note 54974 deleted from function.simplexml-load-file by nlopess

From: Date: Tue, 06 Sep 2005 15:22:09 +0000
Subject: note 54974 deleted from function.simplexml-load-file by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-94817@lists.php.net to get a copy of this message
Note Submitter: Frank Denis - Jedi/Sector One ---- An important thing to note is that the argument to simplexml_load_file() is not a file name, but it has to be an encoded file name. If you try to do : simplexml_load_file('http://example.com/a=' . urlencode('b&c')); The function will load http://example.com/a=b&c which means that the content of 'a' will be 'b' not 'b&c', as if urlencode() was pointless. You *must* rawurlencode() every URL passed to simplexml_load_file() in order to have it work as expected, or you can even get unwanted security flaws : simplexml_load_file(rawurlencode('http://example.com/a=' . urlencode('b&c'))); And you get the right behavior.

« previous php.notes (#94817) next »