Re: [RFC] New operator for context-dependent escaping
| From: | Rowan Collins | Date: | Sun, 24 Jul 2016 16:39:05 +0000 |
| Subject: | Re: [RFC] New operator for context-dependent escaping | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94682@lists.php.net to get a copy of this message | ||
On 24/07/2016 17:21, Thomas Bley wrote:
It's not that difficult to write a static analyser that detects instances of "<?=" not followed by "h(" or "e(" or whatever.<?* $str ?> instead of <?=h($str)?>benefits are using static code analyzers, grep "<?=" for code reviews, etc.
Having function names with single characters is bad taste and only useful for obfuscating.And having a token "*" that calls a different function in every application is somehow less obfuscated?
Using multiple frameworks or libraries, it's not possible to redeclare functions with the same name.It's not possible for multiple frameworks or libraries to declare different escape handlers in your proposal, either.
The big difference is: With <?*, you have to define an escaping function, with <?= it's optional.You could equally say, "with <?=e()?> you have to define an e() function". The main effort is remembering to use the right syntax, which you have to do either way. Surely the feature gets most of its value from what you *don't* need to do - which is why I think it's bizarre that the current version doesn't even have a built-in HTML escaper at all. Regards, -- Rowan Collins [IMSoP]