note 32484 added to security.variables

From: Date: Wed, 28 May 2003 20:52:08 +0000
Subject: note 32484 added to security.variables
Groups: php.notes 
Request: Send a blank email to php-notes+get-49211@lists.php.net to get a copy of this message
As mentioned somewhere else, magic_quotes can be dealt with by: # Unmangle input if PHP is running in "Magic Quotes" mode. # I need the input for both DB and HTML generation, so use # the appopriate translations in the appropriate places. if(get_magic_quotes_gpc()) { $content = stripslashes($content); $title = stripslashes($title); } Then in HTML I use the htmlspecialchars() function to output, and in SQL I use addslashes(). Because I'm using the same variable in multiple places, I need to be aware of what it is and what to do with it. Whether fast or not, I use Perl like regular functions for validity checking. The below checks for a number, though PHP has functions to handle this (I am only learning) if(!preg_match("/^[0-9]*$/", $alterExistingID)) { # showWarning is one of my functions showWarning("Page called with malformed comment ID"); $alterExistingID = ""; } See the is_numeric() function for a better solution to this. ---- Manual Page -- http://www.php.net/manual/en/security.variables.php Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+32484 Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+32484&report=yes Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+32484&report=yes

« previous php.notes (#49211) next »