Re: [VOTE] Improve HTML escape
| From: | Yasuo Ohgaki | Date: | Thu, 20 Feb 2014 22:09:30 +0000 |
| Subject: | Re: [VOTE] Improve HTML escape | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-72725@lists.php.net to get a copy of this message | ||
Hi All,
On Fri, Feb 21, 2014 at 6:57 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote:
> I don't mind adding
>
> - ENT_SINGLE(escape only ')
> - ENT_DOUBLE(escape only ". Same as ENT_COMPAT, but better name)
>
> as HTML5 supports ", ' and no quotes for attributes. It seems good for
> completeness. This would be issue for new RFC, though. I may write new RFC
> for this when this is over if many of think this is better to have.
>
Correction.
To control escape fully, we need
- ENT_SINGLE(escape only ' )
- ENT_DOUBLE(escape only ". Same as ENT_COMPAT, but better name)
- ENT_AMP(escape only & )
- ENT_SEMI_COLON(escape only ; )
- ENT_SLASH(escape only / )
It seems too much...
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net