Re: [RFC] Improve HTML escape
| From: | Andrea Faulds | Date: | Sun, 02 Feb 2014 03:27:44 +0000 |
| Subject: | Re: [RFC] Improve HTML escape | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-71970@lists.php.net to get a copy of this message | ||
On 02/02/14 03:09, Yasuo Ohgaki wrote:
"/" escape is recommended by OWASP and we may follow them.Surely if this is to stop <foo bar=<?=htmlspecialchars($foobar); ?>>, then we'd have to escape ' ' too? -- Andrea Faulds http://ajf.me/