Re: [RFC] Improve HTML escape
| From: | Pádraic Brady | Date: | Tue, 04 Feb 2014 21:22:26 +0000 |
| Subject: | Re: [RFC] Improve HTML escape | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72214@lists.php.net to get a copy of this message | ||
Hi,
Doing a bit of due diligence, the reason the forward slash was added
was to prevent any possibility of someone introducing a Javascript
comment into an attribute. It's very sketchy, but the theory is that
since html escaping won't escape /, using html escaping on a
javascript attribute like onmouseover might allow the browser to
interpret a comment, disregard the terminating quotes of an attribute,
and then inject HTML. Personally, it seems a bit garbled - user input
in a Javascript attribute should be escaped as a Javascript string
literal with no input injected as actual Javascript code - so it would
require both a severe browser parsing issue AND a lack of proper
contextual escaping.
Paddy