note 43190 deleted from function.get-magic-quotes-gpc by aidan
| From: | aidan@php.net | Date: | Tue, 06 Jul 2004 06:19:07 +0000 |
| Subject: | note 43190 deleted from function.get-magic-quotes-gpc by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-72685@lists.php.net to get a copy of this message | ||
Note Submitter: mutus123@hotmail.com
----
Sometimes I want user input escaped, and sometimes I don't... in that regard, magic quotes can
get annoying. (I am not able to change the setting through php.ini or even .htaccess on my host)
So I use a single function to explicitly escape or unescape input values, regardless of magic
quotes.
<?php
function backslash(&$arr, $escape)
{
$magic_on = get_magic_quotes_gpc();
if($escape && !$magic_on):
foreach($arr as $k => $v):
switch(gettype($v)):
case 'string' :
$arr[$k] = addslashes($v);
break;
case 'array' :
backslash($arr[$k], true);
endswitch;
endforeach;
endif;
if(!$escape && $magic_on):
foreach($arr as $k => $v):
switch(gettype($v)):
case 'string' :
$arr[$k] = stripslashes($v);
break;
case 'array' :
backslash($arr[$k], false);
endswitch;
endforeach;
endif;
}
//examples
backslash($_POST, true); // force all $_POST values to be properly escaped with backslashes
backslash($_GET, false); // force all $_GET values to NOT be escaped with backslashes
?>