note 54974 deleted from function.simplexml-load-file by nlopess
| From: | nlopess@php.net | Date: | Tue, 06 Sep 2005 15:22:09 +0000 |
| Subject: | note 54974 deleted from function.simplexml-load-file by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-94817@lists.php.net to get a copy of this message | ||
Note Submitter: Frank Denis - Jedi/Sector One
----
An important thing to note is that the argument to simplexml_load_file() is not a file name, but it
has to be an encoded file name.
If you try to do :
simplexml_load_file('http://example.com/a=' .
urlencode('b&c'));
The function will load http://example.com/a=b&c which
means that the content of 'a' will be 'b' not 'b&c', as if
urlencode() was pointless.
You *must* rawurlencode() every URL passed to simplexml_load_file() in order to have it work as
expected, or you can even get unwanted security flaws :
simplexml_load_file(rawurlencode('http://example.com/a=' .
urlencode('b&c')));
And you get the right behavior.