doulang2311 2009-02-03 15:40
浏览 45
已采纳

使用Zend Framework逃避用户输出的最佳方法是什么?

I'm a little confused by what I should use to escape user output.

Firstly, there's the Zend_Filter_Input class which looks like it might do what I want but seems oriented towards batch filtering lots of items. At the moment I only want to filter one. Also I'm a little confused by the definition of escapers compared to filters. What's the difference between the StringTrim filter and the escaper?

Is there a better solution for escaping single elements?

  • 写回答

3条回答 默认 最新

  • dsqve08622 2009-02-03 18:07
    关注

    Filters are great on your forms so that you can clean & normalize your data before processing/storing it. You mentioned StringTrim - you've got other ones that ensure capitalization or that your input is all numeric (or alphanumeric or...). Make a note that this is to ensure consistency and sanity in your data - not for avoiding SQL injection - ZF's Database libraries handle that as a separate issue.

    On the flip-side of this, you get to escape things for output. While "x < 5" or "PB&J" may be perfectly valid data to store and process in your system, they can cause problems when displayed on a web page. This is why you'd normally use htmlspecialchars() or htmlentities() - by default, Zend_View uses htmlspecialchar() when you $this->escape($foo).

    本回答被题主选为最佳回答 , 对您是否有帮助呢?
    评论
查看更多回答(2条)

报告相同问题?

悬赏问题

  • ¥15 Mac系统vs code使用phpstudy如何配置debug来调试php
  • ¥15 目前主流的音乐软件,像网易云音乐,QQ音乐他们的前端和后台部分是用的什么技术实现的?求解!
  • ¥60 pb数据库修改与连接
  • ¥15 spss统计中二分类变量和有序变量的相关性分析可以用kendall相关分析吗?
  • ¥15 拟通过pc下指令到安卓系统,如果追求响应速度,尽可能无延迟,是不是用安卓模拟器会优于实体的安卓手机?如果是,可以快多少毫秒?
  • ¥20 神经网络Sequential name=sequential, built=False
  • ¥16 Qphython 用xlrd读取excel报错
  • ¥15 单片机学习顺序问题!!
  • ¥15 ikuai客户端多拨vpn,重启总是有个别重拨不上
  • ¥20 关于#anlogic#sdram#的问题,如何解决?(关键词-performance)