Re: [RFC] Improve HTML escape
| From: | Yasuo Ohgaki | Date: | Sun, 02 Feb 2014 03:33:37 +0000 |
| Subject: | Re: [RFC] Improve HTML escape | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-71972@lists.php.net to get a copy of this message | ||
Hi Andrea,
On Sun, Feb 2, 2014 at 12:27 PM, Andrea Faulds <ajf@ajf.me> wrote:
> On 02/02/14 03:09, Yasuo Ohgaki wrote:
>
>> "/" escape is recommended by OWASP and we may follow them.
>>
>
> Surely if this is to stop <foo bar=<?=htmlspecialchars($foobar); ?>>,
> then we'd have to escape ' ' too?
Making ENT_QUOTES as a default is good idea also.
I should have add this to the RFC.
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net