Re: html entities
| From: | Marek Kilimajer | Date: | Sat, 05 Mar 2005 14:20:35 +0000 |
| Subject: | Re: html entities | ||
| References: | 1 | Groups: | php.pear.general |
| Request: | Send a blank email to pear-general+get-17865@lists.php.net to get a copy of this message | ||
fluidliqatyahoodotcom wrote:
I never did anything to store it as HTML entities in the db. PEAR converted it itself and stored it into the db. on line 140 of common.php in the PHP PEAR, there is this line: $strAttr .= ' ' . $key . '="' . htmlspecialchars($value) . '"'; this line converts all the values to html entities with the htmlspecialchars().This is ok, PEAR should do that. If it does not, your site would be vulnerable to XSS atacks.
I tried things like html_entity_decode before storing into the db so that it will be saved as its characters but it didn't work.You should be able to use html_entity_decode(), but only with the third parameter (charset). Look at http://www.php.net/html_entity_decode if your character set is supported. Else you will have to specify the charset on the page so browser sends text in the right charset and not in html entities.