Re: Re: RFC: Implementing a core anti-XSS escaping class
| From: | Leigh | Date: | Wed, 19 Sep 2012 16:15:23 +0000 |
| Subject: | Re: Re: RFC: Implementing a core anti-XSS escaping class | ||
| References: | 1 2 3 4 5 6 7 8 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-63146@lists.php.net to get a copy of this message | ||
> Call it str_escape(string, flags optional, encoding optional) and be done with it.
Keeping it simple definitely preferred
> 1) do we even need encoding or is UTF8 just fine
Definitely need encoding.
mbstring supports quite a lot
http://php.net/manual/en/mbstring.supported-encodings.php
I think you'd need to at least approximately match those encodings,
perhaps there is code already there that can be depended upon?