Re: [PEPr] Comment on Web Services::Services_ABR
| From: | Alan Knowles | Date: | Wed, 28 Sep 2005 11:55:54 +0000 |
| Subject: | Re: [PEPr] Comment on Web Services::Services_ABR | ||
| References: | 1 2 3 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-39954@lists.php.net to get a copy of this message | ||
Partly because it's in the CS AFAIR, which used to be due to the speed
difference, but in reality using '' allows you to ignore blocks of code
when reviewing potential security issues caused by intopolating
variables into strings without correctly escaping...
eg.
$x = 'xxx'; // is always safe
$y= "something {$xxx} else"; // may be outputing unescaped text, and
needs to be considered/checked.
Regards
Alan
On Wed, 2005-09-28 at 13:14 +0200, Martin Jansen wrote:
> On Tue Sep 27, 2005 at 09:5133PM -0000, Philippe Jausions wrote:
> > Just one thing, try to use single quotes whenever possible instead of the
> > double-quotes around string.
>
> Why should he be doing that?
>
> - Martin
>