Re: HTML escaped short echo tag

From: Date: Sun, 21 Oct 2012 17:01:14 +0000
Subject: Re: HTML escaped short echo tag
References: 1  Groups: php.internals 
Request: Send a blank email to internals+get-63592@lists.php.net to get a copy of this message
Hi! > I'd like to propose a new short tag that echos with HTML escaping. What is "HTML escaping"? Different contexts need different escaping. For outside tags it's one escaping, for tag attribute it's another, for JS code context - yet another. Selecting just one use case and integrating it into the language is a bad idea - since you are basically saying everybody should use this specific case in any case, which is wrong. > The new tag should be just as short and easy to type as <?=. Personally I'm > a fan of <?- or perhaps <?~. Personally I'm hugely *not* a fan of more obscure syntax in PHP. Especially one that will quickly lead people into writing insecure code because of applying wrong escaping function for the context. -- Stanislav Malyshev, Software Architect SugarCRM: http://www.sugarcrm.com/ (408)454-6900 ext. 227

« previous php.internals (#63592) next »