Re: RFC: Implementing a core anti-XSS escaping class
| From: | Andrew Faulds | Date: | Tue, 18 Sep 2012 17:11:04 +0000 |
| Subject: | Re: RFC: Implementing a core anti-XSS escaping class | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-63076@lists.php.net to get a copy of this message | ||
On 18/09/12 18:09, Stas Malyshev wrote:
Hi!-- Andrew Faulds http://ajf.me/No it's not. A filter removes, but escaping lets the original content pass through unchanged, with the necessary in-band signalling to make sure that its content is not treated as in-band signalling.Again, you are confusing particular implementation of a particular filter with the idea of filtering. Moreover, even existing filters do not match your description: FILTER_SANITIZE_ENCODED, FILTER_SANITIZE_MAGIC_QUOTES, FILTER_SANITIZE_SPECIAL_CHARS, FILTER_SANITIZE_FULL_SPECIAL_CHARS, FILTER_SANITIZE_STRING, FILTER_CALLBACK But in general, look at implementation of filters anywhere - like Apache filters or IIS filters - nowhere it is said that filter can only remove data. Ah, sorry, I think I'm confusing the standard English language meaning of filter with regards to the physical device or signal processing, with the meaning in the field of computer science etc.