note 26852 deleted from function.htmlentities by nlopess
| From: | nlopess@php.net | Date: | Sun, 12 Sep 2004 14:58:06 +0000 |
| Subject: | note 26852 deleted from function.htmlentities by nlopess | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-76532@lists.php.net to get a copy of this message | ||
Note Submitter: dakota at tensen dot net
----
In doing some form post, MySQL, PHP applications, it became apparent that special chars are
stubborn. For instance, before I can put a string submitted with a form into mysql, for safety I
need to do this:
mysql_escape_string(htmlspecialchars(stripslashes($field)))
Its not hard to do and I've noticed that I use it a lot. It might be interesting to see in
future versions of PHP a function that does this, but for now heres an easy solution which anyone
with a similar problem can use:
function formspecialchars($var)
{
$out = mysql_escape_string(htmlspecialchars(stripslashes($var)));
return $out;
}