note 31350 added to function.addslashes
| From: | mattman32 at rcn dot com | Date: | Fri, 18 Apr 2003 07:11:38 +0000 |
| Subject: | note 31350 added to function.addslashes | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-46769@lists.php.net to get a copy of this message | ||
Just to reiterate and confirm the following post:
=====================================
leingang at math dot harvard dot edu
08-Aug-2000 11:16
Not sure if this is the right place to put this, but...adding slashes will not work to escape quotes
in the VALUE field of hidden elements! Instead, use urlencode() and urldecode().
=====================================
I have an Add Article page where text is added in a textArea. Then that text is passed to a Preview
page where it is displayed, and stored in a hidden input field variable ($body) to be eventually
added to a database.
If i simply pass $body in the hidden field to the DB, it gets slashed again, and gets cut off at a
double quote, displaying two slashes at where the double quote was, but nothing following. But if i
stripslash($body) in the hidden field, and then pass it to the DB, i still have the cutting off
problem, although no slashes are displayed ;-) I even again stripslashed the $body variable after
it was passed (after being stripped once) to the Add to DB script, and it wouldn't even go into
the DB.
Only by using urlencode() in the hidden variable field (and using urldecode() on my Article Display
page) could i get the quotes to pass from one form to the [hidden] other to the DB and back. Thank
you leingang!
--
http://www.php.net/manual/en/function.addslashes.php
http://master.php.net/manage/user-notes.php?action=edit+31350
http://master.php.net/manage/user-notes.php?action=delete+31350
http://master.php.net/manage/user-notes.php?action=reject+31350