Re: [RFC] Improve HTML escape

From: Date: Tue, 04 Feb 2014 05:46:35 +0000
Subject: Re: [RFC] Improve HTML escape
References: 1 2 3 4 5 6 7 8 9 10 11 12  Groups: php.internals 
Request: Send a blank email to internals+get-72172@lists.php.net to get a copy of this message
Hi Lester, On Tue, Feb 4, 2014 at 8:22 AM, Lester Caine <lester@lsces.co.uk> wrote: > Yasuo Ohgaki wrote: > >> I'm lost here. >> OWASP suggests to escape at least >> >> & --> &amp; >> < --> &lt; >> > --> &gt; >> " --> &quot; >> ' --> &#x27; &apos; not recommended because its not in the HTML spec >> (See: section 24.4.1) &apos; is in the XML and XHTML specs. >> / --> &#x2F; forward slash is included as it helps end an HTML >> entity >> >> https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting) >> _Prevention_Cheat_Sheet#RULE_.231_-_HTML_Escape_Before_ >> Inserting_Untrusted_Data_into_HTML_Element_Content >> >> I'm not sure why you state "already violate this requirement". >> > > It may be that what you are asking for is a flag on htmlentities for > 'OWASP' compliant option. Others would probably view that as not then being > html5 compliant since html5 has it's own list of 'escaped' characters. One > of the irritating things I find is 'unescaping' a string does not return > the original string simply because the html5 rule has not been followed! A > clean html5 result should be the default. > > Looking at the Rule 2 from the OWASP they are actually asking for every > character below 256 to be escaped when used in an attribute! But the > important thing here is 'untrusted' data, and sanitising any externally > supplied data needs a little more care than simply trying to wrap it in > htmlentities which I think is what Stas is saying? Personally I try to > avoid any path where input can be processed direct back to output, filter > the input, don't simply try and patch the output? I suggests "Validate *all* inputs if they meet spec" and "Escape/Use secure and proper API". Currently PHP lacks these APIs. JavaScript literal escape is one of them. As you can see in my blog, escaping is not a simple task to do. There should be APIs for it. I'm willing to address this issue and there is a RFC for it already. https://wiki.php.net/rfc/escaper I just don't have time for it :) Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#72172) next »