Re: [RFC Idea] Short echo tag with automatic HTML escaping (<?~ ... ?>)

From: Date: Tue, 23 Dec 2025 09:55:00 +0000
Subject: Re: [RFC Idea] Short echo tag with automatic HTML escaping (<?~ ... ?>)
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-129673@lists.php.net to get a copy of this message
Hi Sergei, XSS escaping is unfortunately not as simple as that. Templating engines are context-aware and can know whether to apply escaping for free-form text or an attribute (which can often also be validated by type), specific tag behaviors, and even whether the output is to be executed as HTML, XML, CSS, JS, etc. One-size-fits-all escaping that doesn't take such context into account is not effective and even makes things worse by giving developers a false sense of security. Cheers, Andrey.

« previous php.internals (#129673) next »