Re: RFC: Implementing a core anti-XSS escaping class

From: Date: Tue, 18 Sep 2012 17:11:04 +0000
Subject: Re: RFC: Implementing a core anti-XSS escaping class
References: 1 2 3 4 5 6  Groups: php.internals 
Request: Send a blank email to internals+get-63076@lists.php.net to get a copy of this message
On 18/09/12 18:09, Stas Malyshev wrote:
Hi!
No it's not. A filter removes, but escaping lets the original content pass through unchanged, with the necessary in-band signalling to make sure that its content is not treated as in-band signalling.
Again, you are confusing particular implementation of a particular filter with the idea of filtering. Moreover, even existing filters do not match your description: FILTER_SANITIZE_ENCODED, FILTER_SANITIZE_MAGIC_QUOTES, FILTER_SANITIZE_SPECIAL_CHARS, FILTER_SANITIZE_FULL_SPECIAL_CHARS, FILTER_SANITIZE_STRING, FILTER_CALLBACK But in general, look at implementation of filters anywhere - like Apache filters or IIS filters - nowhere it is said that filter can only remove data. Ah, sorry, I think I'm confusing the standard English language meaning of filter with regards to the physical device or signal processing, with the meaning in the field of computer science etc.
-- Andrew Faulds http://ajf.me/

« previous php.internals (#63076) next »