note 18267 deleted from function.eval by nlopess
| From: | nlopess@php.net | Date: | Tue, 18 May 2004 13:37:17 +0000 |
| Subject: | note 18267 deleted from function.eval by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-69764@lists.php.net to get a copy of this message | ||
Note Submitter: office@@universalmetropolis.com
----
Take note of something very simple about this function which I have had several people write to me
and thank me for keeping things so straightforward.
The reason you get parse errors when using EVAL on HTML or includes, is because the EVAL() function
reads the target as if it were a standard block string.
// For example, you would never do this:
$string=""Hi," said the giant monkey.";
// But you would do this, by escaping the quotes:
$string="\"Hi,\" said the giant monkey.";
// When you include HTML for parsing, of course you are going to have ""s all over the
place
<table width=200 align="center" bgcolor="#131313">
// etc... so when EVAL() opens this as a string, it will fail at the first instance of quotation
marks.
Here is the fix:
// open file, be it from a database or a physical include
$file=fopen("myinclude.inc","r");
$openedfile=fread($file,filesize($file));
// add slashes to prevent premature string escaping
$string=addslashes($openedfile);
// evaluate the code (note the value is returned in the function
eval("\$string=\"$string\";");
// remove the slashes you used to protect your string during parsing
$string=stripslashes($string);