Re: RFC: Implementing a core anti-XSS escaping class

From: Date: Wed, 19 Sep 2012 16:16:44 +0000
Subject: Re: RFC: Implementing a core anti-XSS escaping class
References: 1 2 3 4 5 6 7 8 9  Groups: php.internals 
Request: Send a blank email to internals+get-63147@lists.php.net to get a copy of this message
Hi, Am 19.09.2012 um 18:11 schrieb Michael Stowe <me@mikestowe.com>: > Personally, I would like to see it operate similar to MySQLi, where you > have the convenience of OOP, but can still call a function directly in a > procedural manner. There seems to be a need for a procedural API. As their is one, let’s do it similar to how MySQLi etc. does it and use a context resource: $ctx = escape_context_create('UTF-8'); $str = escape_html_attr($ctx, $str); And so on. cu, Lars

« previous php.internals (#63147) next »