Bug #3441: Magicquotes is not good.

From: Date: Wed, 09 Feb 2000 22:33:19 +0000
Subject: Bug #3441: Magicquotes is not good.
Groups: php.dev 
Request: Send a blank email to php-dev+get-15336@lists.php.net to get a copy of this message
From: eric@friesen.org Operating system: RedHat Linux 6.1 PHP version: 3.0.14 PHP Bug Type: Feature/Change Request Bug description: Magicquotes is not good. Magicquotes behaves in a very awkward manner. Magicquotes keeps on generating more and more backslashes in your variables if you use them in forms or in outputting HTML where you normally only want them for use in MySQL functions for example. In PERL you can formulate your SQL like so: $SQL_COMMAND = "select * from table where field like ?"; $dbh->prepare($SQL_COMMAND,$variable); this makes your sql query immune to the variable containing quotes and backslashes. But PHP lacks this feature and magicquotes sucks for this. Sure GPC guarantees that you won't have nay unescaped characters in your variable for this situation but for every other situation (echo, mail or any HTML output) you are going to be stripping the slashes in a rather annoying amount. The problem with using magicquotes can be demonstrated if you do this test.php3: <FORM action="test.php3" method="GET"> <? echo '<INPUT type="TEXT" name="test" value="' . $test . '">' ?> <INPUT TYPE="SUBMIT"></FORM> you will just keep on duplicating backslashes unless everytime you go to use a variable you strip the slashes. If PHP could do something like this: $var1 = '" or username="root'; mysql_do('select password from user where username="?"',$var1); and you wouldn't have a problem because it would recognize the ? as a place holder for the backslashed $var1. Thanks

« previous php.dev (#15336) next »