Re: Magic Quotes

From: Date: Mon, 17 Jun 2002 17:55:39 +0000
Subject: Re: Magic Quotes
References: 1  Groups: php.db 
Request: Send a blank email to php-db+get-19847@lists.php.net to get a copy of this message
Hi Bruce, Experts, please correct me or fill in the blanks: 1) I do see slashes when I echo variables after they have been posted to the next page, not sure why you do not unless there is some other setting that would affect this 2) I believe phpMyAdmin removes the slashes before displaying data by using stripslashes() (i.e. they are still stored in the DB but not displayed) 3) You should 4) Basically, as I understand it, you want the slashes because otherwise you will have problems with, for instance, executing the following query: $text = "Here's to you!"; $query = "INSERT into table (text) VALUES ('$text')"; echoing the query will produce the following: INSERT into table (text) VALUES ('Here' because the extra quote in here's would effectively be the end of your query. Yes, this could be solved by using double quotes instead of single, but then you'd have the same problem when inserting text containing double quotes. So addslashes() or magic_quotes_gpc automatically escapes any potentially problematic characters, and then you remove them with stripslashes when displaying. -Lisi At 02:37 PM 6/14/02 -0500, Bruce Vander Werf wrote:
Frankly, I've never quite "gotten" the whole quoting thing in PHP. If magic_quotes_gpc is turned on in the environment: 1. I don't see slashes in any form variables outputted with echo() or print() Does this mean that these functions effectively remove the slashes? 2. After posting the form variables, I don't see slashes when I view the MySQL data in phpMyAdmin? 3. I do see slashes in e-mail messages sent with mail() using these variables. 4. Why would you need to add slashes to anything put in a mysql database? Can someone shed some light on what is going on? -- Bruce Vander Werf brucev@cyberlink.com -- PHP Database Mailing List (http://www.php.net/) To unsubscribe, visit: http://www.php.net/unsub.php


« previous php.db (#19847) next »