What's the best practice to set html attribute via PHP?

后端 未结 4 950
遥遥无期
遥遥无期 2020-11-27 06:07

When doing this job in PHP,one may meet this kind of issue:

\">...

The problem is that if

4条回答
  •  孤独总比滥情好
    2020-11-27 06:33

    To address your edit [Edit: that you have removed meanwhile]: When you place dynamically JavaScript onto your site, you should before know quite well, what it would look like. Else you open the door widely for XSS attacks. That doesn't mean you have to know every quotation mark, but you should know enough to decide how to embed it at the line where you finally output it in the HTML file.

    Beyond that,

    
    

    works exactly like

    
    

提交回复
热议问题