note 49723 deleted from function.addslashes by betz
| From: | betz@php.net | Date: | Mon, 26 Sep 2005 22:02:51 +0000 |
| Subject: | note 49723 deleted from function.addslashes by betz | ||
| References: | 1 | Groups: | php.notes |
| Request: | Send a blank email to php-notes+get-95817@lists.php.net to get a copy of this message | ||
Note Submitter: caya
----
Unfortunately magic quotes is the default and violates a simple principle: what the user types is
what you get.
If you want to follow that principle the following code snippet may be useful:
function cleanData() {
foreach($_GET as $k => $k)
$_GET[$k] = stripslashes($k);
// likewise for $_POST, $_COOKIE
}
...
if (get_magic_quotes_gpc()) {
cleanData();
}
You will need to add this to every page... sorry. But this is sometimes easier than convincing a
webhosting company to change the settings...(if you use a front-controller pattern it's a lot
easier...)
With this principle, then you always have in memory real data.
When generating HTML, you may need then to do htmlentities(...), as you are moving from the
'php data world' to the 'html data world', but you are playing on the safe side.
Same analysis apply to generating SQL sentences...