note 30029 deleted from function.htmlspecialchars by didou
| From: | didou@php.net | Date: | Tue, 29 Jul 2003 19:17:09 +0000 |
| Subject: | note 30029 deleted from function.htmlspecialchars by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-52958@lists.php.net to get a copy of this message | ||
Note Submitter: dystopia589@yahoo.com
----
It's strange how close this function resembles joseph at nextique dot com's.. I wrote it
before checking this site. It works really well for securing the values from $_GET and $_POST data.
I had to add the is_array check because sometimes array data is submitted by form.
function SpecialChars($Security)
{
if (is_array($Security))
{
while(list($key, $val) = each($Security))
{
if (is_array($val))
{
$Security[$key] = SpecialChars($val);
}
else
{
$Security[$key] = htmlspecialchars(stripslashes($val), ENT_QUOTES);
}
}
}
else
{
$Security = htmlspecialchars(stripslashes($Security), ENT_QUOTES);
}
return $Security;
}
Using this function, it's good to put these lines in a common include file for all your scripts
handling form data:
while(list($key, $val) = each($_GET))
{
${$key} = SpecialChars($val);
}
while(list($key, $val) = each($_POST))
{
${$key} = SpecialChars($val);
}
This way, all values from $_GET and $_POST are converted properly, without having to specifically
handle each one before displaying.. it makes your code so much easier to read, and ensures that you
don't forget one or two..