Re: RFC: Implementing a core anti-XSS escaping class

From: Date: Tue, 18 Sep 2012 19:50:08 +0000
Subject: Re: RFC: Implementing a core anti-XSS escaping class
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14  Groups: php.internals 
Request: Send a blank email to internals+get-63112@lists.php.net to get a copy of this message
On 09/18/2012 03:46 PM, Pádraic Brady wrote: > Bear in mind the RFC, in userland (and likely any PECL ext) implements > the ESAPI rules. They've been hacked on a lot over the years which is > why I made sure they were followed exactly. It's very unlikely that a > browser bug could scupper these unless they allowed in more unencoded > characters to be taken advantage of. There are benefits to reusing > pre-peer review rules. Sure, but you have potential for buffer overflows, regex backtrack/recursion issues and general programming errors when this moves to C. I guarantee there will be dozens of bugs in the first version no matter who writes it. -Rasmus

« previous php.internals (#63112) next »