Re: RFC: Implementing a core anti-XSS escaping class
| From: | Lars Strojny | Date: | Wed, 19 Sep 2012 16:16:44 +0000 |
| Subject: | Re: RFC: Implementing a core anti-XSS escaping class | ||
| References: | 1 2 3 4 5 6 7 8 9 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-63147@lists.php.net to get a copy of this message | ||
Hi,
Am 19.09.2012 um 18:11 schrieb Michael Stowe <me@mikestowe.com>:
> Personally, I would like to see it operate similar to MySQLi, where you
> have the convenience of OOP, but can still call a function directly in a
> procedural manner.
There seems to be a need for a procedural API. As their is one, let’s do it similar to how MySQLi
etc. does it and use a context resource:
$ctx = escape_context_create('UTF-8');
$str = escape_html_attr($ctx, $str);
And so on.
cu,
Lars