note 18267 modified in function.eval by jsheets

From: Date: Sun, 09 Feb 2003 17:09:47 +0000
Subject: note 18267 modified in function.eval by jsheets
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-43695@lists.php.net to get a copy of this message
Take note of something very simple about this function which I have had several people write to me and thank me for keeping things so straightforward. The reason you get parse errors when using EVAL on HTML or includes, is because the EVAL() function reads the target as if it were a standard block string. // For example, you would never do this: $string=""Hi," said the giant monkey."; // But you would do this, by escaping the quotes: $string="\"Hi,\" said the giant monkey."; // When you include HTML for parsing, of course you are going to have ""s all over the place <table width=200 align="center" bgcolor="#131313"> // etc... so when EVAL() opens this as a string, it will fail at the first instance of quotation marks. Here is the fix: // open file, be it from a database or a physical include $file=fopen("myinclude.inc","r"); $openedfile=fread($file,filesize($file)); // add slashes to prevent premature string escaping $string=addslashes($openedfile); // evaluate the code (note the value is returned in the function eval("\$string=\"$string\";"); // remove the slashes you used to protect your string during parsing $string=stripslashes($string); --was-- For some reason, all but one of the comments on this function were deleted about a month ago, which is unfortunate because the sole one they retained suggested a fix to the problem, but did not explain WHY the problem occurs. There is little sense allowing comments for fixes when said comments don't say WHY the problem is happening - this impedes the actual process of learning and subsequently causes further headaches down the road. For the second time, take note of something very simple about this function which I have had several people write to me and thank me for keeping things so straightforward, which is why I am relatively bitter that it was deleted, with everybody else's, to begin with: The reason you get parse errors when using EVAL on HTML or includes, is because the EVAL() function reads the target as if it were a standard block string. // For example, you would never do this: $string=""Hi," said the giant monkey."; // But you would do this, by escaping the quotes: $string="\"Hi,\" said the giant monkey."; // When you include HTML for parsing, of course you are going to have ""s all over the place <table width=200 align="center" bgcolor="#131313"> // etc... so when EVAL() opens this as a string, it will fail at the first instance of quotation marks. Here is the fix: // open file, be it from a database or a physical include $file=fopen("myinclude.inc","r"); $openedfile=fread($file,filesize($file)); // add slashes to prevent premature string escaping $string=addslashes($openedfile); // evaluate the code (note the value is returned in the function eval("\$string=\"$string\";"); // remove the slashes you used to protect your string during parsing $string=stripslashes($string); // note to PHP/Zend - where are the rejection emails we are supposed to receive if our comments don't meet your criteria? http://www.php.net/manual/en/function.eval.php

« previous php.notes (#43695) next »