Re: RFC: Implementing a core anti-XSS escaping class
| From: | Stas Malyshev | Date: | Tue, 18 Sep 2012 18:21:26 +0000 |
| Subject: | Re: RFC: Implementing a core anti-XSS escaping class | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-63096@lists.php.net to get a copy of this message | ||
Hi!
> Filter has already gone down this road--I doubt the value added by having a second, much
> more verbose way to call htmlspecialchars()--but I don't see why we must continue down
> that path.
So, you don't think there should be second, more verbose way to call
htmlspecialchars - that's why we should add third, more verbose way to
call htmlspecialchars? Somehow this does not sound convincing to me.
--
Stanislav Malyshev, Software Architect
SugarCRM: http://www.sugarcrm.com/
(408)454-6900 ext. 227