note 50339 added to function.get-magic-quotes-gpc
| From: | Caya at osu1 dot php dot net | Date: | Fri, 25 Feb 2005 02:14:24 +0000 |
| Subject: | note 50339 added to function.get-magic-quotes-gpc | ||
| Groups: | php.notes | ||
| Request: | Send a blank email to php-notes+get-85519@lists.php.net to get a copy of this message | ||
If get_magic_quotes_gpc() is 1 (on) then the Get, Post and Cookie data is dirty (you have something
in memory the user didn't type). You need to clean it up by calling stripslashes.
I use this code snippet:
function cleanArray(&$arr) {
foreach($arr as $k => $v)
if (is_array($v))
cleanArray($arr[$k]);
else
$arr[$k] = stripslashes($v);
}
/// before processing anything in PHP do
if (get_magic_quotes()) {
cleanArray($_POST);
cleanArray($_COOKIE);
cleanArray($_GET);
}
// here if the user typed O'Connell, you have [O]['][C][o][n][n][e][l][l]
// in your variable in memory (say $name=$_POST['name']).
// (I use [ ] to represent individual characters here. Don't be confused)
// All pattern matching etc, you do with that variable works as
// expected (strlen is 9 not 10, for example!).
// Of course, sending this back to the user by HTML involves using
// htmlentities($var), to store in DB use addslashes($var), to send as
// plain email use it content as it is, etc.
The above code implies that you need to be aware of what a variable is supposed to have to handle it
properly (Isn't this obvious? So, why a global behaviour like magic_quotes in the first place?
well... that's life...).
If you can change you webshoting setting I recommend magic_quotes=no.
----
Manual Page -- http://www.php.net/manual/en/function.get-magic-quotes-gpc.php
Edit -- http://master.php.net/manage/user-notes.php?action=edit+50339
Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+50339&report=yes&reason=added+to+the+manual
Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+50339&report=yes&reason=bad+code
Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+50339&report=yes&reason=spam
Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+50339&report=yes&reason=useless
Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+50339&report=yes
Reject -- http://master.php.net/manage/user-notes.php?action=reject+50339&report=yes
Search -- http://master.php.net/manage/user-notes.php