Re: [RFC] New operator for context-dependent escaping
| From: | Michael Vostrikov | Date: | Sat, 30 Jul 2016 14:01:59 +0000 |
| Subject: | Re: [RFC] New operator for context-dependent escaping | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94752@lists.php.net to get a copy of this message | ||
> This new tag will not simply replace <?= $var ?> because you still need
to output HTML sometimes.
This can be done with e.g. "<?* $str, 'raw' ?>".
> What you've coined "context" is really just a pseudo function-call - it
does not automatically establish context
Yes. Because the language cannot know the task, it cannot know exact set of
escapers which are needed for a ceratin value. But it can provide tools to
do this. Automatic context determination is not the aim of this RFC.
> specifying the right "context" requires the exact same choice and
diligence as selecting the right function
Yes. The aim is to call escaping function automatically and to make some
context default, so that the user will not take care about calling it
everywhere manually.
> it somewhat changes the problem, but doesn't actually solve the problem
Sorry, I don't know what problem are you talking about, the problem which
this operator solves is described in the RFC.