note 68321 deleted from function.htmlentities by nlopess
| From: | nlopess@php.net | Date: | Sat, 30 Dec 2006 18:49:59 +0000 |
| Subject: | note 68321 deleted from function.htmlentities by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-121115@lists.php.net to get a copy of this message | ||
Note Submitter: info at pirandot dot de
----
The data returned by a text input field is ready to be used in a data base query when enclosed in
single quotes, e.g.
<?php
mysql_query ("SELECT * FROM Article WHERE id = '$data'");
?>
But you will get problems when writing back this data into the input field's value,
<?php
echo "<input type='text' value='$data'>";
?>
because hmtl codes would be interpreted and escape sequences would cause strange output.
The following function may help:
<?php
function deescape ($s, $charset='UTF-8')
{
// don't interpret html codes and don't convert quotes
$s = htmlentities ($s, ENT_NOQUOTES, $charset);
// delete the inserted backslashes except those for protecting single quotes
$s = preg_replace ("/\\\\\\\\([^'])/e", '"&#" .
ord("$1") . ";"', $s);
// delete the backslashes inserted for protecting single quotes
$s = str_replace ("\\\\'", "&#" . ord ("'") .
";", $s);
return $s;
}
?>
Try some input like: a'b"c\\d\\'e\\"f\\\\g&x#27;h to test ...