Re: [RFC] Improve HTML escape
| From: | Pádraic Brady | Date: | Wed, 05 Feb 2014 10:54:07 +0000 |
| Subject: | Re: [RFC] Improve HTML escape | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72262@lists.php.net to get a copy of this message | ||
Hi Yasuo,
On 5 February 2014 02:10, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> Is it ready to vote?
> No more issues to discuss?
> Anyone?
I would remove all mention of htmlentities() other than briefly noting
that it would also be changed as part of the RFC. The rationale is
that the proper escaping function for HTML is htmlspecialchars() (so
emphasise that function). htmlentities() escapes anything with a
suitable HTML entity including non-special UTF-8 characters, i.e. it's
overkill and it disproportionately increases output size in
non-English languages such as Gaelic. The use of htmlentities() is
just a senseless bad habit by English speaking programmers based on
historic ties to non-Unicode output that needs to die already:
http://stackoverflow.com/questions/12648655/html-encoding-of-japanese-text
I would also split the vote into three sections:
1. Should we escape single quotes by default?
2. Should we escape forward slashes by default?
3. Should we deprecate ENT_COMPAT and ENT_QUOTES?
The main risk I'd see is if people don't won't to escape forward slash
and kill the entire RFC over that one change.
You also don't mention single quotes anywhere in the RFC ;). You
should note that with an example so voters know it will be encoded by
default.
Paddy
--
Pádraic Brady
http://blog.astrumfutura.com
http://www.survivethedeepend.com
Zend Framework Community Review Team
Zend Framework PHP-FIG Representative