Re: escaping HTML
| From: | Chris Hayes | Date: | Tue, 12 Dec 2000 00:42:22 +0000 |
| Subject: | Re: escaping HTML | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-29785@lists.php.net to get a copy of this message | ||
> Jim Carey wrote:
> >
> > how about ?
> >
> > <?php
> > $sess_name = session_name();
> > $sess_id = session_id();
> > print ("
> > <form action='test1.php' method='post'>
> > <input type='hidden' name='$sess_name'
> > value='$sess_id'>
> > <input type='submit' value='submit'>
> > ");
> > ?>
> >
>
> I would have thought that the single qoutes would of kept the vars
> from being interpolated. But not so! This apparently works.
> Apparently? Well, I thought that by some HTML spec that the values needed to
> be enclosed in double quotes - that single quotes not by standard. But my
> NS4.6 renders the above fine. But will more compliant browsers? Say NS6x?
Dear Mike,
Fortunately PHP is a serverside language so it does not matter what browser
is being used.
If you look again you can see that the whole lot print line is definitely
inside double quotes, and the vars are inside these double quotes so they
are parsed. That the vars are in single quotes inside the double quotes
apparently (...) does not matter. Apparently (...) the outside quotes count.
cheers,
Chris
--------------------------------------------------------------------
-- C.Hayes Droevendaal 35 6708 PB Wageningen the Netherlands --
--------------------------------------------------------------------