RE: [PHP] OT? passing text variables through html forms.
| From: | John Steele | Date: | Thu, 29 Jun 2000 06:47:59 +0000 |
| Subject: | RE: [PHP] OT? passing text variables through html forms. | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-3808@lists.php.net to get a copy of this message | ||
People, instead of taking blind stabs at this, why not read the manual?
stripslashes(), addslashes() and magic_quotes_gpc pretty much cover this.
You might also take a look at htmlentities(), htmlspecialchars() and nl2br().
At 6/29/2000 01:41 PM, Stewart Taylor wrote:
>You might try
>$var = str_replace("'", "\'", $var); // escape all ' in $var
>before you display the variable using html
>then
>$var = str_replace("\'", "'", $var); // unescape all ' in
>$var
>before you save it to the database.
>
>
>-----Original Message-----
>From: Travis Ruthenburg [mailto:listboi@wacko.trickster.net]
>Sent: 29 June 2000 13:26
>To: David Newcomb
>Cc: PHP-General Mailing List
>Subject: Re: [PHP] OT? passing text variables through html forms.
>
>
>David,
>
>Thanks a lot for your response, I really appreciate it. While this is a
>solution to my exact problem, it's not a solution to the whole problem.
>This fixes single quotes, but breaks double quotes.
>
>Is there any solution short of replacing single quotes with their html
>entity equivalent?
>
>
>Regards,
>
>Travis
>
>
>On Thu, 29 Jun 2000, David Newcomb wrote:
>
>>
>> Try:
>> <?php
>> $var = "This is 'a' test";
>> echo "<input type=\"hidden\" name=\"name\"
>> value=\"$var\">\n";
>> ?>
>>
>> ----- Original Message -----
>> From: Travis Ruthenburg <listboi@wacko.trickster.net>
>> To: PHP-General Mailing List <php-general@lists.php.net>
>> Sent: Thursday, June 29, 2000 12:50 PM
>> Subject: [PHP] OT? passing text variables through html forms.
>>
>>
>> > Hey there Web Gurus,
>> >
>> > I'm having a little trouble with inserting getting my text into a
>postgres
>> > database. I'm working on a message-board program in which users must
>> > preview their messages. I'm passing the information through the preview
>> > page using hidden inputs.
>> >
>> > My problem is that single quotes (apostrophe's) aren't being excaped
>> > properly in the html. I wrote my html with single quotes, example:
>> >
>> >
>> > <?
>> > $var = "This is 'a' test";
>> > <input type='hidden' name='name' value='$var'>
>> > ?>
>> >
>> > This comes out in the html is something like:
>> >
>> > <input type='hidden' name='name' value='This is
>> > 'a' test'>
>> > 1^ 2^
>> >
>> > The problem is that, as far as the html is concerned, the value ends at
>> > the second quote.
>> >
>> > I know many people do similiar things, so I'm sure I'm simply missing
>some
>> > fairly obvious solution. Any help would be much appreciated.
>> >
>> > Thanks,
>> >
>> > Travis Ruthenburg
--
/* SteeleSoft Consulting John Steele - Systems Analyst/Programmer
* We also walk dogs... jsteele@writeme.com
* http://www.gamecomputer.com/ssc/
*/