Re: [RFC] Improve HTML escape

From: Date: Sun, 02 Feb 2014 03:33:37 +0000
Subject: Re: [RFC] Improve HTML escape
References: 1 2  Groups: php.internals 
Request: Send a blank email to [email protected] to get a copy of this message
Hi Andrea,

On Sun, Feb 2, 2014 at 12:27 PM, Andrea Faulds <[email protected]> wrote:

> On 02/02/14 03:09, Yasuo Ohgaki wrote:
>
>> "/" escape is recommended by OWASP and we may follow them.
>>
>
> Surely if this is to stop <foo bar=<?=htmlspecialchars($foobar); ?>>,
> then we'd have to escape ' ' too?


Making ENT_QUOTES as a default is good idea also.
I should have add this to the RFC.

Regards,

--
Yasuo Ohgaki
[email protected]


Thread (37 messages)

« previous php.internals (#71972) next »