note 68822 rejected from faq.html by betz
| From: | betz@php.net | Date: | Sat, 12 Aug 2006 08:47:57 +0000 |
| Subject: | note 68822 rejected from faq.html by betz | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-115820@lists.php.net to get a copy of this message | ||
Note Submitter: tchibolecafe at freemail dot hu
----
Notes on question "1. What encoding/decoding do I need when I pass a value through a
form/URL?"
Doing an htmlspecialchars() when echoing a string as an HTML attribute value is not enough to make
the string safe if you have accented (non-ASCII) characters in it. See http://www.w3.org/TR/REC-html40/appendix/notes.html#non-ascii-chars
The referred document recommends the following method to be used:
<?php
function fs_attr($path){
$retval='';
for($i=0;$i<strlen($path);$i++){
$c=$path{$i};
if(ord($c)<128){
$retval.=$c;
}else{
$retval.=urlencode(utf8_encode($c));
}
}
return htmlspecialchars($retval);
}
$img_path='anyád.jpg';
echo '<img src="'.fs_attr($img_path).'">';
?>
However, using utf8 encoding for path names is only supported by Windows NT, above method fails when
running on an Apache server on Linux.
A more fail safe way:
<?php
function fs_attr($path){
$retval='';
for($i=0;$i<strlen($path);$i++){
$c=$path{$i};
if(ord($c)<128){
$retval.=$c;
}else{
if(PHP_OS==='WINNT')
$retval.=urlencode(utf8_encode($c));
else
$retval.=urlencode($c);
}
}
return htmlspecialchars($retval);
}
?>
There may be operating systems that want utf8 encoding, other than WINNT. Even this latter one
won't work on those systems. Is there any possibility to determine exactly which encoding to be
used on the file system of the server?