RE: [PHP] Strings in text fields are bad

From: Date: Tue, 26 Sep 2000 06:00:41 +0000
Subject: RE: [PHP] Strings in text fields are bad
Groups: php.general 
Request: Send a blank email to php-general+get-17531@lists.php.net to get a copy of this message
We should clarify ;) If you use ' as a separator then having a ' in your output will break the html If you use " as a separator then having a " in your output will break the html Eg: $stuff = 'nasty"person'; echo '<name=stuff value='" . $stuff '">'; is ok but $stuff = "nasty'person"; echo '<name=stuff value='" . $stuff '">'; is not Won't break the php, just the html output. Thats why you always validate + htmlspecialchars it. BTW htmlspecialchars has an additional option to trap 's, but it only works on the "new" version of php4. Have a look at htmlspecialchars in the manual on php.net for details. cheers, Lawrence. -----Original Message----- From: Simon Edwards [mailto:simon@animated.net.au] Sent: September 26, 2000 12:52 PM To: Lawrence.Sheed@dfait-maeci.gc.ca Cc: php-general@lists.php.net Subject: Re: [PHP] Strings in text fields are bad Lawrence.Sheed@dfait-maeci.gc.ca wrote: > I was paranoid too ;) perhaps not paranoid enough. > See my example mail earlier. > $caddress=stripslashes ( htmlspecialchars("12345 Abc Ave.")); $caddress = htmlspecialchars(stripslashes("12345 Abc Ave.")); :-) -- Simon Edwards Animated Design, Melbourne http://www.animated.net.au/ Ph: (03) 98850990 -- PHP General Mailing List (http://www.php.net/) To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net For additional commands, e-mail: php-general-help@lists.php.net To contact the list administrators, e-mail: php-list-admin@lists.php.net

« previous php.general (#17531) next »