Re: [RFC Idea] Short echo tag with automatic HTML escaping (<?~ ... ?>)

From: Date: Tue, 23 Dec 2025 10:09:46 +0000
Subject: Re: [RFC Idea] Short echo tag with automatic HTML escaping (<?~ ... ?>)
References: 1 2  Groups: php.internals 
Request: Send a blank email to internals+get-129676@lists.php.net to get a copy of this message
On Tue, Dec 23, 2025, at 10:55, Andrey Andreev wrote: > Hi Sergei, > > XSS escaping is unfortunately not as simple as that. Templating engines are context-aware and > can know whether to apply escaping for free-form text or an attribute (which can often also be > validated by type), specific tag behaviors, and even whether the output is to be executed as HTML, > XML, CSS, JS, etc. > > One-size-fits-all escaping that doesn't take such context into account is not effective > and even makes things worse by giving developers a false sense of security. > > Cheers, > Andrey. Hi Andrey, Which template engines are context aware? The only ones I'm aware of is my own and Latte (which take a similar approach but is quite architecturally different). — Rob

« previous php.internals (#129676) next »