note 41220 deleted from function.stripslashes by nlopess
| From: | nlopess@php.net | Date: | Sat, 03 Apr 2004 12:36:01 +0000 |
| Subject: | note 41220 deleted from function.stripslashes by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-67555@lists.php.net to get a copy of this message | ||
Note Submitter: spam@pasher.org
----
There is a very important thing to keep in mind about this function: it is NOT the reverse of
addslashes()
addslashes() will only backslash ', ", \, and NUL
stripslashes() does not care if the character being backslashed is one of these four; it will strip
the slash out regardless. According to bug report http://bugs.php.net/bug.php?id=19947 , this is not a
bug (as apparently stripslashes was never intended to be the exact opposite of the addslashes()
function).
This means that a string such as
\"this is a\ test\"
will become
"this is a test"
as opposed to
"this is a\ test"
Why would this cause problems? If you are depending on stripslashes to perform the exact opposite of
addslashes(), you can potentially mess up your data. Take the following example:
<?
$var = "\\\"this is a\\ test\\\"\\n";
echo "var: $var\n";
echo "stripslashes: " . stripslashes($var) . "\n";
?>
Output:
var: \"this is a\ test\"\n
stripslashes: "this is a test"n
Obviously, this is not what you were expecting. If you wish to have a function that is TRULY the
opposite of addslashes(), here are two ways you can do so:
Go through character by character and when you find a slash, see if the next character is in your
list (', ", \, NUL). If so, remove the slash.
Use a simple regex to accomplish the same thing as above.
<?
function my_stripslashes($text)
{
$char_list = "\"'\\0\\\\";
return preg_replace("/\\\\([$char_list])/", '$1', $text);
}
?>
NOTE: This function has not been FULLY tested, but it worked for my simple test cases.