' name='foo' value='<? echo htmlspecialchars($foo) ?>'> Please do not tell me that the above HTML is not valid without reading the URL I have given first. I do not understand the arguments put in #5254 about databases. What has this function got to do with databases? --------------------------------------------------------------------------- Full Bug description available at: http://bugs.php.net/?id=6625

« previous php.dev (#32928) next »