RE: [PHP] Quotation Marks in <textarea>...</textarea>

From: Date: Wed, 10 Oct 2001 00:19:16 +0000
Subject: RE: [PHP] Quotation Marks in <textarea>...</textarea>
References: 1  Groups: php.general 
Request: Send a blank email to php-general+get-70555@lists.php.net to get a copy of this message
Hello friends, Here are some important points to understand about magic quotes a. Most likely your magic_quotes_gpc setting is ON which is automagically adding the quotes. See php.ini http://www.php.net/manual/en/configuration.php#ini.magic-quotes-gpc b. magic_quotes_gpc can NOT ever be set at runtime within a script. magic_quotes_runtime() does not affect this setting at all. Using .htaccess to alter the magic_quotes_gpc setting is possible. ini_set() is NOT an option here. c. You want to get aquanted with stripslashes() and addslashes() functions http://www.php.net/addslashes http://www.php.net/stripslashes Why do we worry about slashes?! Quite simply, it's because they allow strings such as O'Reilly to make it in our database. A little information on this can be seen here: http://www.zend.com/zend/tut/using-strings.php#slashes These slashes are not stored in the database. But if you addslashes() to magically quoted data, you will get \' in the database. Please don't do that :). http://www.php.net/get_magic_quotes_gpc Also, don't forget to check your users data!!! http://www.php.net/manual/en/security.variables.php Regards, Philip Olson On Tue, 9 Oct 2001, Jack Dempsey wrote: > Hi KC, > > you've come across a useful feature of php: magic quotes. Variables are > often posted to scripts, processed, then stored in a database...magic quotes > means that php automatically backslashes these quotes for you so that you > don't have to manually addslashes to all your data. This is usually desired, > but sometimes you won't want it.... > > If you need the data for a database or some other system that needs quotes > in text backslashed, i'd leave the magic quotes setting alone and just > stripslashes before you echo... > If you're not working with databases you can either edit the magic_quotes > variablein your php.ini file, your you can set it at runtime in your php > script: > http://www.php.net/manual/en/function.set-magic-quotes-runtime.php > > -jack > > -----Original Message----- > From: KC [mailto:k_c@pacbell.net] > Sent: Tuesday, October 09, 2001 6:04 PM > To: php-general@lists.php.net > Subject: [PHP] Quotation Marks in <textarea>...</textarea> > > > Hi... I am having some difficulty with my quotation marks in a textarea HTML > tag and processed by a PHP form handling script. It seems that if you enter > a string in these tags that is surrounded by quotation marks, then you get a > backslash and quotation marks surrounding your string in the output. > > For example, if I am a user writing a message in a comments section of a > form: > > My dog's name is "Harry". We call him that because he is VERY hairy. > > And the form stores the above into a variable called $Comments, and I decide > to print out the result of this string: > > print ("$Comments\n"); > > On the browser screen, I get: > > My dog's name is \"Harry\". We call him that because he is VERY hairy. > > As far as I know, PHP is supposed to display quotations in textareas without > incident and without the backslashes. Please let me know what I am doing > wrong. > > Thanks, > KC > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net > > > > -- > PHP General Mailing List (http://www.php.net/) > To unsubscribe, e-mail: php-general-unsubscribe@lists.php.net > For additional commands, e-mail: php-general-help@lists.php.net > To contact the list administrators, e-mail: php-list-admin@lists.php.net >

« previous php.general (#70555) next »