note 26852 added to function.htmlentities
| From: | dakota at tensen dot net | Date: | Thu, 14 Nov 2002 22:30:53 +0000 |
| Subject: | note 26852 added to function.htmlentities | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-39505@lists.php.net to get a copy of this message | ||
In doing some form post, MySQL, PHP applications, it became apparent that special chars are
stubborn. For instance, before I can put a string submitted with a form into mysql, for safety I
need to do this:
mysql_escape_string(htmlspecialchars(stripslashes($field)))
Its not hard to do and I've noticed that I use it a lot. It might be interesting to see in
future versions of PHP a function that does this, but for now heres an easy solution which anyone
with a similar problem can use:
function formspecialchars($var)
{
$out = mysql_escape_string(htmlspecialchars(stripslashes($var)));
return $out;
}
--
http://www.php.net/manual/en/function.htmlentities.php
http://master.php.net/manage/user-notes.php?action=edit+26852
http://master.php.net/manage/user-notes.php?action=delete+26852
http://master.php.net/manage/user-notes.php?action=reject+26852