Re: RFC: Implementing a core anti-XSS escaping class

From: Date: Tue, 18 Sep 2012 17:16:34 +0000
Subject: Re: RFC: Implementing a core anti-XSS escaping class
References: 1 2 3 4 5 6 7  Groups: php.internals 
Request: Send a blank email to internals+get-63078@lists.php.net to get a copy of this message
On 18/09/12 18:14, Anthony Ferrara wrote:
Stas, On Tue, Sep 18, 2012 at 1:09 PM, Stas Malyshev <smalyshev@sugarcrm.com <mailto:smalyshev@sugarcrm.com>> wrote:
    Hi!
No it's not. A filter removes, but escaping lets the original
    content
pass through unchanged, with the necessary in-band signalling to
    make
sure that its content is not treated as in-band signalling.
    Again, you are confusing particular implementation of a particular
    filter with the idea of filtering. Moreover, even existing filters do
    not match your description:
No, he's not. Filtering and escaping are two very significant concepts in security. Just because PHP implemented some escaping concepts into the filter function does not mean that the concerns are co-related. Ah, again you see, I'm confusing things :) In the security context, English language context, and signal processing context, a filter removes. In computer science, but not computer security, it processes.
I'm very confused :P -- Andrew Faulds http://ajf.me/

« previous php.internals (#63078) next »