#44748 [Asn->Csd]: php.ini comments on magic_quotes_gpc promote bad practices
| From: | kalle@php.net | Date: | Sun, 26 Oct 2008 15:40:42 +0000 |
| Subject: | #44748 [Asn->Csd]: php.ini comments on magic_quotes_gpc promote bad practices | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-1249@lists.php.net to get a copy of this message | ||
ID: 44748
Updated by: kalle@php.net
Reported By: johnston dot joshua at gmail dot com
-Status: Assigned
+Status: Closed
Bug Type: Documentation problem
Operating System: any
PHP Version: Irrelevant
Assigned To: kalle
New Comment:
This bug has been fixed in the documentation's XML sources. Since the
online and downloadable versions of the documentation need some time
to get updated, we would like to ask you to be a bit patient.
Thank you for the report, and for helping us make our documentation
better.
I updated PHP 5.3 and PHP 5.2's php.ini-recommeded to reflect this as
HEAD is not affected by this.
Previous Comments:
------------------------------------------------------------------------
[2008-04-16 19:34:47] johnston dot joshua at gmail dot com
Description:
------------
The section at the top related to magic_quotes_gpc suggests
addslashes() for database escaping. It should instead say to use your
the escaping function that is native to your database extension.
; - magic_quotes_gpc = Off [Performance]
; Input data is no longer escaped with slashes so that it can be
sent into
; SQL databases without further manipulation. Instead, you should
use the
; function addslashes() on each input element you wish to send to a
database.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/?id=44748&edit=1