escaping slashes in variables

From: Date: Fri, 28 Jul 2000 17:06:29 +0000
Subject: escaping slashes in variables
Groups: php.general 
Request: Send a blank email to php-general+get-8816@lists.php.net to get a copy of this message
ok, here's my problem users fill a form form data is passed to the scritp as variables each time a user enters quotes or double quotes in teh forms it is escaped by a \ in the variable I take a template file and put it in an array (code based on coding made by Rudy Nooyen) if(!@fopen($F_TEMPLATE, "r")) echo "<br>FICG n'a pas pu recevoir votre formulaire. SVP réessayez.<br>\n"; else $arr_t1 = @file( $F_TEMPLATE ); $nr_mail = 1; if (! $F_TEMPLATE2 == "" && @fopen($F_TEMPLATE2, "r")) $arr_t2 = @file( $F_TEMPLATE2 ); $nr_mail = 2; I then analyse each line of the template and replaces predermined types (ex : {{variable}}) from the template by their $variable equivalent, casue I want the variables values to appear in the template I then use eval() to replace the variables names by their values, appending each line to a string (which will need to be emailed later) while ($domail <= $nr_mail): if ($domail == 1) $var2use = $arr_t1; else $var2use = $arr_t2; for ($index = 0; $index < count($var2use); $index++) { $pattern = ereg("{{[A-z0-9_]*}}", $var2use[$index]); if ($pattern) { $line = ereg_replace("{{","$",$var2use[$index]); $line = ereg_replace("}}","",$line); } else { $line = $var2use[$index]; } $line .= "<BR>"; eval( "\$line = \"$line\";" ); if ($index == 0 && $domail == 1) $linetot1 = $line; elseif ($index > 0 && $domail == 1) $linetot1 .= $line; if ($index == 0 && $domail == 2) $linetot2 = $line; elseif ($index > 0 && $domail == 2) $linetot2 .= $line; } ++$domail; endwhile; Ok, here's my problem : that code I just showed returns the variables contents alright in the strings, but with the slashes in them if the variable contains quotes or doublequotes (ex : $var=" \"test\" " or $var2=" \'test\' ") obviously, i don't want the slashes displayed in the resulting string, cause that string as to be emailed, and this is unproper presentation of data. if I execute stripslashes() on the lines, before doing the eval(), eval returns a parse error ???? why?? and if I do the stripslashes() after the eval() it does nothing???? the slashes are not removed, why ??? is there something else I can use beside stripslashes to remove them? or than eval for teh values to show instead of teh variable names?

« previous php.general (#8816) next »