Re: escaping HTML
| From: | Michael Dearman | Date: | Mon, 11 Dec 2000 14:44:45 +0000 |
| Subject: | Re: escaping HTML | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-29681@lists.php.net to get a copy of this message | ||
Jim Carey wrote:
>
> how about ?
>
> <?php
> $sess_name = session_name();
> $sess_id = session_id();
> print ("
> <form action='test1.php' method='post'>
> <input type='hidden' name='$sess_name' value='$sess_id'>
> <input type='submit' value='submit'>
> ");
> ?>
>
I would have thought that the single qoutes would of kept the vars
from being interpolated. But not so! This apparently works.
Apparently? Well, I thought that by some HTML spec that the values needed
to be enclosed in double quotes - that single quotes not by standard. But
my NS4.6 renders the above fine. But will more compliant browsers? Say NS6x?
Mike D.