note 68831 added to faq.html

From: Date: Sat, 12 Aug 2006 11:34:37 +0000
Subject: note 68831 added to faq.html
Groups: php.notes 
Request: Send a blank email to php-notes+get-115825@lists.php.net to get a copy of this message
Notes on question "1. What encoding/decoding do I need when I pass a value through a form/URL?" Doing an htmlspecialchars() when echoing a string as an HTML attribute value is not enough to make the string safe if you have accented (non-ASCII) characters in it. See http://www.w3.org/TR/REC-html40/appendix/notes.html#non-ascii-chars The referred document recommends the following method to be used: <?php function fs_attr($path){ $retval=''; for($i=0;$i<strlen($path);$i++){ $c=$path{$i}; if(ord($c)<128){ $retval.=$c; }else{ $retval.=urlencode(utf8_encode($c)); } } return htmlspecialchars($retval); } $img_path='éöüä.jpg'; echo '<img src="'.fs_attr($img_path).'">'; ?> However, using utf8 encoding for path names is among others supported by Windows NT, above method fails when running for example on an Apache server on Linux. A more fail safe way: <?php function fs_attr($path){ $retval=''; for($i=0;$i<strlen($path);$i++){ $c=$path{$i}; if(ord($c)<128){ $retval.=$c; }else{ if(PHP_OS==='WINNT') $retval.=urlencode(utf8_encode($c)); else $retval.=urlencode($c); } } return htmlspecialchars($retval); } ?> There may be operating systems that want utf8 encoding, other than WINNT. Even this latter one won't work on those systems. I don't know about any possibility to determine immediately which encoding to be used on the file system of the server... ---- Server IP: 195.70.37.52 Probable Submitter: 84.0.167.107 ---- X-Spam-Status: No, hits=4.8 required=5.0 tests=DATE_MISSING,FROM_NO_LOWER, HTML_30_40,HTML_IMAGE_ONLY_10,HTML_MESSAGE autolearn=no version=2.64 ---- Manual Page -- http://www.php.net/manual/en/faq.html.php Edit -- https://master.php.net/note/edit/68831 Del: integrated -- https://master.php.net/note/delete/68831/integrated Del: useless -- https://master.php.net/note/delete/68831/useless Del: bad code -- https://master.php.net/note/delete/68831/bad+code Del: spam -- https://master.php.net/note/delete/68831/spam Del: non-english -- https://master.php.net/note/delete/68831/non-english Del: in docs -- https://master.php.net/note/delete/68831/in+docs Del: other reasons-- https://master.php.net/note/delete/68831 Reject -- https://master.php.net/note/reject/68831 Search -- https://master.php.net/manage/user-notes.php

« previous php.notes (#115825) next »