note 31350 deleted from function.addslashes by aidan
| From: | aidan@php.net | Date: | Thu, 09 Sep 2004 02:04:45 +0000 |
| Subject: | note 31350 deleted from function.addslashes by aidan | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-76261@lists.php.net to get a copy of this message | ||
Note Submitter: mattman32 at rcn dot com
----
Just to reiterate and confirm the following post:
=====================================
leingang at math dot harvard dot edu
08-Aug-2000 11:16
Not sure if this is the right place to put this, but...adding slashes will not work to escape quotes
in the VALUE field of hidden elements! Instead, use urlencode() and urldecode().
=====================================
I have an Add Article page where text is added in a textArea. Then that text is passed to a Preview
page where it is displayed, and stored in a hidden input field variable ($body) to be eventually
added to a database.
If i simply pass $body in the hidden field to the DB, it gets slashed again, and gets cut off at a
double quote, displaying two slashes at where the double quote was, but nothing following. But if i
stripslash($body) in the hidden field, and then pass it to the DB, i still have the cutting off
problem, although no slashes are displayed ;-) I even again stripslashed the $body variable after
it was passed (after being stripped once) to the Add to DB script, and it wouldn't even go into
the DB.
Only by using urlencode() in the hidden variable field (and using urldecode() on my Article Display
page) could i get the quotes to pass from one form to the [hidden] other to the DB and back. Thank
you leingang!