note 50339 added to function.get-magic-quotes-gpc

From: Date: Fri, 25 Feb 2005 02:14:24 +0000
Subject: note 50339 added to function.get-magic-quotes-gpc
Groups: php.notes 
Request: Send a blank email to php-notes+get-85519@lists.php.net to get a copy of this message
If get_magic_quotes_gpc() is 1 (on) then the Get, Post and Cookie data is dirty (you have something in memory the user didn't type). You need to clean it up by calling stripslashes. I use this code snippet: function cleanArray(&$arr) { foreach($arr as $k => $v) if (is_array($v)) cleanArray($arr[$k]); else $arr[$k] = stripslashes($v); } /// before processing anything in PHP do if (get_magic_quotes()) { cleanArray($_POST); cleanArray($_COOKIE); cleanArray($_GET); } // here if the user typed O'Connell, you have [O]['][C][o][n][n][e][l][l] // in your variable in memory (say $name=$_POST['name']). // (I use [ ] to represent individual characters here. Don't be confused) // All pattern matching etc, you do with that variable works as // expected (strlen is 9 not 10, for example!). // Of course, sending this back to the user by HTML involves using // htmlentities($var), to store in DB use addslashes($var), to send as // plain email use it content as it is, etc. The above code implies that you need to be aware of what a variable is supposed to have to handle it properly (Isn't this obvious? So, why a global behaviour like magic_quotes in the first place? well... that's life...). If you can change you webshoting setting I recommend magic_quotes=no. ---- Manual Page -- http://www.php.net/manual/en/function.get-magic-quotes-gpc.php Edit -- http://master.php.net/manage/user-notes.php?action=edit+50339 Delete: added to the manual -- http://master.php.net/manage/user-notes.php?action=delete+50339&report=yes&reason=added+to+the+manual Delete: bad code -- http://master.php.net/manage/user-notes.php?action=delete+50339&report=yes&reason=bad+code Delete: spam -- http://master.php.net/manage/user-notes.php?action=delete+50339&report=yes&reason=spam Delete: useless -- http://master.php.net/manage/user-notes.php?action=delete+50339&report=yes&reason=useless Delete: other reasons -- http://master.php.net/manage/user-notes.php?action=delete+50339&report=yes Reject -- http://master.php.net/manage/user-notes.php?action=reject+50339&report=yes Search -- http://master.php.net/manage/user-notes.php

« previous php.notes (#85519) next »