Re: XML_Feed_Parser and HTML security

From: Date: Wed, 16 Aug 2006 21:06:11 +0000
Subject: Re: XML_Feed_Parser and HTML security
References: 1 2 3  Groups: php.pear.dev 
Request: Send a blank email to pear-dev+get-43712@lists.php.net to get a copy of this message
On Wed, 16 Aug 2006 20:27:18 +0200, Martin Jansen wrote: > On Wed Aug 16, 2006 at 11:3937AM -0400, Arnaud Limbourg wrote: >> What about filtering html and give methods to access the raw input ? >> >> It makes the package relatively safe to use and different methods make >> it clear that it is the unfiltered content being accessed without the >> need to see if a parameter is set to true or false. > > This sounds like the best compromise to me. I wonder why we should pollute the package, as in we should keep the API clean, I mean why not just document that the user has to do the escaping them self and provide example with HTML_Safe or so (users are suckers for doing a copy/paste from the examples ;)) Tho I suppose adding the security part to the project isn't all that bad. One idea would be to have 2 packages, feed_parser and feed_parser_security, the latter is on top of the first one and thus we kinda have the raw/safe API and the user just instances the package depending on what they want but that of course isn't optimal approach at all ;-) Just brainfarting a bit =) - Helgi

« previous php.pear.dev (#43712) next »