Place htmlspecialchars in PHP script
Hello,
I just placed my scripts on another server (infinityfree), but these do not display special characters.
I saw that we use the function :
function htmlspecialchars(
$string,
$flags = ENT_QUOTES | ENT_SUBSTITUTE | ENT_HTML401,
$encoding = ,
$double_encode =
):
But where should I place it? Only in index.php or in all scripts? And where exactly?
Thanks
3 answers
-
Hello,
It would be preferable to continue the previous discussion, because the context and history are important.
Regarding htmlspecialchars, its role is to clean/secure text before storing it in a database; this function will not resolve accent issues following a hosting provider migration.
So, to better understand, it would be useful to know whether the problem affects the text present in the database, or if it concerns all the text on the page. -
Hello,
Look at the examples:
You will need this for everything displayed from content entered by a user (you want to control what is shown and avoid injections)
(Feldrip's answer is also valid)
-
Hello,
The functions htmlspecialchars or htmlentities, as their names indicate, should be used when displaying data in an HTML document.
Contrary to a bad practice unfortunately common, you should not use htmlspecialchars before saving to the database because this will cause other data processing issues in the database.
More info: zestedesavoir.com/articles/2489/ne-pas-confondre-faille-par-injection-sql-et-faille-xss/If the problem of displaying special characters comes from data stored in the database, the issue often lies with the charset of the database connection.
You simply need to set the charset after the connection, via set_charset with mysqli or in the DNS with PDO (see first comment on the doc):
www.php.net/manual/fr/mysqli.set-charset.php
www.php.net/manual/fr/pdo.construct.php