note 37609 added to function.htmlspecialchars
| From: | mike-php at emerge2 dot com | Date: | Thu, 20 Nov 2003 19:13:16 +0000 |
| Subject: | note 37609 added to function.htmlspecialchars | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-60712@lists.php.net to get a copy of this message | ||
Here's a handy function that guards against 'double' encoding:
# Given a string, this function first strips out all html special characters, then
# encodes the string, safely returning an encoded string without double-encoding.
function get_htmlspecialchars( $given, $quote_style = ENT_QUOTES ){
return htmlspecialchars( html_entity_decode( $given, $quote_style ), $quote_style );
}
# Needed for older versions of PHP that do not have this function built-in.
function html_entity_decode( $given_html, $quote_style = ENT_QUOTES ) {
$trans_table = get_html_translation_table( HTML_SPECIALCHARS, $quote_style );
if( $trans_table["'"] != ''' ) { # some versions of PHP match
single quotes to '
$trans_table["'"] = ''';
}
return ( strtr( $given_html, array_flip( $trans_table ) ) );
}
Note: I set the default to ENT_QUOTES, as this makes more sense to me than the PHP function's
default of ENT_COMPAT.
----
Manual Page -- http://www.php.net/manual/en/function.htmlspecialchars.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+37609
Delete -- http://master.php.net/manage/user-notes.php?action=delete+37609&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+37609&report=yes
Search -- http://master.php.net/manage/user-notes.php