Re: New escaped output operator

From: Date: Mon, 20 Jun 2016 08:50:27 +0000
Subject: Re: New escaped output operator
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15  Groups: php.internals 
Request: Send a blank email to internals+get-94146@lists.php.net to get a copy of this message
On 20/06/2016 04:22, Михаил Востриков wrote:
And it can really improve security, not in 90% but about 99.9999% cases.
I think you are rather overstating how much of a "special edge case" it is to echo a variable into other contexts like URLs, or JS. It doesn't need to be anything fancy, just an innocent-looking snippet like this: <ul> <?php foreach ( $things as $thing ) { ?> <li><a href="/things/<?= $thing['name'] ?>" onclick="show_popup('<?= $thing['name'] ?>');"><?= $thing['name'] ?></a> <?php } ?> </ul> There are three different escape mechanism needed there; if there is a shorthand for one, do you think it will be more likely or less that people will get the other two right? Regards, -- Rowan Collins [IMSoP]

« previous php.internals (#94146) next »