Re: [VOTE] Improve HTML escape
| From: | Ángel González | Date: | Thu, 20 Feb 2014 20:43:36 +0000 |
| Subject: | Re: [VOTE] Improve HTML escape | ||
| References: | 1 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72720@lists.php.net to get a copy of this message | ||
On 17/02/14 05:10, Yasuo Ohgaki wrote:
Hi all, This RFC for improving HTML escape by confirming OWASP recommendation. PCI DSS suggests to follow their guidelines. https://wiki.php.net/rfc/secure-html-escape It makes escape OWASP recommended chars always. It simplifies coding a little, too. Thank you for voting! I see the point to change the default value, but I don't think PHP should ignore the flags requesting a specific behavior.