[PEPr] Comment on HTML::HTML_Safe
| From: | Daniel Convissor | Date: | Sun, 30 Jan 2005 16:47:29 +0000 |
| Subject: | [PEPr] Comment on HTML::HTML_Safe | ||
| References: | 1 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-35803@lists.php.net to get a copy of this message | ||
Daniel Convissor (http://pear.php.net/user/danielc) has commented on the proposal for
HTML::HTML_Safe.
Comment:
Is there any relation between your package and SafeHTML?
http://freshmeat.net/projects/safehtml/
Does your package deal with people trying to obfuscate their attacks by
using HTML entities (both ordinal and hex)? This was an issue in SafeHTML
which they apparently addressed in release 1.2.1.
The layout of arrays could use some neatening up, including
alphabetizing:
$array = array(
'another',
'value',
);
Some other pedantic comments:
* use single quotes instead of double quotes around strings when
possible.
* put spaces between concatenated elements (eg "/" . $css . "/i") and
assignment operators (eg $this->_xhtml .= "<" . $name;).
Proposal information:
http://pear.php.net/pepr/pepr-proposal-show.php?id=199
--
Sent by PEPr, the automatic proposal system at http://pear.php.net