note 49399 added to security.magicquotes
| From: | nitrous at fuckoff dot com | Date: | Wed, 26 Jan 2005 19:01:51 +0000 |
| Subject: | note 49399 added to security.magicquotes | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-84038@lists.php.net to get a copy of this message | ||
This "feature" is the cause of so many escaping problems. It's very important to
understand the implications of what magic quotes really do.
Nearly every call, except those being written directly to the database, using user submitted data
will require a call to strip_slashes. It gets very ugly very fast.
What should be done is proper escaping of shell parameters and database parameters. PHP provides
several escaping functions intended for this purpose. Slashes alone don't cut it anyway.
----
Manual Page -- http://www.php.net/manual/en/security.magicquotes.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+49399
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+49399&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+49399&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+49399&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+49399&report=yes&reason=useless
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+49399&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+49399&report=yes
Search -- http://master.php.net/manage/user-notes.php