note 26782 modified in function.addslashes by vrana
| From: | vrana@php.net | Date: | Tue, 17 Aug 2004 13:56:39 +0000 |
| Subject: | note 26782 modified in function.addslashes by vrana | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-80036@lists.php.net to get a copy of this message | ||
Beware of using addslashes() on input to the serialize() function. serialize() stores strings with
their length; the length must match the stored string or unserialize() will fail.
Such a mismatch can occur if you serialize the result of addslashes() and store it in a database;
some databases (definitely including PostgreSQL) automagically strip backslashes from
"special" chars in SELECT results, causing the returned string to be shorter than it was
when it was serialized.
In other words, do this...
<?php
$string="O'Reilly";
$ser=serialize($string); # safe -- won't count the slash
$result=addslashes($ser);
?>
...and not this...
<?php
$string="O'Reilly";
$add=addslashes($string); # RISKY! -- will count the slash
$result=serialize($add);
?>
In both cases, a backslash will be added after the apostrophe in "O'Reilly"; only in
the second case will the backslash be included in the string length as recorded by serialize().
[Note to the maintainers: You may, at your option, want to link this note to serialize() as well as
to addslashes(). I'll refrain from doing such cross-posting myself...]
--was--
Beware of using addslashes() on input to the serialize() function. serialize() stores strings with
their length; the length must match the stored string or unserialize() will fail.
Such a mismatch can occur if you serialize the result of addslashes() and store it in a database;
some databases (definitely including PostgreSQL) automagically strip backslashes from
"special" chars in SELECT results, causing the returned string to be shorter than it was
when it was serialized.
In other words, do this...
$string="O'Reilly";
$ser=serialize($string); # safe -- won't count the slash
$result=addslashes($ser);
...and not this...
$string="O'Reilly";
$add=addslashes($string); # RISKY! -- will count the slash
$result=serialize($add);
In both cases, a backslash will be added after the apostrophe in "O'Reilly"; only in
the second case will the backslash be included in the string length as recorded by serialize().
[Note to the maintainers: You may, at your option, want to link this note to serialize() as well as
to addslashes(). I'll refrain from doing such cross-posting myself...]
http://php.net/manual/en/function.addslashes.php