Re: escaping HTML

From: Date: Tue, 12 Dec 2000 00:42:22 +0000
Subject: Re: escaping HTML
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-29785@lists.php.net to get a copy of this message
> Jim Carey wrote: > > > > how about ? > > > > <?php > > $sess_name = session_name(); > > $sess_id = session_id(); > > print (" > > <form action='test1.php' method='post'> > > <input type='hidden' name='$sess_name' > > value='$sess_id'> > > <input type='submit' value='submit'> > > "); > > ?> > > > > I would have thought that the single qoutes would of kept the vars > from being interpolated. But not so! This apparently works. > Apparently? Well, I thought that by some HTML spec that the values needed to > be enclosed in double quotes - that single quotes not by standard. But my > NS4.6 renders the above fine. But will more compliant browsers? Say NS6x? Dear Mike, Fortunately PHP is a serverside language so it does not matter what browser is being used. If you look again you can see that the whole lot print line is definitely inside double quotes, and the vars are inside these double quotes so they are parsed. That the vars are in single quotes inside the double quotes apparently (...) does not matter. Apparently (...) the outside quotes count. cheers, Chris -------------------------------------------------------------------- -- C.Hayes Droevendaal 35 6708 PB Wageningen the Netherlands -- --------------------------------------------------------------------

« previous php.general (#29785) next »