note 43190 added to function.get-magic-quotes-gpc
| From: | mutus123 at hotmail dot com | Date: | Sat, 12 Jun 2004 17:19:24 +0000 |
| Subject: | note 43190 added to function.get-magic-quotes-gpc | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-70977@lists.php.net to get a copy of this message | ||
Sometimes I want user input escaped, and sometimes I don't... in that regard, magic quotes can
get annoying. (I am not able to change the setting through php.ini or even .htaccess on my host)
So I use a single function to explicitly escape or unescape input values, regardless of magic
quotes.
<?php
function backslash(&$arr, $escape)
{
$magic_on = get_magic_quotes_gpc();
if($escape && !$magic_on):
foreach($arr as $k => $v):
switch(gettype($v)):
case 'string' :
$arr[$k] = addslashes($v);
break;
case 'array' :
backslash($arr[$k], true);
endswitch;
endforeach;
endif;
if(!$escape && $magic_on):
foreach($arr as $k => $v):
switch(gettype($v)):
case 'string' :
$arr[$k] = stripslashes($v);
break;
case 'array' :
backslash($arr[$k], false);
endswitch;
endforeach;
endif;
}
//examples
backslash($_POST, true); // force all $_POST values to be properly escaped with backslashes
backslash($_GET, false); // force all $_GET values to NOT be escaped with backslashes
?>
----
Manual Page -- http://www.php.net/manual/en/function.get-magic-quotes-gpc.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+43190
Delete -- http://master.php.net/manage/user-notes.php?action=delete+43190&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+43190&report=yes
Search -- http://master.php.net/manage/user-notes.php