Re: [RFC] Improve HTML escape

From: Date: Sun, 02 Feb 2014 09:54:38 +0000
Subject: Re: [RFC] Improve HTML escape
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-71984@lists.php.net to get a copy of this message
Hi Pavel, On Sun, Feb 2, 2014 at 6:38 PM, Pavel Kouřil <pajousek@gmail.com> wrote: > On Sun, Feb 2, 2014 at 4:31 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > > The code is broken in first place since attribute must be enclosed by > > "(HTML5/XHTML) or '(HTML4), but many (if not most) browsers just allows > > attributes without qoutes. > > Well, the HTML5 specification says attribute values can be left > unquoted, so I'd say that the "code is broken" statement is invalid. > > http://www.w3.org/TR/html-markup/syntax.html#syntax-attr-unquoted Thank you for heads up! We must have this change as a security fix, then. Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#71984) next »