Re: [RFC] Improve HTML escape

From: Date: Wed, 05 Feb 2014 10:54:07 +0000
Subject: Re: [RFC] Improve HTML escape
References: 1 2 3 4  Groups: php.internals 
Request: Send a blank email to internals+get-72262@lists.php.net to get a copy of this message
Hi Yasuo, On 5 February 2014 02:10, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > Is it ready to vote? > No more issues to discuss? > Anyone? I would remove all mention of htmlentities() other than briefly noting that it would also be changed as part of the RFC. The rationale is that the proper escaping function for HTML is htmlspecialchars() (so emphasise that function). htmlentities() escapes anything with a suitable HTML entity including non-special UTF-8 characters, i.e. it's overkill and it disproportionately increases output size in non-English languages such as Gaelic. The use of htmlentities() is just a senseless bad habit by English speaking programmers based on historic ties to non-Unicode output that needs to die already: http://stackoverflow.com/questions/12648655/html-encoding-of-japanese-text I would also split the vote into three sections: 1. Should we escape single quotes by default? 2. Should we escape forward slashes by default? 3. Should we deprecate ENT_COMPAT and ENT_QUOTES? The main risk I'd see is if people don't won't to escape forward slash and kill the entire RFC over that one change. You also don't mention single quotes anywhere in the RFC ;). You should note that with an example so voters know it will be encoded by default. Paddy -- Pádraic Brady http://blog.astrumfutura.com http://www.survivethedeepend.com Zend Framework Community Review Team Zend Framework PHP-FIG Representative

« previous php.internals (#72262) next »