Re: [RFC] Improve HTML escape
| From: | Stas Malyshev | Date: | Sun, 02 Feb 2014 10:19:03 +0000 |
| Subject: | Re: [RFC] Improve HTML escape | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-71986@lists.php.net to get a copy of this message | ||
Hi!
> They don't explain as code. AFAIK This is the case for generating invalid
> HTML that destroys HTML tag structure.
>
> <tag attr=<?php htmlentities($str, ENT_QUOTES, 'UTF-8') ?>>
htmlentities() is no good for encoding unquoted tags. This is obvious
since it does not encode space and space is a significant character with
unquoted tags. So if you have code like the above, it's game over for
you, no need to do anything further.
> As long as user don't have other mistakes, it's not a security issue. It's
> not vulnerable by itself, but it may be possible do some bad thing on some
> implementations. It's just a precaution. It's good precaution as it does
> not break any existing browsers. IMHO.
I don't see any reason so far to do this. The code above is broken with
and without quoting /, and quoting / adds nothing to its security as far
as I can see.
--
Stanislav Malyshev, Software Architect
SugarCRM: http://www.sugarcrm.com/
(408)454-6900 ext. 227