Re: [RFC] Escaping RFC for PHP Core - Updates?
| From: | Nikita Nefedov | Date: | Sat, 07 Sep 2013 16:36:30 +0000 |
| Subject: | Re: [RFC] Escaping RFC for PHP Core - Updates? | ||
| References: | 1 2 3 4 5 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-68946@lists.php.net to get a copy of this message | ||
On Sat, 07 Sep 2013 20:08:45 +0400, Michael John Burgess <michael@mjburgess.co.uk> wrote:
On 07/09/2013 15:41, Levi Morrison wrote:Hi, Wrapping those functions in methods means they can be extended in child classes. So suppose you have some library that takes object of type Spl_Escaper and uses its methods for escaping some data. Now if you will need some additional escaping you just need to make child class for Spl_Escaper and override methods which behavior you need to change. This can't be done with pure functions (in PHP).There doesnt need to be any object-oriented version for this problem. It's a series of pure functions. Wraping them in one or more classes adds nothing. MichaelIt looks nicer than Escaper::escapeJs(), Escaper::escapeHtml(), etc. Any comments?Please, don't go down this route. You do not want one class to escape all kinds of data; delegate each type of escaping to its own class: JavaScriptEscaper->escape(); PhpEscaper->escape(); HtmlEscaper->escape(); HtmlAttributeEscaper->escape(); I should not have to defend this but I am willing to explain in more detail if someone would like me to.