note 26852 added to function.htmlentities

From: Date: Thu, 14 Nov 2002 22:30:53 +0000
Subject: note 26852 added to function.htmlentities
Groups: php.notes 
Request: Send a blank email to php-notes+get-39505@lists.php.net to get a copy of this message
In doing some form post, MySQL, PHP applications, it became apparent that special chars are stubborn. For instance, before I can put a string submitted with a form into mysql, for safety I need to do this: mysql_escape_string(htmlspecialchars(stripslashes($field))) Its not hard to do and I've noticed that I use it a lot. It might be interesting to see in future versions of PHP a function that does this, but for now heres an easy solution which anyone with a similar problem can use: function formspecialchars($var) { $out = mysql_escape_string(htmlspecialchars(stripslashes($var))); return $out; } -- http://www.php.net/manual/en/function.htmlentities.php http://master.php.net/manage/user-notes.php?action=edit+26852 http://master.php.net/manage/user-notes.php?action=delete+26852 http://master.php.net/manage/user-notes.php?action=reject+26852

« previous php.notes (#39505) next »