Re: New escaped output operator
| From: | Rowan Collins | Date: | Mon, 20 Jun 2016 08:50:27 +0000 |
| Subject: | Re: New escaped output operator | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94146@lists.php.net to get a copy of this message | ||
On 20/06/2016 04:22, Михаил Востриков wrote:
And it can really improve security, not in 90% but about 99.9999% cases.I think you are rather overstating how much of a "special edge case" it is to echo a variable into other contexts like URLs, or JS. It doesn't need to be anything fancy, just an innocent-looking snippet like this: <ul> <?php foreach ( $things as $thing ) { ?> <li><a href="/things/<?= $thing['name'] ?>" onclick="show_popup('<?= $thing['name'] ?>');"><?= $thing['name'] ?></a> <?php } ?> </ul> There are three different escape mechanism needed there; if there is a shorthand for one, do you think it will be more likely or less that people will get the other two right? Regards, -- Rowan Collins [IMSoP]