RE: [PHP] Strings in text fields are bad

From: Date: Tue, 26 Sep 2000 04:18:04 +0000
Subject: RE: [PHP] Strings in text fields are bad
Groups: php.general 
Request: Send a blank email to php-general+get-17515@lists.php.net to get a copy of this message
I was paranoid too ;) See my example mail earlier. $caddress=stripslashes ( htmlspecialchars("12345 Abc Ave.")); Maxim, its the same issue for ' and " effects wise if you're switching between value = ' xxx ' or value = " xxx " styles. Eg <value= "user trying to "screw up the input""> Would come out as "screw up the input""> (or something similar - this is off the top of my head). cheers, Lawrence -----Original Message----- From: Simon Edwards [mailto:simon@animated.net.au] Sent: September 26, 2000 12:13 PM To: Maxim Maletsky Cc: php-general@lists.php.net Subject: Re: [PHP] Strings in text fields are bad Maxim Maletsky wrote: > Stop, Stop, Stop Guys ... > Why not to teach this guy doing it simplier: > > $caddress = '12345 Abc Ave.'; > echo '<input type=text name=caddress value="' . $caddress . > '">'; Also now would be a good time to explain why wrapping htmlspecialchars() around the variables in the echo statement are a good idea if you want to avoid a nasty surprise in the future. (what happens to the HTML when $caddress contains a string with a ' in it?) Is it just me who is paranoid about these encoding issues? -- Simon Edwards Animated Design, Melbourne http://www.animated.net.au/ Ph: (03) 98850990 -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#17515) next »