Re: [RFC] New operator for context-dependent escaping

From: Date: Sun, 31 Jul 2016 05:16:29 +0000
Subject: Re: [RFC] New operator for context-dependent escaping
References: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17  Groups: php.internals 
Request: Send a blank email to internals+get-94760@lists.php.net to get a copy of this message
2016-07-31 1:49 GMT+05:00 Reinis Rozitis <r@roze.lv>: > From: Michael Vostrikov >> >> The problem is that these functions should be called everywhere manually, >> and there is no error when these functions are not called. >> And this RFC proposes a solution - call a function automatically. >> > > Though you can use pecl/taint for that. > If anything imo it would make more sense to propose/vote for such > functionality to be included in core. > How can I use it for that? <?php $user['description'] = 'Some data from DB with <script>alert("XSS");</script>'; ?> <?= $a ?> The code does not procude any error messages. This extension works only for variables from GET, POST, COOKIE, this is not escaping of output data.

« previous php.internals (#94760) next »