Re: addslashes Question
| From: | Hardy Merrill | Date: | Wed, 21 Mar 2001 22:16:33 +0000 |
| Subject: | Re: addslashes Question | ||
| References: | 1 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-45012@lists.php.net to get a copy of this message | ||
Jeff, here's what I do:
1. set magic_quotes_gpc On in php.ini
* this will automatically quote all GET, POST, and COOKIE
variables - read up on magic_quotes_gpc.
2. at the top of each script, stripslashes all the COOKIE, GET,
and POST variables, since they will have been automatically
quoted by magic_quotes_gpc.
3. At the top of the the routine that INSERT's or UPDATE's fields
in the database, for all string variables invoke addslashes -
this will properly quote all characters(I think there's only 4
- single quote, double quote, NULL character, and I can't
remember what the 4th one is - look at the manual under
"addslashes"). Then you can INSERT or UPDATE the columns with
those addslash'ed values.
There's many different ways to do this, but this is what works best
for me.
--
Hardy Merrill
Mission Critical Linux, Inc.
http://www.missioncriticallinux.com
Jeff Oien [jeff@webdesigns1.com] wrote:
> I have a form to modify a record in a MySQL database.
> The record contains this:
> 3" Brush
> The code in question is like this:
> while ($row = mysql_fetch_array($result)) {
> $desc1 = $row['desc1'];
> ------
> <input type="text" name="desc1" value="<?php echo
"$desc1"; ?>">
>
> I've tried using addslashes to the variable in various ways and it
> always returns:
> 3\
> What am I doing wrong? Sorry this is probably the 1000th time
> this has been asked.
> Jeff Oien
>
> --
> PHP General Mailing List (http://www.php.net/)
> To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net
> For additional commands, e-mail: php-general-help@lists.php.net
> To contact the list administrators, e-mail: php-list-admin@lists.php.net
--
Hardy Merrill
Mission Critical Linux, Inc.
http://www.missioncriticallinux.com