note 68831 added to faq.html
| From: | tchibolecafe at freemail dot hu | Date: | Sat, 12 Aug 2006 11:34:37 +0000 |
| Subject: | note 68831 added to faq.html | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-115825@lists.php.net to get a copy of this message | ||
Notes on question "1. What encoding/decoding do I need when I pass a value through a
form/URL?"
Doing an htmlspecialchars() when echoing a string as an HTML attribute value is not enough to make
the string safe if you have accented (non-ASCII) characters in it. See http://www.w3.org/TR/REC-html40/appendix/notes.html#non-ascii-chars
The referred document recommends the following method to be used:
<?php
function fs_attr($path){
$retval='';
for($i=0;$i<strlen($path);$i++){
$c=$path{$i};
if(ord($c)<128){
$retval.=$c;
}else{
$retval.=urlencode(utf8_encode($c));
}
}
return htmlspecialchars($retval);
}
$img_path='éöüä.jpg';
echo '<img src="'.fs_attr($img_path).'">';
?>
However, using utf8 encoding for path names is among others supported by Windows NT, above method
fails when running for example on an Apache server on Linux.
A more fail safe way:
<?php
function fs_attr($path){
$retval='';
for($i=0;$i<strlen($path);$i++){
$c=$path{$i};
if(ord($c)<128){
$retval.=$c;
}else{
if(PHP_OS==='WINNT')
$retval.=urlencode(utf8_encode($c));
else
$retval.=urlencode($c);
}
}
return htmlspecialchars($retval);
}
?>
There may be operating systems that want utf8 encoding, other than WINNT. Even this latter one
won't work on those systems. I don't know about any possibility to determine immediately
which encoding to be used on the file system of the server...
----
Server IP: 195.70.37.52
Probable Submitter: 84.0.167.107
----
X-Spam-Status: No, hits=4.8 required=5.0 tests=DATE_MISSING,FROM_NO_LOWER,
HTML_30_40,HTML_IMAGE_ONLY_10,HTML_MESSAGE autolearn=no version=2.64
----
Manual Page -- http://www.php.net/manual/en/faq.html.php
Edit -- https://master.php.net/note/edit/68831
Del: integrated -- https://master.php.net/note/delete/68831/integrated
Del: useless -- https://master.php.net/note/delete/68831/useless
Del: bad code -- https://master.php.net/note/delete/68831/bad+code
Del: spam -- https://master.php.net/note/delete/68831/spam
Del: non-english -- https://master.php.net/note/delete/68831/non-english
Del: in docs -- https://master.php.net/note/delete/68831/in+docs
Del: other reasons-- https://master.php.net/note/delete/68831
Reject -- https://master.php.net/note/reject/68831
Search -- https://master.php.net/manage/user-notes.php