Re: [RFC] Improve HTML escape

From: Date: Sun, 02 Feb 2014 10:19:03 +0000
Subject: Re: [RFC] Improve HTML escape
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-71986@lists.php.net to get a copy of this message
Hi! > They don't explain as code. AFAIK This is the case for generating invalid > HTML that destroys HTML tag structure. > > <tag attr=<?php htmlentities($str, ENT_QUOTES, 'UTF-8') ?>> htmlentities() is no good for encoding unquoted tags. This is obvious since it does not encode space and space is a significant character with unquoted tags. So if you have code like the above, it's game over for you, no need to do anything further. > As long as user don't have other mistakes, it's not a security issue. It's > not vulnerable by itself, but it may be possible do some bad thing on some > implementations. It's just a precaution. It's good precaution as it does > not break any existing browsers. IMHO. I don't see any reason so far to do this. The code above is broken with and without quoting /, and quoting / adds nothing to its security as far as I can see. -- Stanislav Malyshev, Software Architect SugarCRM: http://www.sugarcrm.com/ (408)454-6900 ext. 227

« previous php.internals (#71986) next »