Bug #3441: Magicquotes is not good.
| From: | eric at friesen dot org | Date: | Wed, 09 Feb 2000 22:33:19 +0000 |
| Subject: | Bug #3441: Magicquotes is not good. | ||
| Groups: | php.dev | ||
| Request: | Send a blank email to php-dev+get-15336@lists.php.net to get a copy of this message | ||
From: eric@friesen.org
Operating system: RedHat Linux 6.1
PHP version: 3.0.14
PHP Bug Type: Feature/Change Request
Bug description: Magicquotes is not good.
Magicquotes behaves in a very awkward manner. Magicquotes keeps on generating more and more
backslashes in your variables if you use them in forms or in outputting HTML where you normally only
want them for use in MySQL functions for example. In PERL you can formulate your SQL like so:
$SQL_COMMAND = "select * from table where field like ?";
$dbh->prepare($SQL_COMMAND,$variable);
this makes your sql query immune to the variable containing quotes and backslashes. But PHP lacks
this feature and magicquotes sucks for this. Sure GPC guarantees that you won't have nay
unescaped characters in your variable for this situation but for every other situation (echo, mail
or any HTML output) you are going to be stripping the slashes in a rather annoying amount.
The problem with using magicquotes can be demonstrated if you do this
test.php3:
<FORM action="test.php3" method="GET">
<? echo '<INPUT type="TEXT" name="test" value="' . $test .
'">' ?>
<INPUT TYPE="SUBMIT"></FORM>
you will just keep on duplicating backslashes unless everytime you go to use a variable you strip
the slashes.
If PHP could do something like this:
$var1 = '" or username="root';
mysql_do('select password from user where username="?"',$var1);
and you wouldn't have a problem because it would recognize the ? as a place holder for the
backslashed $var1.
Thanks