Bug #17758: magic_quotes_gpc causes more trouble than it helps
| From: | php dot net at odi dot ch | Date: | Fri, 14 Jun 2002 07:23:50 +0000 |
| Subject: | Bug #17758: magic_quotes_gpc causes more trouble than it helps | ||
| Groups: | php.bugs | ||
| Request: | Send a blank email to php-bugs+get-10425@lists.php.net to get a copy of this message | ||
From: php.net@odi.ch
Operating system:
PHP version: 4.0CVS-2002-06-14
PHP Bug Type: PHP options/info functions
Bug description: magic_quotes_gpc causes more trouble than it helps
magic_quotes_gpc is a bad idea and should be abandoned for the following
reasons:
While the option may look very tempting at the first glance there are some
caveats however:
1. Most parameters do not go to a database.
In a web application most form field are used internally without the need
to store them in a database. Magic quotes cause troubles in these cases.
Moreover the data passed to the application is not the data entered by the
user if it was processed by magic quotes. This is undesireable.
2. Impedes code reuse.
If you feed data from either form parameters or internal data sources into
the same function then your function must know if the data was processed
by magic quotes or not.
3. Bad surprises at deployment time and code portability.
If you do not carefully check if this parameter is set on your development
and production system you can run into troubles. Especially if you can not
change the settings on one system (because the hoster does not let you).
4. Behaviour can not be controlled at script runtime.
The ini_set does not help in this case. Even though the parameter can be
modified at runtime the behaviour does not change. Consequently you are
bound to the php.ini settings (which may be not under the developer's
control).
I therefore request that this (and related) option be removed from future
versions of PHP and the default behaviour should be FALSE.
--
Edit bug report at http://bugs.php.net/?id=17758&edit=1
--
Fixed in CVS: http://bugs.php.net/fix.php?id=17758&r=fixedcvs
Fixed in release: http://bugs.php.net/fix.php?id=17758&r=alreadyfixed
Need backtrace: http://bugs.php.net/fix.php?id=17758&r=needtrace
Try newer version: http://bugs.php.net/fix.php?id=17758&r=oldversion
Not developer issue: http://bugs.php.net/fix.php?id=17758&r=support
Expected behavior: http://bugs.php.net/fix.php?id=17758&r=notwrong
Not enough info: http://bugs.php.net/fix.php?id=17758&r=notenoughinfo
Submitted twice: http://bugs.php.net/fix.php?id=17758&r=submittedtwice
register_globals: http://bugs.php.net/fix.php?id=17758&r=globals