Re: anti htmlspecialchars
| From: | Chris Adams | Date: | Wed, 12 Jul 2000 19:31:43 +0000 |
| Subject: | Re: anti htmlspecialchars | ||
| References: | 1 2 | Groups: | php.general |
| Request: | Send a blank email to php-general+get-6234@lists.php.net to get a copy of this message | ||
>We have the same problem, and as we divided the frontend / logical
>/databaseconnection
>in several layers, we made some converting functions in the db-object,
where we
>do things like converting don`t to don#t.
>We ´ve searched several oracle sources to avoid such a convert function,
but
>for now we didn´t find it.
The real answer would be for PHP database driver developers to add support
for binding variables. This would also be handy when working with BLOBs and
would solve the nationalization issues since browsers can handle the raw
data for any encoding.
As a workaround, you can use the example from the PHP manual for
get_html_translation_table to do the equivalent of an unhtmlspecialchars():
header("Content-Type: text/plain");
$trans = get_html_translation_table (HTML_ENTITIES);
$str = "Hallo & <Frau> & Krämer";
$encoded = strtr ($str, $trans);
$trans = array_flip ($trans);
$original = strtr ($str, $trans);
echo "str: $str\n";
echo "encoded: $encoded\n";
echo "reversed: $original\n";