Re: Optimizing php_html_entities()

From: Date: Wed, 24 Jun 2015 02:49:33 +0000
Subject: Re: Optimizing php_html_entities()
References: 1 2 3 4 5 6  Groups: php.internals 
Request: Send a blank email to internals+get-86830@lists.php.net to get a copy of this message
Hi Xinchen, On Wed, Jun 24, 2015 at 11:42 AM, Xinchen Hui <laruence@php.net> wrote: > and for the "age" usage you replied in github, I think the author of > such codes should be aware, if it's only number, then instead of > htmlespcicalchars($age), he should use echo $age directly... which is > more faster. > To build secure apps, users MUST escape everything for the context by _default_. Selective escaping is the cause of injection vulnerability especially with language like PHP. Principle is "Don't think, escape all (for the context)". Regards, -- Yasuo Ohgaki yohgaki@ohgaki.net

« previous php.internals (#86830) next »