Re: [RFC] New operator for context-dependent escaping
| From: | Marco Pivetta | Date: | Wed, 20 Jul 2016 18:30:41 +0000 |
| Subject: | Re: [RFC] New operator for context-dependent escaping | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94593@lists.php.net to get a copy of this message | ||
The syntax is weird as heck.
That said, frameworks without templating engine already have escaping
helpers, for example:
<?= $this->escapeHtml($value); ?>
<?= $this->escapeHtmlAttr($value); ?>
<?= $this->escapeJs($value); ?>
<?= $this->escapeCss($value); ?>
I don't see what is hard in using that syntax, plus it's not a global
registry.
Marco Pivetta
http://twitter.com/Ocramius
http://ocramius.github.com/
On Wed, Jul 20, 2016 at 8:17 PM, Michael Vostrikov <
michael.vostrikov@gmail.com> wrote:
> > Personally I don't know any developer who is using raw php in project
> without template engine
>
> Zend, Yii, various CMS like Wordperss, internal business-applications - in
> many cases such projects don't have a template engine.
> I usually work with Yii and internal applications on custom engines. This
> is the reason why I raised this question.
> By the way, the syntax is not weird. It is just <?* $var1, $var2 ?>. How to
> use $var2 is fully up to application.
>