note 32788 deleted from function.str-replace by didou
| From: | didou@php.net | Date: | Sat, 16 Aug 2003 09:52:55 +0000 |
| Subject: | note 32788 deleted from function.str-replace by didou | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-54317@lists.php.net to get a copy of this message | ||
Note Submitter: nospam@floconsdepaques.com.com
----
nimrod leahvi is half way to the thruth :
"When repalcing a string for a later use with JavaScript document.write use these:
str_repalce("\"", "\\\"", $str) (1)
str_repalce("\'", "\\\'", $str) (2)
str_repalce("\\", "\\\\", $str) (3)
this will add \ before the otherwise problematic ", ', \"
This is wrong. When encoutering an ", line (1) will return \", then line (3) will return
\\" which will block the javascript.
You need to put line (1) after line (3) like this :
str_repalce("\'", "\\\'", $str) (a)
str_repalce("\\", "\\\\", $str) (b)
str_repalce("\"", "\\\"", $str) (c)
In this case, when " is encoutered, line (c) will return a correct escaped \" .