note 31657 deleted from function.stripslashes by aidan
| From: | aidan@php.net | Date: | Sun, 29 Aug 2004 10:23:07 +0000 |
| Subject: | note 31657 deleted from function.stripslashes by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-75534@lists.php.net to get a copy of this message | ||
Note Submitter: jpleveille at webgraphe dot com
----
Pay attention to the fact that always using stripslashes() on information coming from $_POST is bad
if get_magic_quotes_gpc() returns you false (this function tells you if magic quotes or slashes were
added to GET, POST or COOKIE content).
Notice that the PHP configuration file php.ini will let you set this parameter to On or Off and its
effect on GPCs variables (like $_GET, $_POST, $_COOKIE) is the same as if you were doing
addslashes() on each of their string items.
Magic quotes are in fact slashes added by default by PHP in front of special characters (to escape
them automatically), if the configuration magic_quotes_gpc = ON in your php.ini file.
The result is that if I submit a POST value like "aujourd'hui", I'll get
"aujourd\'hui" automatically. >>THEN<< I use stripslashes to revert the
effect of magic_quotes_gpc, I >>DON'T<< do this EVERY time I access a value from
$_GET, $_POST or $_COOKIE or I might get some slashes lost even if I want them to be in my GPC
variables.
On the other hand, having magic_quotes_gpc = ON may avoid you to call addslashes() for values you
may want to insert in SQL queries automatically (and to avoid hack attempts to your database).
Note: configuration magic_quotes_runtime has the same effect on values returned by functions like
mysql_fetch_row() of fread(). This is a legacy option likely to be turned off by default and
generally not used by anyone.
JP.