Doc #62341 [Opn]: Secure behavior htmlspecialchars() not reflected in the documentation

From: Date: Sun, 17 Jun 2012 10:25:58 +0000
Subject: Doc #62341 [Opn]: Secure behavior htmlspecialchars() not reflected in the documentation
References: 1  Groups: php.doc.bugs 
Request: Send a blank email to doc-bugs+get-8475@lists.php.net to get a copy of this message
Edit report at https://bugs.php.net/bug.php?id=62341&edit=1 ID: 62341 User updated by: bfanger at gmail dot com Reported by: bfanger at gmail dot com -Summary: htmlspecialchars() should work on ascii compatible encodings by default. +Summary: Secure behavior htmlspecialchars() not reflected in the documentation Status: Open Type: Documentation Problem Package: Documentation problem PHP Version: 5.4.4 Block user comment: N Private report: N New Comment: Updated summary to "Secure behavior htmlspecialchars() not reflected in the documentation" My initial change request "htmlspecialchars() should work on ascii compatible encodings by default" no longer applies. After some research agree with the new behavior. Previous Comments: ------------------------------------------------------------------------ [2012-06-17 10:06:34] bfanger at gmail dot com Description: ------------ In PHP 5.4 the default encoding for htmlentities is changed to 'UTF-8', When a ISO-8859-1 encoded string with a special character is passed to the htmlspecialchars() it returns an empty string (invalid mutlibyte sequence) This is the new intended (and more secure) behavior, and i agree, but... The old default (ISO-8859-1) worked on both UTF-8, ISO-8859-1 and other ascii compatible encodings, which is reflected in the documentation: "Calling htmlspecialchars() is sufficient if the encoding supports all characters in the input string (such us UTF-8 but also ISO-8859-1 on ISO-8859-1 only input). htmlentities() needs to be called only if the output encoding doesn't support all characters in the input string." This is no longer the case, unless ENT_IGNORE is passed. Solution: Drop the paragraph from the documentation. PS: You might wan't to add a paragraph that incorrect encoded text will cause htmlspecialschars() to return an empty string. ------------------------------------------------------------------------ -- Edit this bug report at https://bugs.php.net/bug.php?id=62341&edit=1

« previous php.doc.bugs (#8475) next »