note 32484 deleted from security.variables by aidan
| From: | aidan@php.net | Date: | Tue, 07 Sep 2004 23:32:13 +0000 |
| Subject: | note 32484 deleted from security.variables by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-76180@lists.php.net to get a copy of this message | ||
Note Submitter: rcphp at littondale dot dyndns dot org
----
As mentioned somewhere else, magic_quotes can be dealt with by:
# Unmangle input if PHP is running in "Magic Quotes" mode.
# I need the input for both DB and HTML generation, so use
# the appopriate translations in the appropriate places.
if(get_magic_quotes_gpc())
{
$content = stripslashes($content);
$title = stripslashes($title);
}
Then in HTML I use the htmlspecialchars() function to output, and in SQL I use addslashes(). Because
I'm using the same variable in multiple places, I need to be aware of what it is and what to do
with it.
Whether fast or not, I use Perl like regular functions for validity checking. The below checks for a
number, though PHP has functions to handle this (I am only learning)
if(!preg_match("/^[0-9]*$/", $alterExistingID))
{
# showWarning is one of my functions
showWarning("Page called with malformed comment ID");
$alterExistingID = "";
}
See the is_numeric() function for a better solution to this.