note 28271 added to function.get-magic-quotes-gpc
| From: | gordon at kanazawa dot ac dot jp | Date: | Wed, 08 Jan 2003 02:59:47 +0000 |
| Subject: | note 28271 added to function.get-magic-quotes-gpc | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-41808@lists.php.net to get a copy of this message | ||
In deciding whether or not to stripslash the input to your script, you must consider the settings of
magic_quotes_sybase and magic_quotes_runtime because both of these completely override the setting
of magic_quotes_gpc (see http://www.php.net/manual/en/ref.sybase.php).
The following function (an enhanced version of code posted by "gnarf at gnarf dot net" on
the "set_magic_quotes_runtime()" page) accounts for these settings when removing magic
quotes from the main HTTP_*_VARS arrays.
remove_magic_quotes($HTTP_GET_VARS);
remove_magic_quotes($HTTP_POST_VARS);
remove_magic_quotes($HTTP_COOKIES_VARS);
remove_magic_quotes($HTTP_SESSION_VARS);
set_magic_quotes_runtime(0);
function remove_magic_quotes(&$x) {
if (is_array($x)) {
while (list($key,$value) = each($x)) {
if ($value) remove_magic_quotes($x[$key]);
}
} else if (ini_get('magic_quotes_sybase')) {
$x = preg_replace("/''/", "'", $x);
} else if (get_magic_quotes_runtime()) {
$x = preg_replace("/\\\"/", '"', $x);
} else if (get_magic_quotes_gpc()) {
$x = stripslashes($x);
}
}
The "ini_get" function does not appear to be available to PHP3 so to prevent errors you
could change the if-condition to:
if (function_exists('ini_get') && ini_get( ... )) {
However, then you wouldn't know if 'magic_quotes_sybase' was set or not. Suggestions
anyone?
--
http://www.php.net/manual/en/function.get-magic-quotes-gpc.php
http://master.php.net/manage/user-notes.php?action=edit+28271
http://master.php.net/manage/user-notes.php?action=delete+28271
http://master.php.net/manage/user-notes.php?action=reject+28271