note 25994 rejected from function.set-magic-quotes-runtime by nicos
| From: | nicos@php.net | Date: | Tue, 15 Oct 2002 00:05:18 +0000 |
| Subject: | note 25994 rejected from function.set-magic-quotes-runtime by nicos | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-38074@lists.php.net to get a copy of this message | ||
I have to agree with the above note that magic_quotes_gpc is a really bad "feature". My
main problem with it is that when a form is submitted, you have to remove the slashes in order to
validate the data, or to display the data back to the user. Well, that's at least just as much
trouble as adding the slashes in before doing an SQL call. So what is the benefit of the
magic_quotes_gpc "feature"? And while you may often be putting form fields into a
database, many times you are just sending the field data in an email, in which case you don't
want the slashes, and you rarely are putting the query_string or cookie values into a database. All
in all this really is an ill-conceived idea that should never have been made the default behavior.
The trouble is that most Web hosting companies have magic_quotes_gpc turned on for their shared
accounts AND they don't allow you to use "php_value" in .htaccess. So we REALLY need
a way to turn this "feature" off within our scripts.