Re: [RFC] New operator for context-dependent escaping
| From: | Michael Vostrikov | Date: | Sun, 31 Jul 2016 05:16:29 +0000 |
| Subject: | Re: [RFC] New operator for context-dependent escaping | ||
| References: | 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 | Groups: | php.internals |
| Request: | Send a blank email to internals+get-94760@lists.php.net to get a copy of this message | ||
2016-07-31 1:49 GMT+05:00 Reinis Rozitis <r@roze.lv>:
> From: Michael Vostrikov
>>
>> The problem is that these functions should be called everywhere manually,
>> and there is no error when these functions are not called.
>> And this RFC proposes a solution - call a function automatically.
>>
>
> Though you can use pecl/taint for that.
> If anything imo it would make more sense to propose/vote for such
> functionality to be included in core.
>
How can I use it for that?
<?php $user['description'] = 'Some data from DB with
<script>alert("XSS");</script>'; ?>
<?= $a ?>
The code does not procude any error messages. This extension works only for
variables from GET, POST, COOKIE, this is not escaping of output data.