Re: [RFC] New operator for context-dependent escaping
| From: | Michael Vostrikov | Date: | Sat, 16 Jul 2016 16:51:19 +0000 |
| Subject: | Re: [RFC] New operator for context-dependent escaping | ||
| References: | 1 2 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94521@lists.php.net to get a copy of this message | ||
> if I see it correctly, this is just a framework for defining callbacks to
a escaping operator, without a implementation of "html" and "js"?
> Not sure if this helps.
There is a default escaping for HTML. If there is no registered handler for
'html' context, it calls htmlspecialchars($str, ENT_QUOTES |
ENT_SUBSTITUTE).