RE: [PHP] Strings in text fields are bad
| From: | Lawrence dot Sheed at dfait-maeci dot gc dot ca | Date: | Tue, 26 Sep 2000 04:18:04 +0000 |
| Subject: | RE: [PHP] Strings in text fields are bad | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-17515@lists.php.net to get a copy of this message | ||
I was paranoid too ;)
See my example mail earlier.
$caddress=stripslashes ( htmlspecialchars("12345 Abc Ave."));
Maxim, its the same issue for ' and " effects wise if you're switching
between
value = ' xxx ' or value = " xxx " styles.
Eg
<value= "user trying to "screw up the input"">
Would come out as
"screw up the input"">
(or something similar - this is off the top of my head).
cheers,
Lawrence
-----Original Message-----
From: Simon Edwards [mailto:simon@animated.net.au]
Sent: September 26, 2000 12:13 PM
To: Maxim Maletsky
Cc: php-general@lists.php.net
Subject: Re: [PHP] Strings in text fields are bad
Maxim Maletsky wrote:
> Stop, Stop, Stop Guys ...
> Why not to teach this guy doing it simplier:
>
> $caddress = '12345 Abc Ave.';
> echo '<input type=text name=caddress value="' . $caddress .
> '">';
Also now would be a good time to explain why wrapping htmlspecialchars()
around the variables in the echo statement are a good idea if you want
to avoid a nasty surprise in the future. (what happens to the HTML when
$caddress contains a string with a ' in it?)
Is it just me who is paranoid about these encoding issues?
--
Simon Edwards
Animated Design, Melbourne
http://www.animated.net.au/ Ph: (03) 98850990
--
PHP General Mailing List (http://www.php.net/)
To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
For additional commands, e-mail: php-general-help@lists.php.net
To contact the list administrators, e-mail: php-list-admin@lists.php.net