Re: RFC: Implementing a core anti-XSS escaping class
| From: | Andrew Faulds | Date: | Tue, 18 Sep 2012 17:16:34 +0000 |
| Subject: | Re: RFC: Implementing a core anti-XSS escaping class | ||
| References: | 1 2 3 4 5 6 7 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-63078@lists.php.net to get a copy of this message | ||
On 18/09/12 18:14, Anthony Ferrara wrote:
Stas, On Tue, Sep 18, 2012 at 1:09 PM, Stas Malyshev <smalyshev@sugarcrm.com <mailto:smalyshev@sugarcrm.com>> wrote:I'm very confused :P -- Andrew Faulds http://ajf.me/Hi!No it's not. A filter removes, but escaping lets the originalcontentpass through unchanged, with the necessary in-band signalling tomakesure that its content is not treated as in-band signalling.Again, you are confusing particular implementation of a particular filter with the idea of filtering. Moreover, even existing filters do not match your description:No, he's not. Filtering and escaping are two very significant concepts in security. Just because PHP implemented some escaping concepts into the filter function does not mean that the concerns are co-related. Ah, again you see, I'm confusing things :) In the security context, English language context, and signal processing context, a filter removes. In computer science, but not computer security, it processes.