Re: Proposed feature for json_encode()

From: Date: Wed, 05 Dec 2007 18:20:56 +0000
Subject: Re: Proposed feature for json_encode()
References: 1 2 3 4 5 6 7 8 9 10 11 12 13  Groups: php.internals 
Request: Send a blank email to internals+get-33751@lists.php.net to get a copy of this message
payload to innerHTML, you are hosed. Using the \u syntax, even if you mess up and that blob of data finds its way to an innerHTML, nothing nasty can happen. Basically this is a more robust context-protected way
I'm not sure this is correct - if you just write something like: <script> var = <?php json_encode($_GET['pleasehackme']) ?>; myDomElement.innerHTML = var.content; </script> you are still in trouble, \u or not. Am I wrong? -- Stanislav Malyshev, Zend Software Architect stas@zend.com http://www.zend.com/ (408)253-8829 MSN: stas@zend.com

« previous php.internals (#33751) next »