Re: Optimizing php_html_entities()

From: Date: Wed, 24 Jun 2015 09:20:56 +0000
Subject: Re: Optimizing php_html_entities()
References: 1 2 3 4 5 6 7  Groups: php.internals 
Request: Send a blank email to internals+get-86837@lists.php.net to get a copy of this message
Hi, On Wed, Jun 24, 2015 at 5:49 AM, Yasuo Ohgaki <yohgaki@ohgaki.net> wrote: > Hi Xinchen, > > On Wed, Jun 24, 2015 at 11:42 AM, Xinchen Hui <laruence@php.net> wrote: > >> and for the "age" usage you replied in github, I think the author of >> such codes should be aware, if it's only number, then instead of >> htmlespcicalchars($age), he should use echo $age directly... which is >> more faster. >> > > To build secure apps, users MUST escape everything for the context by > _default_. > Selective escaping is the cause of injection vulnerability especially with > language like > PHP. > > Principle is "Don't think, escape all (for the context)". > The key word here is "context" ... you know that there's nothing to escape for an integer, because the type is your context. Selective escaping isn't a problem by itself, but that many people use a blacklist approach instead of a whitelist one; and you can only fix that with education. Cheers, Andrey.

« previous php.internals (#86837) next »