Re: [RFC] Improve HTML escape
| From: | Yasuo Ohgaki | Date: | Tue, 04 Feb 2014 05:46:35 +0000 |
| Subject: | Re: [RFC] Improve HTML escape | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72172@lists.php.net to get a copy of this message | ||
Hi Lester,
On Tue, Feb 4, 2014 at 8:22 AM, Lester Caine <lester@lsces.co.uk> wrote:
> Yasuo Ohgaki wrote:
>
>> I'm lost here.
>> OWASP suggests to escape at least
>>
>> & --> &
>> < --> <
>> > --> >
>> " --> "
>> ' --> ' ' not recommended because its not in the HTML spec
>> (See: section 24.4.1) ' is in the XML and XHTML specs.
>> / --> / forward slash is included as it helps end an HTML
>> entity
>>
>> https://www.owasp.org/index.php/XSS_(Cross_Site_Scripting)
>> _Prevention_Cheat_Sheet#RULE_.231_-_HTML_Escape_Before_
>> Inserting_Untrusted_Data_into_HTML_Element_Content
>>
>> I'm not sure why you state "already violate this requirement".
>>
>
> It may be that what you are asking for is a flag on htmlentities for
> 'OWASP' compliant option. Others would probably view that as not then being
> html5 compliant since html5 has it's own list of 'escaped' characters. One
> of the irritating things I find is 'unescaping' a string does not return
> the original string simply because the html5 rule has not been followed! A
> clean html5 result should be the default.
>
> Looking at the Rule 2 from the OWASP they are actually asking for every
> character below 256 to be escaped when used in an attribute! But the
> important thing here is 'untrusted' data, and sanitising any externally
> supplied data needs a little more care than simply trying to wrap it in
> htmlentities which I think is what Stas is saying? Personally I try to
> avoid any path where input can be processed direct back to output, filter
> the input, don't simply try and patch the output?
I suggests "Validate *all* inputs if they meet spec" and "Escape/Use secure
and proper API".
Currently PHP lacks these APIs. JavaScript literal escape is one of them.
As you can see in
my blog, escaping is not a simple task to do. There should be APIs for it.
I'm willing to address this issue and there is a RFC for it already.
https://wiki.php.net/rfc/escaper
I just don't have time for it :)
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net