note 31350 added to function.addslashes

From: Date: Fri, 18 Apr 2003 07:11:38 +0000
Subject: note 31350 added to function.addslashes
Groups: php.notes 
Request: Send a blank email to php-notes+get-46769@lists.php.net to get a copy of this message
Just to reiterate and confirm the following post: ===================================== leingang at math dot harvard dot edu 08-Aug-2000 11:16 Not sure if this is the right place to put this, but...adding slashes will not work to escape quotes in the VALUE field of hidden elements! Instead, use urlencode() and urldecode(). ===================================== I have an Add Article page where text is added in a textArea. Then that text is passed to a Preview page where it is displayed, and stored in a hidden input field variable ($body) to be eventually added to a database. If i simply pass $body in the hidden field to the DB, it gets slashed again, and gets cut off at a double quote, displaying two slashes at where the double quote was, but nothing following. But if i stripslash($body) in the hidden field, and then pass it to the DB, i still have the cutting off problem, although no slashes are displayed ;-) I even again stripslashed the $body variable after it was passed (after being stripped once) to the Add to DB script, and it wouldn't even go into the DB. Only by using urlencode() in the hidden variable field (and using urldecode() on my Article Display page) could i get the quotes to pass from one form to the [hidden] other to the DB and back. Thank you leingang! -- http://www.php.net/manual/en/function.addslashes.php http://master.php.net/manage/user-notes.php?action=edit+31350 http://master.php.net/manage/user-notes.php?action=delete+31350 http://master.php.net/manage/user-notes.php?action=reject+31350

« previous php.notes (#46769) next »