htmlentities() versus htmlspecialchars()?
Posted 17 May 2006 - 05:04 PM
Anyone want to take a stab at explanation?
my best guess is htmlspecialchars() only does whats needed(' " & < >) so it seems like the default choice when need to pull database values and put them into html (which needs those chars escapes). But when would you need to convert all chars to their equivalents (i know there are probably alot of scanarios but was looking for common things you see in web programming)? Someone told me encoding/decoding values into the query string, but wasnt sure.
Posted 17 May 2006 - 05:56 PM
This function is identical to htmlspecialchars() in all ways, except with htmlentities(), all characters which have HTML character entity equivalents are translated into these entities.
as for one example when you might want to translate all characters to their equivalents may be if you're creating an RSS feed or generating XML or XHTML through the PHP. for best practices, it's good to use entities rather than the symbols themselves whenever possible.
0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users