note 50339 deleted from function.get-magic-quotes-gpc by philip
| From: | philip@php.net | Date: | Tue, 27 Jun 2006 06:39:45 +0000 |
| Subject: | note 50339 deleted from function.get-magic-quotes-gpc by philip | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-114351@lists.php.net to get a copy of this message | ||
Note Submitter: Caya
----
If get_magic_quotes_gpc() is 1 (on) then the Get, Post and Cookie data is dirty (you have something
in memory the user didn't type). You need to clean it up by calling stripslashes.
I use this code snippet:
function cleanArray(&$arr) {
foreach($arr as $k => $v)
if (is_array($v))
cleanArray($arr[$k]);
else
$arr[$k] = stripslashes($v);
}
/// before processing anything in PHP do
if (get_magic_quotes()) {
cleanArray($_POST);
cleanArray($_COOKIE);
cleanArray($_GET);
}
// here if the user typed O'Connell, you have [O]['][C][o][n][n][e][l][l]
// in your variable in memory (say $name=$_POST['name']).
// (I use [ ] to represent individual characters here. Don't be confused)
// All pattern matching etc, you do with that variable works as
// expected (strlen is 9 not 10, for example!).
// Of course, sending this back to the user by HTML involves using
// htmlentities($var), to store in DB use addslashes($var), to send as
// plain email use it content as it is, etc.
The above code implies that you need to be aware of what a variable is supposed to have to handle it
properly (Isn't this obvious? So, why a global behaviour like magic_quotes in the first place?
well... that's life...).
If you can change you webshoting setting I recommend magic_quotes=no.