note 32788 added to function.str-replace
| From: | nospam at floconsdepaques dot com dot com | Date: | Fri, 06 Jun 2003 20:47:37 +0000 |
| Subject: | note 32788 added to function.str-replace | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-49913@lists.php.net to get a copy of this message | ||
nimrod leahvi is half way to the thruth :
"When repalcing a string for a later use with JavaScript document.write use these:
str_repalce("\"", "\\\"", $str) (1)
str_repalce("\'", "\\\'", $str) (2)
str_repalce("\\", "\\\\", $str) (3)
this will add \ before the otherwise problematic ", ', \"
This is wrong. When encoutering an ", line (1) will return \", then line (3) will return
\\" which will block the javascript.
You need to put line (1) after line (3) like this :
str_repalce("\'", "\\\'", $str) (a)
str_repalce("\\", "\\\\", $str) (b)
str_repalce("\"", "\\\"", $str) (c)
In this case, when " is encoutered, line (c) will return a correct escaped \" .
----
Manual Page -- http://www.php.net/manual/en/function.str-replace.php
Edit Note -- http://master.php.net/manage/user-notes.php?action=edit+32788
Delete Note -- http://master.php.net/manage/user-notes.php?action=delete+32788&report=yes
Reject Note -- http://master.php.net/manage/user-notes.php?action=reject+32788&report=yes