note 68822 added to faq.html
| From: | tchibolecafe at freemail dot hu | Date: | Fri, 11 Aug 2006 23:54:27 +0000 |
| Subject: | note 68822 added to faq.html | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-115815@lists.php.net to get a copy of this message | ||
Notes on question "1. What encoding/decoding do I need when I pass a value through a
form/URL?"
Doing an htmlspecialchars() when echoing a string as an HTML attribute value is not enough to make
the string safe if you have accented (non-ASCII) characters in it. See http://www.w3.org/TR/REC-html40/appendix/notes.html#non-ascii-chars
The referred document recommends the following method to be used:
<?php
function fs_attr($path){
$retval='';
for($i=0;$i<strlen($path);$i++){
$c=$path{$i};
if(ord($c)<128){
$retval.=$c;
}else{
$retval.=urlencode(utf8_encode($c));
}
}
return htmlspecialchars($retval);
}
$img_path='anyád.jpg';
echo '<img src="'.fs_attr($img_path).'">';
?>
However, using utf8 encoding for path names is only supported by Windows NT, above method fails when
running on an Apache server on Linux.
A more fail safe way:
<?php
function fs_attr($path){
$retval='';
for($i=0;$i<strlen($path);$i++){
$c=$path{$i};
if(ord($c)<128){
$retval.=$c;
}else{
if(PHP_OS==='WINNT')
$retval.=urlencode(utf8_encode($c));
else
$retval.=urlencode($c);
}
}
return htmlspecialchars($retval);
}
?>
There may be operating systems that want utf8 encoding, other than WINNT. Even this latter one
won't work on those systems. Is there any possibility to determine exactly which encoding to be
used on the file system of the server?
----
Server IP: 195.70.37.52
Probable Submitter: 84.2.148.18
----
X-Spam-Status: No, hits=4.6 required=5.0 tests=DATE_MISSING,FROM_NO_LOWER,
HTML_20_30,HTML_IMAGE_ONLY_10,HTML_MESSAGE autolearn=no version=2.64
----
Manual Page -- http://www.php.net/manual/en/faq.html.php
Edit -- https://master.php.net/note/edit/68822
Del: integrated -- https://master.php.net/note/delete/68822/integrated
Del: useless -- https://master.php.net/note/delete/68822/useless
Del: bad code -- https://master.php.net/note/delete/68822/bad+code
Del: spam -- https://master.php.net/note/delete/68822/spam
Del: non-english -- https://master.php.net/note/delete/68822/non-english
Del: in docs -- https://master.php.net/note/delete/68822/in+docs
Del: other reasons-- https://master.php.net/note/delete/68822
Reject -- https://master.php.net/note/reject/68822
Search -- https://master.php.net/manage/user-notes.php