note 50339 deleted from function.get-magic-quotes-gpc by philip

From: Date: Tue, 27 Jun 2006 06:39:45 +0000
Subject: note 50339 deleted from function.get-magic-quotes-gpc by philip
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-114351@lists.php.net to get a copy of this message
Note Submitter: Caya ---- If get_magic_quotes_gpc() is 1 (on) then the Get, Post and Cookie data is dirty (you have something in memory the user didn't type). You need to clean it up by calling stripslashes. I use this code snippet: function cleanArray(&$arr) { foreach($arr as $k => $v) if (is_array($v)) cleanArray($arr[$k]); else $arr[$k] = stripslashes($v); } /// before processing anything in PHP do if (get_magic_quotes()) { cleanArray($_POST); cleanArray($_COOKIE); cleanArray($_GET); } // here if the user typed O'Connell, you have [O]['][C][o][n][n][e][l][l] // in your variable in memory (say $name=$_POST['name']). // (I use [ ] to represent individual characters here. Don't be confused) // All pattern matching etc, you do with that variable works as // expected (strlen is 9 not 10, for example!). // Of course, sending this back to the user by HTML involves using // htmlentities($var), to store in DB use addslashes($var), to send as // plain email use it content as it is, etc. The above code implies that you need to be aware of what a variable is supposed to have to handle it properly (Isn't this obvious? So, why a global behaviour like magic_quotes in the first place? well... that's life...). If you can change you webshoting setting I recommend magic_quotes=no.

« previous php.notes (#114351) next »