Re: XML_Tree bug fix
| From: | Blair Robertson | Date: | Thu, 27 Mar 2003 00:59:47 +0000 |
| Subject: | Re: XML_Tree bug fix | ||
| References: | 1 2 3 4 5 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-14653@lists.php.net to get a copy of this message | ||
Sorry for the delay in getting back to you, and I apologise in advance
for the size of this email, but I need a bit of background in order to
explain about the patch and a small BC issue.
First if you can have a glance at the what the attached test.php does.
In my opinion when you add content and attributes to the XML_Tree_Node
and then get them out again later in the execution, they should be the
same as they went in, not escaped for XML.
In other words the call to _xml_entities() shouldn't happen in
setContent(), but in get() when we are creating the xml output.
This is particularly important because when an XML document is parsed
setContent() is called on a node and it's contents is re-escaped, after
being unescaped by PHP's xml parser.
My patch essentially does this and also escapes the attribute values
during the get() process.
These are results for test.php when using the current XML_Tree release
(1.1), the current cvs version and the patched version.
CURRENT RELEASE :
--- msgs_root->content ---
New Site "->> Blah & Co <<-" created
--- msgs_root->attributes['type'] ---
Info "Notice"
--- msgs->dump() ---
<?xml version="1.0"?>
<messages type="Info "Notice"">New Site "->> Blah &
Co <<-"
created</messages>
+ Content escaped when retrieved
+ less than, greater than and quotes not escaped in XML or content
+ attributes not escaped in XML
CURRENT CVS VERSION :
--- msgs_root->content ---
New Site "->> Blah & Co <<-" created
--- msgs_root->attributes['type'] ---
Info "Notice"
--- msgs->dump() ---
<?xml version="1.0"?>
<messages type="Info "Notice"">New Site "->>
Blah & Co
<<-" created</messages>
+ Content escaped when retrieved
+ less than, greater than and quotes not escaped in XML or content
+ attributes not escaped in XML
NEW VERSION :
--- msgs_root->content ---
New Site "->> Blah & Co <<-" created
--- msgs_root->attributes['type'] ---
Info "Notice"
--- msgs->dump() ---
<?xml version="1.0"?>
<messages type="Info "Notice"">New Site
"->>
Blah & Co <<-" created</messages>
+ Content not escaped when retrieved
+ attributes and less than, greater than and quotes escaped in XML
The potential BC issue is for people that are using the current stable
release and getting the contents from the Node and unescaping it outside
- which will cause a double unescape to happen.
Personally I think that the chances of this being an issue are slim, but
it is there.
Anyway tell me what you think.
BCR