Re: RFC about automatic template escaping

From: Date: Mon, 21 Mar 2016 12:27:03 +0000
Subject: Re: RFC about automatic template escaping
References: 1 2 3  Groups: php.internals 
Request: Send a blank email to internals+get-91814@lists.php.net to get a copy of this message
Daniel Beardsley wrote on 21/03/2016 06:35:
You are right. Though not all those problems are serious: * URI escaping: Does anyone really use <?= ?> or echo when generating a uri? * Javascript: Good point, though I would say it's fairly rare to create javascript code using a php template with variables. The most we ever do in our app is <?= json_encode($someArray) ?>
I've done both of these in the past (using Smarty, in my case); here's some example uses: <a href="/products/<?= $product['category'] ?>/<?= $product['id'] ?>"><?= $product['name'] ?></a> <script>var debug_session_id = '<?= get_debug_session_id() ?>';</script> Now, I'm not saying there aren't better ways of doing these things, but people absolutely do it like this, and a hook into something as fundamental as "echo" can't really rely on "it's quite rare" as an excuse for not accounting for them. Regards, -- Rowan Collins [IMSoP]

« previous php.internals (#91814) next »