note 31222 added to function.stripslashes

From: Date: Mon, 14 Apr 2003 13:28:41 +0000
Subject: note 31222 added to function.stripslashes
Groups: php.notes 
Request: Send a blank email to php-notes+get-46595@lists.php.net to get a copy of this message
Just to mention that you strip slashes, by example, in queries for databases, not for inputs in an HTML form (unless you display information coming from a variable altered by magic_quotes_gpc). Use htmlspecialchars() or htmlentities() in an input to set its value: <input type="text" value="<?php echo htmlspecialchars($value); ?>" /> As I mentioned before, you may want to stripslashes() $value if this value is coming from a variable altered by magic_quotes_gpc. htmlspecialchars() will avoid double-quotes of $value to enter in conflict with double-quotes of the input to set its value because double-quotes will, for example, be replaced by the string "&quot;". It is also important to do that in TEXTAREAs (or in any HTML form input). I already had the problem with a link I wanted to print in a TEXTAREA that contained a query like this: http://www.myserver.com/link.php?id=123&currentSection=Section%20Name The TEXTAREA (in IE & Mozilla) turned the part "&curren" into a special character, "¤", the Currency sign, even if no semi-colon was found ;) JP. -- http://www.php.net/manual/en/function.stripslashes.php http://master.php.net/manage/user-notes.php?action=edit+31222 http://master.php.net/manage/user-notes.php?action=delete+31222 http://master.php.net/manage/user-notes.php?action=reject+31222

« previous php.notes (#46595) next »