note 30029 deleted from function.htmlspecialchars by didou

From: Date: Tue, 29 Jul 2003 19:17:09 +0000
Subject: note 30029 deleted from function.htmlspecialchars by didou
References: 1  Groups: php.notes 
Request: Send a blank email to php-notes+get-52958@lists.php.net to get a copy of this message
Note Submitter: dystopia589@yahoo.com ---- It's strange how close this function resembles joseph at nextique dot com's.. I wrote it before checking this site. It works really well for securing the values from $_GET and $_POST data. I had to add the is_array check because sometimes array data is submitted by form. function SpecialChars($Security) { if (is_array($Security)) { while(list($key, $val) = each($Security)) { if (is_array($val)) { $Security[$key] = SpecialChars($val); } else { $Security[$key] = htmlspecialchars(stripslashes($val), ENT_QUOTES); } } } else { $Security = htmlspecialchars(stripslashes($Security), ENT_QUOTES); } return $Security; } Using this function, it's good to put these lines in a common include file for all your scripts handling form data: while(list($key, $val) = each($_GET)) { ${$key} = SpecialChars($val); } while(list($key, $val) = each($_POST)) { ${$key} = SpecialChars($val); } This way, all values from $_GET and $_POST are converted properly, without having to specifically handle each one before displaying.. it makes your code so much easier to read, and ensures that you don't forget one or two..

« previous php.notes (#52958) next »