note 49399 added to security.magicquotes

From: Date: Wed, 26 Jan 2005 19:01:51 +0000
Subject: note 49399 added to security.magicquotes
Groups: php.notes 
Request: Send a blank email to php-notes+get-84038@lists.php.net to get a copy of this message
This "feature" is the cause of so many escaping problems. It's very important to understand the implications of what magic quotes really do. Nearly every call, except those being written directly to the database, using user submitted data will require a call to strip_slashes. It gets very ugly very fast. What should be done is proper escaping of shell parameters and database parameters. PHP provides several escaping functions intended for this purpose. Slashes alone don't cut it anyway. ---- Manual Page -- http://www.php.net/manual/en/security.magicquotes.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+49399 Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+49399&report=yes&reason=added+to+the+manual Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+49399&report=yes&reason=bad+code Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+49399&report=yes&reason=spam Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+49399&report=yes&reason=useless Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+49399&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+49399&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#84038) next »