duanbei8904 2017-05-08 18:50
浏览 145

jquery'html'对php'htmlspecialchars'安全吗?

I use jquery ajax and some methods - after, replacewith, html. For all "get" and "post" data i use htmlspecialchars. Is it safe to use jquery methods when validate data using htmlspecialchars?

  • 写回答

2条回答 默认 最新

  • dscdttg4389 2017-05-08 19:05
    关注

    If you mean XSS-attack, it makes sense to format the output data:

    htmlentities($str, ENT_QUOTES, 'UTF-8');
    

    Incoming data must be escaped and checked for compliance with the type. What you output to the client affects only him.

    htmlspecialchars only convert special characters to HTML entities. This function doesn't escape variables.

    评论

报告相同问题?

悬赏问题

  • ¥15 GDI处理通道视频时总是带有白色锯齿
  • ¥20 用雷电模拟器安装百达屋apk一直闪退
  • ¥15 算能科技20240506咨询(拒绝大模型回答)
  • ¥15 自适应 AR 模型 参数估计Matlab程序
  • ¥100 角动量包络面如何用MATLAB绘制
  • ¥15 merge函数占用内存过大
  • ¥15 Revit2020下载问题
  • ¥15 使用EMD去噪处理RML2016数据集时候的原理
  • ¥15 神经网络预测均方误差很小 但是图像上看着差别太大
  • ¥15 单片机无法进入HAL_TIM_PWM_PulseFinishedCallback回调函数