note 68321 deleted from function.htmlentities by nlopess

From: Date: Sat, 30 Dec 2006 18:49:59 +0000
Subject: note 68321 deleted from function.htmlentities by nlopess
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-121115@lists.php.net to get a copy of this message
Note Submitter: info at pirandot dot de ---- The data returned by a text input field is ready to be used in a data base query when enclosed in single quotes, e.g. <?php mysql_query ("SELECT * FROM Article WHERE id = '$data'"); ?> But you will get problems when writing back this data into the input field's value, <?php echo "<input type='text' value='$data'>"; ?> because hmtl codes would be interpreted and escape sequences would cause strange output. The following function may help: <?php function deescape ($s, $charset='UTF-8') { // don't interpret html codes and don't convert quotes $s = htmlentities ($s, ENT_NOQUOTES, $charset); // delete the inserted backslashes except those for protecting single quotes $s = preg_replace ("/\\\\\\\\([^'])/e", '"&#" . ord("$1") . ";"', $s); // delete the backslashes inserted for protecting single quotes $s = str_replace ("\\\\'", "&#" . ord ("'") . ";", $s); return $s; } ?> Try some input like: a'b"c\\d\\'e\\"f\\\\g&x#27;h to test ...

« previous php.notes (#121115) next »