note 26782 added to function.addslashes

From: Date: Tue, 12 Nov 2002 21:16:25 +0000
Subject: note 26782 added to function.addslashes
Groups: php.notes 
Request: Send a blank email to php-notes+get-39409@lists.php.net to get a copy of this message
Beware of using addslashes() on input to the serialize() function. serialize() stores strings with their length; the length must match the stored string or unserialize() will fail. Such a mismatch can occur if you serialize the result of addslashes() and store it in a database; some databases (definitely including PostgreSQL) automagically strip backslashes from "special" chars in SELECT results, causing the returned string to be shorter than it was when it was serialized. In other words, do this... $string="O'Reilly"; $ser=serialize($string); # safe -- won't count the slash $result=addslashes($ser); ...and not this... $string="O'Reilly"; $add=addslashes($string); # RISKY! -- will count the slash $result=serialize($add); In both cases, a backslash will be added after the apostrophe in "O'Reilly"; only in the second case will the backslash be included in the string length as recorded by serialize(). [Note to the maintainers: You may, at your option, want to link this note to serialize() as well as to addslashes(). I'll refrain from doing such cross-posting myself...] -- http://www.php.net/manual/en/function.addslashes.php http://master.php.net/manage/user-notes.php?action=edit+26782 http://master.php.net/manage/user-notes.php?action=delete+26782 http://master.php.net/manage/user-notes.php?action=reject+26782

« previous php.notes (#39409) next »