note 30029 added to function.htmlspecialchars

From: Date: Tue, 04 Mar 2003 17:13:09 +0000
Subject: note 30029 added to function.htmlspecialchars
Groups: php.notes 
Request: Send a blank email to php-notes+get-44834@lists.php.net to get a copy of this message
It's strange how close this function resembles joseph at nextique dot com's.. I wrote it before checking this site. It works really well for securing the values from $_GET and $_POST data. I had to add the is_array check because sometimes array data is submitted by form. function SpecialChars($Security) { if (is_array($Security)) { while(list($key, $val) = each($Security)) { if (is_array($val)) { $Security[$key] = SpecialChars($val); } else { $Security[$key] = htmlspecialchars(stripslashes($val), ENT_QUOTES); } } } else { $Security = htmlspecialchars(stripslashes($Security), ENT_QUOTES); } return $Security; } Using this function, it's good to put these lines in a common include file for all your scripts handling form data: while(list($key, $val) = each($_GET)) { ${$key} = SpecialChars($val); } while(list($key, $val) = each($_POST)) { ${$key} = SpecialChars($val); } This way, all values from $_GET and $_POST are converted properly, without having to specifically handle each one before displaying.. it makes your code so much easier to read, and ensures that you don't forget one or two.. -- http://www.php.net/manual/en/function.htmlspecialchars.php http://master.php.net/manage/user-notes.php?action=edit+30029 http://master.php.net/manage/user-notes.php?action=delete+30029 http://master.php.net/manage/user-notes.php?action=reject+30029

« previous php.notes (#44834) next »