# Escaping values in dynamic stylesheets

**URL:** <https://community.open-emr.org/t/escaping-values-in-dynamic-stylesheets/21299>\
**Category:** Security\
**Created:** [October 6, 2023, 7:30pm UTC](https://community.open-emr.org/t/escaping-values-in-dynamic-stylesheets/21299 "2023-10-06T19:30:06Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![adunsulag](https://community.open-emr.org/user_avatar/community.open-emr.org/adunsulag/32/12606_2.png) [@adunsulag](https://community.open-emr.org/u/adunsulag)\
**Post date:** [October 6, 2023, 7:30pm UTC](https://community.open-emr.org/t/escaping-values-in-dynamic-stylesheets/21299/1 "2023-10-06T19:30:06Z")

</div>

So I’m injecting a dynamic value into a stylesheet. It comes from importing a value in the SMART json files but module writers could alter that value so it should be escaping in my opinion. I looked at htmlspecialchars.inc.php but I’m not seeing any existing functions to use for escaping stylesheet values. Do we have something, or do we need to implement a method for escaping inline style values. I know some security sites discourage inline **\<style\>** anyways but we have it already in a bunch of places in OpenEMR so should probably handle this.

@brady.miller I know this is your domain expertise so if you have any thoughts let me know.

---

<div class="post-metadata">

**Author:** ![brady.miller](https://community.open-emr.org/user_avatar/community.open-emr.org/brady.miller/32/10178_2.png) [@brady.miller](https://community.open-emr.org/u/brady.miller)\
**Post date:** [October 11, 2023, 5:52am UTC](https://community.open-emr.org/t/escaping-values-in-dynamic-stylesheets/21299/2 "2023-10-11T05:52:21Z")

</div>

Prob should make a specific escaping wrapper function in library/htmlspecialchars.inc.php called css\_escape that will do this. For now would simply base code in this new function on code at here (and assume is utf-8):  
[https://github.com/twigphp/Twig/blob/3.x/src/Extension/EscaperExtension.php#L300](https://github.com/twigphp/Twig/blob/3.x/src/Extension/EscaperExtension.php#L300)
