Re: Optimizing php_html_entities()
| From: | Yasuo Ohgaki | Date: | Wed, 24 Jun 2015 02:49:33 +0000 |
| Subject: | Re: Optimizing php_html_entities() | ||
| References: | 1 2 3 4 5 6 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-86830@lists.php.net to get a copy of this message | ||
Hi Xinchen,
On Wed, Jun 24, 2015 at 11:42 AM, Xinchen Hui <laruence@php.net> wrote:
> and for the "age" usage you replied in github, I think the author of
> such codes should be aware, if it's only number, then instead of
> htmlespcicalchars($age), he should use echo $age directly... which is
> more faster.
>
To build secure apps, users MUST escape everything for the context by
_default_.
Selective escaping is the cause of injection vulnerability especially with
language like
PHP.
Principle is "Don't think, escape all (for the context)".
Regards,
--
Yasuo Ohgaki
yohgaki@ohgaki.net