Re: RFC about automatic template escaping
| From: | Marco Pivetta | Date: | Tue, 22 Mar 2016 12:32:58 +0000 |
| Subject: | Re: RFC about automatic template escaping | ||
| References: | 1 2 3 4 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-91840@lists.php.net to get a copy of this message | ||
On 22 March 2016 at 13:24, Jan Tvrdík <j.tvr@centrum.cz> wrote:
> The escape context could be detected (e.g. Latte template engine supports
> context-aware escaping for years –
> https://latte.nette.org/en/#toc-context-aware-escaping) but the
> logic is
> quite complex for it to be included in PHP core.
Sorry, I have to... *T*O͇̹̺ͅƝ̴ȳ̳ TH̘*Ë͖́̉ ͠P̯͍̭O̚N̐Y̡
H̸̡̪̯ͨ͊̽̅̾̎Ȩ̬̩̾͛ͪ̈́̀́͘
̶̧̨̱̹̭̯ͧ̾ͬC̷̙̲̝͖ͭ̏ͥͮ͟Oͮ͏̮̪̝͍M̲̖͊̒ͪͩͬ̚̚͜Ȇ̴̟̟͙̞ͩ͌͝*
S̨̥̫͎̭ͯ̿̔̀ͅ
http://stackoverflow.com/questions/1732348/regex-match-open-tags-except-xhtml-self-contained-tags,
fwiw.
No, detecting context is not possible unless you are in a very strict and
inflexible context, such as an XML-based templating engine.
Marco Pivetta
http://twitter.com/Ocramius
http://ocramius.github.com/