PHP 4.0 Bug #6625 Updated: htmlspecialchars should escape "'" character

From: Date: Tue, 12 Sep 2000 04:07:03 +0000
Subject: PHP 4.0 Bug #6625 Updated: htmlspecialchars should escape "'" character
Groups: php.dev 
Request: Send a blank email to php-dev+get-32931@lists.php.net to get a copy of this message
ID: 6625 User Update by: jon+php-dev@unequivocal.co.uk Status: Feedback Bug Type: Feature/Change Request Description: htmlspecialchars should escape "'" character You're making it very difficult to remain polite here. I shall summarise in nice easy-to-understand bite-size pieces: It is nothing to do with databases. Databases are nothing to do with it. It is to do with HTML. Not databases. The apostrophe is a special character in HTML. htmlspecialchars is supposed to encode all characters that are special to HMTL. It does not, because it does not encode apostrophes. Backslashes are not the correct way to encode characters in HTML. Entities are the correct way to encode characters. As you can tell by what this function does with other special characters. The function is broken until it encodes apostrophes. The only reason not to make it encode apostrophes would be for reasons of backwards compatibility. Making it encode extra characters is highly unlikely to break old code. You said in a previous bug report that it did, in fact, break code that you had. So it would be helpful if you could explain how, so that the problem could be understood. Previous Comments: --------------------------------------------------------------------------- [2000-09-11 23:53:38] cmv@php.net Change the quotes around your PHP code to double quotes, and it works just fine. As for escaping neither, I hope you agree that would just be silly. Again, the reason this function was (erroneously) changed in the first place was because of this comment: > Because a ' is used for db queries and I think it's pretty > standard behaviour to escape it as well. > For example if you use PHP together with Javascript, > it's much easier if it's escaped. In the first case (DB), use addslashes() or turn magic quotes on. In the second case (JS), you can use addslashes() also, or urlencode() or strtr(). Besides, if you want an apostrophe in your database field, you should be using "'", not "&#039;". Otherwise, you're going to get the 6-character string "&#039;" out of the database, not the one-character single quote. Then what function do you use to convert it back to single-quotes? --------------------------------------------------------------------------- [2000-09-08 08:49:25] jon+php-dev@unequivocal.co.uk I will add a note to the manual. I am mystified as to what code could be broken by escaping additional characters, however. Could one of the people who had some code which broke give us an excerpt so we can understand the problem? --------------------------------------------------------------------------- [2000-09-08 08:41:09] waldschrott@php.net we cannot simply break backwards compatibility, maybe we should add another function or an optional parameter to this one where *both* are converted there have never been complaints about this shortcoming as opposed to where scripts broke changing this function (month ago or so) --------------------------------------------------------------------------- [2000-09-08 06:19:59] jon+php-dev@unequivocal.co.uk Please first see bug report #5254. Either this function should not escape '"', or it *should* escape "'". These characters are equivalent in HTML. For proof, see http://www.w3.org/TR/html4/intro/sgmltut.html#h-3.2.2 . If you do not escape "'", then the following will not work: <input type='hidden' name='foo' value='<? echo htmlspecialchars($foo) ?>'> Please do not tell me that the above HTML is not valid without reading the URL I have given first. I do not understand the arguments put in #5254 about databases. What has this function got to do with databases? --------------------------------------------------------------------------- Full Bug description available at: http://bugs.php.net/?id=6625

« previous php.dev (#32931) next »