Re: XML_Feed_Parser and HTML security
| From: | Helgi Þormar Þorbjörnsson | Date: | Wed, 16 Aug 2006 21:06:11 +0000 |
| Subject: | Re: XML_Feed_Parser and HTML security | ||
| References: | 1 2 3 | Groups: | php.pear.dev |
| Request: | Send a blank email to pear-dev+get-43712@lists.php.net to get a copy of this message | ||
On Wed, 16 Aug 2006 20:27:18 +0200, Martin Jansen wrote:
> On Wed Aug 16, 2006 at 11:3937AM -0400, Arnaud Limbourg wrote:
>> What about filtering html and give methods to access the raw input ?
>>
>> It makes the package relatively safe to use and different methods make
>> it clear that it is the unfiltered content being accessed without the
>> need to see if a parameter is set to true or false.
>
> This sounds like the best compromise to me.
I wonder why we should pollute the package, as in we should keep the API
clean, I mean why not just document that the user has to do the escaping
them self and provide example with HTML_Safe or so (users are suckers for
doing a copy/paste from the examples ;))
Tho I suppose adding the security part to the project isn't all that bad.
One idea would be to have 2 packages, feed_parser and
feed_parser_security, the latter is on top of the first one and thus we
kinda have the raw/safe API and the user just instances the package
depending on what they want but that of course isn't optimal approach at
all ;-) Just brainfarting a bit =)
- Helgi