Re: RFC: Implementing a core anti-XSS escaping class
| From: | Andrew Faulds | Date: | Wed, 19 Sep 2012 16:17:55 +0000 |
| Subject: | Re: RFC: Implementing a core anti-XSS escaping class | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-63148@lists.php.net to get a copy of this message | ||
On 19/09/12 17:16, Lars Strojny wrote:
Hi, There seems to be a need for a procedural API. As their is one, let’s do it similar to how MySQLi etc. does it and use a context resource: $ctx = escape_context_create('UTF-8'); $str = escape_html_attr($ctx, $str); And so on. cu, Lars Oh goodness no, let's please only do OOP with the language features. Creating ridiculous "procedural" OOP abstractions helps absolutely nobody.-- Andrew Faulds http://ajf.me/