note 68321 added to function.htmlentities
| From: | info at pirandot dot de | Date: | Sat, 22 Jul 2006 13:00:06 +0000 |
| Subject: | note 68321 added to function.htmlentities | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-115046@lists.php.net to get a copy of this message | ||
The data returned by a text input field is ready to be used in a data base query when enclosed in
single quotes, e.g.
<?php
mysql_query ("SELECT * FROM Article WHERE id = '$data'");
?>
But you will get problems when writing back this data into the input field's value,
<?php
echo "<input type='text' value='$data'>";
?>
because hmtl codes would be interpreted and escape sequences would cause strange output.
The following function may help:
<?php
function deescape ($s, $charset='UTF-8')
{
// don't interpret html codes and don't convert quotes
$s = htmlentities ($s, ENT_NOQUOTES, $charset);
// delete the inserted backslashes except those for protecting single quotes
$s = preg_replace ("/\\\\\\\\([^'])/e", '"&#" .
ord("$1") . ";"', $s);
// delete the backslashes inserted for protecting single quotes
$s = str_replace ("\\\\'", "&#" . ord ("'") .
";", $s);
return $s;
}
?>
Try some input like: a'b"c\\d\\'e\\"f\\\\g&x#27;h to test ...
----
Server IP: 217.160.72.57
Probable Submitter: 80.145.120.5
----
X-Spam-Status: No, hits=3.1 required=5.0 tests=DATE_MISSING,FROM_NO_LOWER
autolearn=no version=2.64
----
Manual Page -- http://www.php.net/manual/en/function.htmlentities.php
Edit -- http://master.php.net/note/edit/68321
Del: integrated -- http://master.php.net/note/delete/68321/integrated
Del: useless -- http://master.php.net/note/delete/68321/useless
Del: bad code -- http://master.php.net/note/delete/68321/bad+code
Del: spam -- http://master.php.net/note/delete/68321/spam
Del: non-english -- http://master.php.net/note/delete/68321/non-english
Del: in docs -- http://master.php.net/note/delete/68321/in+docs
Del: other reasons-- http://master.php.net/note/delete/68321
Reject -- http://master.php.net/note/reject/68321
Search -- http://master.php.net/manage/user-notes.php