note 43033 added to function.get-magic-quotes-gpc
| From: | Matt at rn2 dot php dot net | Date: | Mon, 07 Jun 2004 13:21:18 +0000 |
| Subject: | note 43033 added to function.get-magic-quotes-gpc | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-70745@lists.php.net to get a copy of this message | ||
IMHO it seems a lot of people dislike magic quotes - but I think they are important. The number one
priority in my mind is to avoid SQL injection attacks and this is where magic quotes work well.
Another words
- Force developers to get rid of magic quotes when they are displaying information to the user
BUT
- Always ensure that any SQL statements when used with user input will be SAFE avoiding an major
security breaches.
Magic quotes SHOULD NOT be removed from the PHP laungage, as disabling them is as simple as changing
the php.ini file. For those on shared servers - sorry but it's no surprise that the
administrators have left magic quotes on.
----
Manual Page -- http://www.php.net/manual/en/function.get-magic-quotes-gpc.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+43033
Delete -- http://master.php.net/manage/user-notes.php?action=delete+43033&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+43033&report=yes
Search -- http://master.php.net/manage/user-notes.php