<?php echo htmlspecialchars($name); ?>
Here's how to do the same thing in Django:
{{ name }}
That's the thing that bugs me most about PHP: it's not even a productive templating language!
<?php echo htmlspecialchars($name); ?>
Here's how to do the same thing in Django:
{{ name }}
That's the thing that bugs me most about PHP: it's not even a productive templating language!
In any case, my intent wasn't to compare Django to PHP, it was to point out that PHP's default way of outputting things really does make it inconvenient to write secure code - hence answering the parent post that argued that poor security had nothing to do with the language used.
I realize I'm playing devil's advocate because I love Python, but you shouldn't put blame nor give credit where it isn't due.
function o($name) { echo htmlspecialchars($name); }
o($name);
<?php o($name); ?>
I've used this exact function in my own code, though I call it "h". Really sucks that we have to do this - not to mention that PHP's global namespace for functions means it's better to have long names that are more likely not to clash with third party code.
function o($name) { return(htmlspecialchars($name));}
<?=o($name)?>
which lo, and behold, looks a lot like the rails candidate below.
<%= h(@var) %>