Re: RFC: Implementing a core anti-XSS escaping class
| From: | Michael Shadle | Date: | Wed, 19 Sep 2012 16:53:26 +0000 |
| Subject: | Re: RFC: Implementing a core anti-XSS escaping class | ||
| References: | 1 2 3 4 5 6 7 8 9 10 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-63152@lists.php.net to get a copy of this message | ||
On Wed, Sep 19, 2012 at 9:16 AM, Lars Strojny <lars@strojny.net> wrote:
> There seems to be a need for a procedural API. As their is one, let’s do it similar to how
> MySQLi etc. does it and use a context resource:
>
> $ctx = escape_context_create('UTF-8');
> $str = escape_html_attr($ctx, $str);
why bother with that? it's called function parameters. (and even
better, named parameters if PHP ever implemented those... :))