Doc #54365 [Wfx]: addslashes says that magic_quotes_gpc is on but it's not the case
| From: | shein@php.net | Date: | Thu, 24 Mar 2011 07:40:49 +0000 |
| Subject: | Doc #54365 [Wfx]: addslashes says that magic_quotes_gpc is on but it's not the case | ||
| References: | 1 | Groups: | php.doc.bugs |
| Request: | Send a blank email to doc-bugs+get-6136@lists.php.net to get a copy of this message | ||
Edit report at http://bugs.php.net/bug.php?id=54365&edit=1
ID: 54365
User updated by: shein@php.net
Reported by: shein@php.net
Summary: addslashes says that magic_quotes_gpc is on but it's
not the case
Status: Wont fix
Type: Documentation Problem
Package: Documentation problem
PHP Version: Irrelevant
Block user comment: N
Private report: N
New Comment:
Oops, sorry.
Previous Comments:
------------------------------------------------------------------------
[2011-03-24 08:36:23] aharvey@php.net
Depressingly, it's still on by default. (Check main/main.c in trunk if
you don't believe me.)
------------------------------------------------------------------------
[2011-03-24 08:24:22] shein@php.net
Description:
------------
---
From manual page: http://www.php.net/function.addslashes#Description
---
Fix the following paragraph because magic_quotes_gpc is off now by
default:
The PHP directive magic_quotes_gpc is on by default, and it essentially
runs
addslashes() on all GET, POST, and COOKIE data. Do not use addslashes()
on
strings that have already been escaped with magic_quotes_gpc as you'll
then do
double escaping. The function get_magic_quotes_gpc() may come in handy
for
checking this.
------------------------------------------------------------------------
--
Edit this bug report at http://bugs.php.net/bug.php?id=54365&edit=1