Re: RFC about automatic template escaping
| From: | Rowan Collins | Date: | Mon, 21 Mar 2016 12:27:03 +0000 |
| Subject: | Re: RFC about automatic template escaping | ||
| References: | 1 2 3 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-91814@lists.php.net to get a copy of this message | ||
Daniel Beardsley wrote on 21/03/2016 06:35:
You are right. Though not all those problems are serious: * URI escaping: Does anyone really use <?= ?> or echo when generating a uri? * Javascript: Good point, though I would say it's fairly rare to create javascript code using a php template with variables. The most we ever do in our app is <?= json_encode($someArray) ?>I've done both of these in the past (using Smarty, in my case); here's some example uses: <a href="/products/<?= $product['category'] ?>/<?= $product['id'] ?>"><?= $product['name'] ?></a> <script>var debug_session_id = '<?= get_debug_session_id() ?>';</script> Now, I'm not saying there aren't better ways of doing these things, but people absolutely do it like this, and a hook into something as fundamental as "echo" can't really rely on "it's quite rare" as an excuse for not accounting for them. Regards, -- Rowan Collins [IMSoP]