RE: [PHP] sending text input with quotes, etc...
| From: | MR | Date: | Sun, 05 Nov 2000 00:08:45 +0000 |
| Subject: | RE: [PHP] sending text input with quotes, etc... | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-23745@lists.php.net to get a copy of this message | ||
"Oguz" ...
> This is more related to HTML but forgive me:
>
> I am writing a web based email program for the boss. Since he will be able
> to send message in html format, and since he doesn't know it well, I want
> him to be able to see his message before sending it. So I need a hidden
> input that will carry a users message to the real script through
> confirmation page. Like
> <input type=hidden name=message value=......................>
>
> What should be instead of those dots? The message may have single quotes,
> double quotes and newlines. if the message user wants to send is
I have a similar problem by now - inserting data within a SQL DB, and you have to put that data to
be input without any ' because i
crashes...
The idea i had is to make a function that reads all the $HTTP_POST_VARS array, and applies a
STR_REPLACE() (or several!) function to
each posted var. That way, seeming simple to me, yo may got rid of all the backslashes, quotes,
tildes, special foreign characters,
blah, blah, blah.
If you're using HTML (i'm using SQL for oracle), you should make a list with all the
"f***king characters" and what would they be
replaced with.
I think you got the idea. Just use the STR_REPLACE function properly.