Re: Using stripslashes() adddslashes() and htmlspecialchars()
| From: | Michael | Date: | Sun, 29 Oct 2000 12:10:58 +0000 |
| Subject: | Re: Using stripslashes() adddslashes() and htmlspecialchars() | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-22547@lists.php.net to get a copy of this message | ||
On Sun, 29 Oct 2000, Robby Whiteside wrote:
> Hi There,
>
> I am making a guestbook and I need help using
> stripslashes() adddslashes() and htmlspecialchars(). Can i use them all
> togother like this:
>
> <?
>
> $comments=stripslashes($comments);
> $comments.=addslashes($comments);
> $comments.=htmlspecialchars($comments);
>
> echo "$comments";
>
> ?>
Well, you could, but you probably wouldn't want to, except to see exactly
what they each do. What you would end up with is a string which has the
comments three times - once with slashes stripped, then once with them
added, and then once with html-specific characters converted.
I'm not sure exactly what you want, but I'm going to presume you've got a
form that the user submits with some comments in it, and you want to store
them and later display them.
[The following only applies if magic_quotes_gpc is on]
When you receive the data, various characters like ' will be escaped with a
backslash in front of them, to make them safer to use in certain functions,
and SQL queries. However, if you print it out, you'll get funny looking
text like:
I\'m really happy with your site. It\'s great.
But if you do:
$comment = stripslashes($comments);
echo $comments;
You'll get:
I'm really happy with your site. It's great.
[If it's off, PHP won't automatically put slashes in there, so you won't
need to strip them]
Which is better. However, if the user decides to be funny and puts in the
comments field something like:
I'm really happy with your site.
<img src="http://www.rotten.com/offensivepic.jpeg">
You'll spit out the image tag. And of course, that could put in nasty
<script>'s that do Bad Things. So, you use htmlspecialchars() or
htmlentities() to convert characters like < and > into their HTML
representation - > and < respectively.
So what you probably want to do is:
$comments = htmlspecialchars(stripslashes($comments));
Then save it somewhere, and then in the 'view guestbook' page you can simply
print it out as is.
Hope this clarifies things.
--
Michael