Re: [RFC] Improve HTML escape
| From: | Andrea Faulds | Date: | Tue, 04 Feb 2014 15:57:29 +0000 |
| Subject: | Re: [RFC] Improve HTML escape | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72203@lists.php.net to get a copy of this message | ||
Hi,
Some thoughts on this. So far as I see it, the point of adding / escaping would be for unquoted attribute values. However, there's nothing we can really do for unquoted attribute values - the moment someone adds a space, they're broken. Unquoted attribute values being legal in HTML5 is, IMO, a good thing. They're nice when authoring HTML, as this:
<input type="text" name="username" id="username" placeholder="Username" />Can become this:
<input type=text name=username id=username placeholder=Username>However, you should *never* be putting user input as an attribute value without quotes around it. I don't think adding / here is a good idea. With or without it, code which does <input foo=<?=$bar?> /> will be vulnerable anyway. But if we add it, people might think doing that is safe, which would be worse. -- Andrea Faulds http://ajf.me/