Re: RFC: Implementing a core anti-XSS escaping class
| From: | Rasmus Lerdorf | Date: | Tue, 18 Sep 2012 16:45:24 +0000 |
| Subject: | Re: RFC: Implementing a core anti-XSS escaping class | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-63068@lists.php.net to get a copy of this message | ||
On 09/18/2012 12:39 PM, Michael Shadle wrote:
> Also as there is also htmlspecialchars() which most people use for escaping this seems like a
> better, more centralized functionality and better nomenclature for escaping on output in general
> with options for various types (and should just be utf-8 by default :))
It is utf-8 by default as of PHP 5.4.