-
Notifications
You must be signed in to change notification settings - Fork 162
Open
Labels
enhancementImprovements to existing rulesImprovements to existing rules

Description
Description
The following code htmlspecialchars($string, ENT_XML1, "UTF-8")
triggers the warning
38 | WARNING | The use of function htmlspecialchars() is discouraged; use
| | \Magento\Framework\Escaper->escapeHtml() instead
| | (Magento2.Functions.DiscouragedFunction.DiscouragedWithAlternative)
Expected behavior
The suggested alternative is not an equivalent solution. A brief search over the Magento codebase also reveals there is no mention of ENT_XML1
. Also \Magento\Framework\Escaper::$htmlSpecialCharsFlag
is a private property making it impossible to set ENT_XML1
in a custom implementation.
Benefits
Ensure XML content can be generated correctly with-in a Magento module.
Additional information
Solutions would be either to a.) ensure the discouraged function sniff only triggers in code that is covered by the alternative or b.) add options to escape for XML in \Magento\Framework\Escaper
Metadata
Metadata
Assignees
Labels
enhancementImprovements to existing rulesImprovements to existing rules