Re: Re: RFC: Implementing a core anti-XSS escaping class

From: Date: Wed, 19 Sep 2012 16:50:00 +0000
Subject: Re: Re: RFC: Implementing a core anti-XSS escaping class
References: 1 2 3 4 5 6 7 8 9  Groups: php.internals 
Request: Send a blank email to internals+get-63151@lists.php.net to get a copy of this message
On Wed, Sep 19, 2012 at 9:08 AM, Andrew Faulds <ajf@ajf.me> wrote: > Yes, but typing the encoding every time is cumbersome. Or, if you don't want > to set it every time, you'd have to set it globally. Then, you forgot to > change it back somewhere when you're dealing with multiple encodings, and it > all goes wrong. then write a reusable function. same amount of code as an OO method. since everyone likes to make OO classes for every little thing. >> After that it seems like the discussion would be: >> 1) do we even need encoding or is UTF8 just fine > > UTF8-only is certainly not just fine. That's fine :) Just a suggestion for discussion. Keep encoding in then! (I was thinking about htmlspecialchars and such)

« previous php.internals (#63151) next »