note 30029 added to function.htmlspecialchars
| From: | dystopia589 at yahoo dot com | Date: | Tue, 04 Mar 2003 17:13:09 +0000 |
| Subject: | note 30029 added to function.htmlspecialchars | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-44834@lists.php.net to get a copy of this message | ||
It's strange how close this function resembles joseph at nextique dot com's.. I wrote it
before checking this site. It works really well for securing the values from $_GET and $_POST data.
I had to add the is_array check because sometimes array data is submitted by form.
function SpecialChars($Security)
{
if (is_array($Security))
{
while(list($key, $val) = each($Security))
{
if (is_array($val))
{
$Security[$key] = SpecialChars($val);
}
else
{
$Security[$key] = htmlspecialchars(stripslashes($val), ENT_QUOTES);
}
}
}
else
{
$Security = htmlspecialchars(stripslashes($Security), ENT_QUOTES);
}
return $Security;
}
Using this function, it's good to put these lines in a common include file for all your scripts
handling form data:
while(list($key, $val) = each($_GET))
{
${$key} = SpecialChars($val);
}
while(list($key, $val) = each($_POST))
{
${$key} = SpecialChars($val);
}
This way, all values from $_GET and $_POST are converted properly, without having to specifically
handle each one before displaying.. it makes your code so much easier to read, and ensures that you
don't forget one or two..
--
http://www.php.net/manual/en/function.htmlspecialchars.php
http://master.php.net/manage/user-notes.php?action=edit+30029
http://master.php.net/manage/user-notes.php?action=delete+30029
http://master.php.net/manage/user-notes.php?action=reject+30029