note 31222 deleted from function.stripslashes by aidan
| From: | aidan@php.net | Date: | Mon, 30 Aug 2004 11:08:06 +0000 |
| Subject: | note 31222 deleted from function.stripslashes by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-75671@lists.php.net to get a copy of this message | ||
Note Submitter: jpleveille at webgraphe dot com
----
Just to mention that you strip slashes, by example, in queries for databases, not for inputs in an
HTML form (unless you display information coming from a variable altered by magic_quotes_gpc). Use
htmlspecialchars() or htmlentities() in an input to set its value:
<input type="text" value="<?php echo htmlspecialchars($value); ?>"
/>
As I mentioned before, you may want to stripslashes() $value if this value is coming from a variable
altered by magic_quotes_gpc. htmlspecialchars() will avoid double-quotes of $value to enter in
conflict with double-quotes of the input to set its value because double-quotes will, for example,
be replaced by the string """. It is also important to do that in TEXTAREAs (or
in any HTML form input). I already had the problem with a link I wanted to print in a TEXTAREA that
contained a query like this:
http://www.myserver.com/link.php?id=123¤tSection=Section%20Name
The TEXTAREA (in IE & Mozilla) turned the part "¤" into a special character,
"¤", the Currency sign, even if no semi-colon was found ;)
JP.