Escaping output safely for both html and input fields

后端 未结 3 1817
名媛妹妹
名媛妹妹 2020-12-19 11:32

In my web app, users can input text data. This data can be shown to other users, and the original author can also go back and edit their data. I\'m looking for the correct w

3条回答
  •  醉话见心
    2020-12-19 12:19

    If you just need to reverse the encode then you can use html_entity_decode - http://www.php.net/manual/en/function.html-entity-decode.php.

    Another possibility to is only run htmlentities at the time the content will be displayed as part of a web page. Otherwise, keep the unencoded text, as submitted or loaded from your datastore.

提交回复
热议问题