note 88490 added to function.htmlspecialchars-decode
| From: | benharoldatmacdotcom at osu1 dot php dot net | Date: | Mon, 26 Jan 2009 21:30:33 +0000 |
| Subject: | note 88490 added to function.htmlspecialchars-decode | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-149806@lists.php.net to get a copy of this message | ||
If you use
htmlspecialchars() to change things like the ampersand (&) into
it's HTML equivalent (&), you might run into a situation where you mistakenly pass the
same string to the function twice, resulting in things appearing on your website like, as I call it,
the ampersanded amp; "&". Clearly nobody want's "&" on his
or her web page where there is supposed to be just an ampersand. Here's a quick and easy trick
to make sure this doesn't happen:
<?php
$var = "This is a string that could be passed to htmlspecialchars multiple times.";
if (htmlspecialchars_decode($var) == $var) {
$var = htmlspecialchars($var);
}
echo $var;
?>
Now, if your dealing with text that is a mixed bag (has HTML entities and non-HTML entities)
you're on your own.
----
Server IP: 64.71.164.2
Probable Submitter: 2002:4ada:c1c6:0:21b:63ff:fe06:6e39
----
Manual Page -- http://www.php.net/manual/en/function.htmlspecialchars-decode.php
Edit -- https://master.php.net/note/edit/88490
Del: integrated -- https://master.php.net/note/delete/88490/integrated
Del: useless -- https://master.php.net/note/delete/88490/useless
Del: bad code -- https://master.php.net/note/delete/88490/bad+code
Del: spam -- https://master.php.net/note/delete/88490/spam
Del: non-english -- https://master.php.net/note/delete/88490/non-english
Del: in docs -- https://master.php.net/note/delete/88490/in+docs
Del: other reasons-- https://master.php.net/note/delete/88490
Reject -- https://master.php.net/note/reject/88490
Search -- https://master.php.net/manage/user-notes.php