RE: [PHP] OT? passing text variables through html forms.

From: Date: Thu, 29 Jun 2000 06:47:59 +0000
Subject: RE: [PHP] OT? passing text variables through html forms.
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-3808@lists.php.net to get a copy of this message
People, instead of taking blind stabs at this, why not read the manual? stripslashes(), addslashes() and magic_quotes_gpc pretty much cover this. You might also take a look at htmlentities(), htmlspecialchars() and nl2br(). At 6/29/2000 01:41 PM, Stewart Taylor wrote: >You might try >$var = str_replace("'", "\'", $var); // escape all ' in $var >before you display the variable using html >then >$var = str_replace("\'", "'", $var); // unescape all ' in >$var >before you save it to the database. > > >-----Original Message----- >From: Travis Ruthenburg [mailto:listboi@wacko.trickster.net] >Sent: 29 June 2000 13:26 >To: David Newcomb >Cc: PHP-General Mailing List >Subject: Re: [PHP] OT? passing text variables through html forms. > > >David, > >Thanks a lot for your response, I really appreciate it. While this is a >solution to my exact problem, it's not a solution to the whole problem. >This fixes single quotes, but breaks double quotes. > >Is there any solution short of replacing single quotes with their html >entity equivalent? > > >Regards, > >Travis > > >On Thu, 29 Jun 2000, David Newcomb wrote: > >> >> Try: >> <?php >> $var = "This is 'a' test"; >> echo "<input type=\"hidden\" name=\"name\" >> value=\"$var\">\n"; >> ?> >> >> ----- Original Message ----- >> From: Travis Ruthenburg <listboi@wacko.trickster.net> >> To: PHP-General Mailing List <php-general@lists.php.net> >> Sent: Thursday, June 29, 2000 12:50 PM >> Subject: [PHP] OT? passing text variables through html forms. >> >> >> > Hey there Web Gurus, >> > >> > I'm having a little trouble with inserting getting my text into a >postgres >> > database. I'm working on a message-board program in which users must >> > preview their messages. I'm passing the information through the preview >> > page using hidden inputs. >> > >> > My problem is that single quotes (apostrophe's) aren't being excaped >> > properly in the html. I wrote my html with single quotes, example: >> > >> > >> > <? >> > $var = "This is 'a' test"; >> > <input type='hidden' name='name' value='$var'> >> > ?> >> > >> > This comes out in the html is something like: >> > >> > <input type='hidden' name='name' value='This is >> > 'a' test'> >> > 1^ 2^ >> > >> > The problem is that, as far as the html is concerned, the value ends at >> > the second quote. >> > >> > I know many people do similiar things, so I'm sure I'm simply missing >some >> > fairly obvious solution. Any help would be much appreciated. >> > >> > Thanks, >> > >> > Travis Ruthenburg -- /* SteeleSoft Consulting John Steele - Systems Analyst/Programmer * We also walk dogs... jsteele@writeme.com * http://www.gamecomputer.com/ssc/ */

« previous php.general (#3808) next »