Re: Using stripslashes() adddslashes() and htmlspecialchars()

From: Date: Sun, 29 Oct 2000 12:10:58 +0000
Subject: Re: Using stripslashes() adddslashes() and htmlspecialchars()
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-22547@lists.php.net to get a copy of this message
On Sun, 29 Oct 2000, Robby Whiteside wrote: > Hi There, > > I am making a guestbook and I need help using > stripslashes() adddslashes() and htmlspecialchars(). Can i use them all > togother like this: > > <? > > $comments=stripslashes($comments); > $comments.=addslashes($comments); > $comments.=htmlspecialchars($comments); > > echo "$comments"; > > ?> Well, you could, but you probably wouldn't want to, except to see exactly what they each do. What you would end up with is a string which has the comments three times - once with slashes stripped, then once with them added, and then once with html-specific characters converted. I'm not sure exactly what you want, but I'm going to presume you've got a form that the user submits with some comments in it, and you want to store them and later display them. [The following only applies if magic_quotes_gpc is on] When you receive the data, various characters like ' will be escaped with a backslash in front of them, to make them safer to use in certain functions, and SQL queries. However, if you print it out, you'll get funny looking text like: I\'m really happy with your site. It\'s great. But if you do: $comment = stripslashes($comments); echo $comments; You'll get: I'm really happy with your site. It's great. [If it's off, PHP won't automatically put slashes in there, so you won't need to strip them] Which is better. However, if the user decides to be funny and puts in the comments field something like: I'm really happy with your site. <img src="http://www.rotten.com/offensivepic.jpeg"> You'll spit out the image tag. And of course, that could put in nasty <script>'s that do Bad Things. So, you use htmlspecialchars() or htmlentities() to convert characters like < and > into their HTML representation - &gt; and &lt; respectively. So what you probably want to do is: $comments = htmlspecialchars(stripslashes($comments)); Then save it somewhere, and then in the 'view guestbook' page you can simply print it out as is. Hope this clarifies things. -- Michael

« previous php.general (#22547) next »