Re: [PEPr] Comment on HTML::HTML_Safe
| From: | Roman Ivanov | Date: | Sun, 30 Jan 2005 17:11:33 +0000 |
| Subject: | Re: [PEPr] Comment on HTML::HTML_Safe | ||
| References: | 1 2 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-35806@lists.php.net to get a copy of this message | ||
> Is there any relation between your package and SafeHTML?
> http://freshmeat.net/projects/safehtml/
HTML_Safe is renamed SafeHTML. It was done because SafeHTML is not a
proper package name for PEAR. I'm an author of SafeHTML.
> Does your package deal with people trying to obfuscate their attacks by
> using HTML entities (both ordinal and hex)? This was an issue in SafeHTML
> which they apparently addressed in release 1.2.1.
Not they but me =)
1.3.0 address it better than 1.2.1.
> The layout of arrays could use some neatening up, including
> alphabetizing:
>
> $array = array(
> 'another',
> 'value',
> );
Oops. Is such formatting (not alphabetizing) really needed? Size of
HTML_Safe is 16K - 2 times more than SafeHTML (which is not rewritten
under PEAR standards). Formatting of arrays` definition will increase
size and decrease readability (readability will be decreased due to
growth array-defining code over size of screen).
> Some other pedantic comments:
>
> * use single quotes instead of double quotes around strings when
> possible.
Fixed.
> * put spaces between concatenated elements (eg "/" . $css . "/i") and
> assignment operators (eg $this->_xhtml .= "<" . $name;).
Fixed.
--
Roman.
http://www.npj.ru/kukutz