Home » Php » php – Escaping/encoding single quotes in JSON encoded HTML5 data attributes

php – Escaping/encoding single quotes in JSON encoded HTML5 data attributes

Posted by: admin April 23, 2020 Leave a comment

Questions:

In PHP, I use json_encode() to echo arrays in HTML5 data attributes.
As JSON requires – and json_encode() generates – values encapsulated by double quotes. I therefor wrap my data attributes with single quotes, like:

<article data-tags='["html5","jquery","php","test's"]'>

As you can see, the last tag (test’s) contains a single quote, and using json_encode() with no options leads to parsing problems.

So I use json_encode() with the JSON_HEX_APOS parameter, and parsing is fine, as my single quotes are encoded, but I wonder: is there a downside doing it like this?

How to&Answers:

You need to HTML escape data echoed into HTML:

printf('<article data-tags="%s">',
    htmlspecialchars(json_encode(array('html5', ...)), ENT_QUOTES, 'UTF-8'));

Answer:

or use the build-in option:

json_encode(array('html5', ...), JSON_HEX_APOS)

you can check it up in the manual: http://php.net/manual/en/json.constants.php#constant.json-hex-apos