3 ms·
PHP Dark Arts: doing something beyond <p>hi there <?php echo $username ?></p>
by bhiggins 16y ago
PHP Dark Arts: doing something beyond <p>hi there <?php echo $username ?></p>
- deleted 16y ago[deleted]
- petervandijck 16y agoI know I'll get flamed for this, but that's actually beautifully elegant.
- pornel 16y agoand insecure. Correct version is: <?php echo htmlspecialchars($username); ?>
- petervandijck 16y agoThat's so incorrect I don't even know where to start.
- pornel 16y agoI'd like to hear what's incorrect about it. Do you think values should be escaped before output? Or that usernames don't include chars that need escaping in HTML? Or perhaps you'd add extra filtering to ensure that page cannot become ill-formed due to encoding error? Or perhaps it's incorrect to use PHP at all? ;)
- bhiggins 16y agowhoa, dark art alert!!