Bug #65290 [Opn->Csd]: The doc for addslashes should not describe database escaping as the use case
| From: | yohgaki@php.net | Date: | Mon, 22 Jul 2013 23:26:46 +0000 |
| Subject: | Bug #65290 [Opn->Csd]: The doc for addslashes should not describe database escaping as the use case | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-10106@lists.php.net to get a copy of this message | ||
Edit report at https://bugs.php.net/bug.php?id=65290&edit=1
ID: 65290
Updated by: yohgaki@php.net
Reported by: stof at notk dot org
Summary: The doc for addslashes should not describe database
escaping as the use case
-Status: Open
+Status: Closed
Type: Bug
Package: Documentation problem
PHP Version: Irrelevant
-Assigned To:
+Assigned To: yohgaki
Block user comment: N
Private report: N
Previous Comments:
------------------------------------------------------------------------
[2013-07-22 23:25:35] yohgaki@php.net
Automatic comment from SVN on behalf of yohgaki
Revision: http://svn.php.net/viewvc/?view=revision&revision=331006
Log: Fix bug #65290
------------------------------------------------------------------------
[2013-07-18 16:01:12] stof at notk dot org
Description:
------------
Using addslashes to escape the input for the database is a really bad idea. But the doc of the
function still describe it as the use case (and then warns that there is better ways to do it).
I think it would be better to avoid mentionning the database escaping for the use case of the
function, to avoid teaching unsecure practices.
Lazy people would stop reading before the end of the description and only see the suggestion of
using it for escaping.
------------------------------------------------------------------------
--
Edit this bug report at https://bugs.php.net/bug.php?id=65290&edit=1