Doc #60401 [Com]: Example 4 results in double quotes slashed
| From: | hello at apfelbox dot net | Date: | Sun, 04 Dec 2011 21:41:12 +0000 |
| Subject: | Doc #60401 [Com]: Example 4 results in double quotes slashed | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-7566@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=60401&edit=1
ID: 60401
Comment by: hello at apfelbox dot net
Reported by: jf at jonathanfoote dot com
Summary: Example 4 results in double quotes slashed
Status: Re-Opened
Type: Documentation Problem
Package: Documentation problem
Operating System: Windows
PHP Version: 5.3.8
Assigned To: frozenfire
Block user comment: N
Private report: N
New Comment:
You could just advise people to use preg_replace_callback() instead of preg_replace() with the
modifier e. It is also safer, because preg_replace() with modifier does imply the eval(), which is
considered unsafe (if you are dealing with user input here).
Previous Comments:
------------------------------------------------------------------------
[2011-12-04 21:35:15] frozenfire@php.net
After seeking some clarification from others, it would seem that eval modifier
is completely idiotic. Pardon my wording, but it really is.
Since it's escaping slashes, and the string is being placed in single quotes in
the replace statement, the single quotes get slashed, then it looks like this:
'\''
So you end up with literal single quotes with no slash
Whereas the double-quotes end up like: '\"'
Which is a double-quote still slashed.
Any example I can give will either avoid using quotes, or will confuse the hell
out of people.
------------------------------------------------------------------------
[2011-12-04 21:01:05] frozenfire@php.net
Err, just after writing that, I felt really silly. I forgot to assign the result
of the preg_replace to a function. It does seem you're right, but I cannot figure
out why.
------------------------------------------------------------------------
[2011-12-04 20:59:19] frozenfire@php.net
I'm finding that it doesn't escape any of the quotes at all. That seems to be
because the backreference that's being run through the strtoupper function is
does not contain either of the tag's attributes.
It would only escape any quotes in the tag name, it would seem.
<?php
$html_body = "<div class=\"test\" style='display: none;' >";
preg_replace("/(<\/?)(\w+)([^>]*>)/e",
"'\\1'.strtoupper('\\2').'\\3'",
$html_body);
echo $html_body;
// Outputs: <div class="test" style='display: none;'>
------------------------------------------------------------------------
[2011-12-03 07:31:35] jf at jonathanfoote dot com
Since it surrounds \\3 with single quotes, the end resulting string does not have
single quotes escaped, just double quotes and I assume null. If for example, you
were to run example #4 on the following:
<div class="test" style='display: none;'>
result:
<DIV class=\"test\" style='display: none;'>
------------------------------------------------------------------------
[2011-12-03 04:28:36] frozenfire@php.net
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation better.
------------------------------------------------------------------------
The remainder of the comments for this report are too long. To view
the rest of the comments, please view the bug report online at
https://bugs.php.net/bug.php?id=60401
--
Edit this bug report at https://bugs.php.net/bug.php?id=60401&edit=1