special character HELL! (& - ' - html - php)
| From: | Dana dot Reed at clinicaldatacare dot com | Date: | Wed, 08 Nov 2000 18:21:07 +0000 |
| Subject: | special character HELL! (& - ' - html - php) | ||
| Groups: | php.general | ||
| Request: | Send a blank email to php-general+get-24357@lists.php.net to get a copy of this message | ||
When data is *written to the DB* I'm wondering how best to:
1. escape all single quotes (Oracle's escape character) with a single quote
2. somehow? escape all ampersands (Oracle waits for user input after an '&')
When data goes *to/from server* from a form I'd like to:
3. somehow? escape all double quotes
4. escape html
5. escape php tags
#1 is essential. I could of course use ereg to replace all single quotes with 2 single quotes on
every insert/update, but what about magic_quotes_sybase? It sounds like magic_quotes_sybase might
do the trick, but magic_quotes_gpc or _runtime must be set to 1 also right?
#2 has now magically fixed itself for the time being??
#3-5 htmlspecialcharacters placed *everywhere* should work, but there must be a better way. And
somehow with double quotes it's not working that well...everything looks OK in the hidden
field, but then on resubmission it loses it altogether.
The general flow of all forms is:
main.php
(default) --> include(form.php) - form page
if submit --> include(process.php) - confirm page
if continue --> include(update.php) - update db
Production machine is PHP4 / Oracle8i / RH. Development is PHP3 / Oracle8i / RH.
Thanks for any help.
Med vänliga hälsningar
/Dana